Configure Connection to Authentication Manager
21 days ago

Configure Connection to Authentication Manager

Users can access cloud-protected resources using RSA authenticators managed in Authentication Manager (AM). The Identity Router (IDR) can use a REST-based MFA agent, rather than a TCP agent, to verify authentication with AM. As part of the transition to a REST agent, you can configure the connection to AM based on your current IDR environment and configuration state as follows:

  • If all IDRs are upgraded to version 12.24.0.0.0 or later and a TCP agent connection exists, both TCP and REST agent configuration options are available. In this case, it is recommended to reconfigure the connection using the REST agent option.

  • If one or more IDRs are not upgraded to version 12.24.0.0.0 or later and have an existing TCP agent connection, only the TCP agent configuration option is available. Therefore, upgrade the IDR to the latest version to enable transition to the REST agent.

  • If no IDR is present or there is no existing TCP agent connection, only the REST agent option is available.

Before you begin

Procedure 

  1. In the Cloud Administration Console, click Platform > Authentication Manager.
  2. Click Configure Connection.

  3. Based on your IDR environment, select the appropriate connection option and complete the required fields in the Configuration Settings dialog box:

  • REST Agent (recommended option)

    1. Authentication Agent Name: Enter the exact name your Authentication Manager (AM) administrator provides.

    2. Primary URL: Enter the URL in the format https://<AM_PRIMARY_INSTANCE_HOSTNAME>:PORT.

    3. Replica URL(s) (optional): Click Add to enter a secondary AM instance URL, if available.

    4. Access Key: Enter the access key your AM administrator provides.

    5. AM Root Certificate: Click Choose file and upload the certificate file from your AM administrator.

  • TCP Agent

    1. Authentication Agent Name: Enter the exact name your AM administrator provides.

    2. sdconf.rec File: Click Choose file and upload the file your AM administrator provides.

  1. Click Save to complete the configuration.

  2. Click Publish Changes.

    Note:  If you are running IDR 12.24.0.0.0 or later, and the existing AM connection is deleted, the TCP agent option will no longer be available. When you configure a new AM connection after this point, you can select only the REST agent option, and the TCP agent cannot be re-enabled.

After you finish 

A graphic shows the connection status for each configured identity router. If any components are not connected, investigate the cause.