Performing client post-installation tasks

You must create the client truststore and specify which client applications use IBM® MFA for authentication.

IBM MFA includes different PAM modules that you customize to specify which applications use IBM MFA for authentication:
  • The pam_azf module, which is installed on every Red Hat Enterprise Linux® for IBM Z® and LinuxONE, or SUSE Linux Enterprise Server on IBM Z system for which you want to use IBM MFA for authentication. This module processes IBM MFA credentials for provisioned users and fails bad IBM MFA credentials.
  • The pam_azf_fallback module. If you are using password fallback, this module must be installed on every Red Hat Enterprise Linux for IBM Z and LinuxONE, or SUSE Linux Enterprise Server on IBM Z system for which you want to use IBM MFA for authentication. This module checks whether a user is provisioned and whether password fallback is enabled. If password fallback is enabled for users, users can log in with their Red Hat Enterprise Linux for IBM Z and LinuxONE or SUSE Linux Enterprise Server on IBM Z password.