Making RSA Authentication Manager 8.1 Self-Service Console Accessible For External Users
2 years ago
Originally Published: 2016-05-23
Article Number
000066275
Applies To
RSA Product Set: SecurID RSA
Product/Service Type: Authentication Manager 
RSA Version/Condition: 8.x
Resolution
The Self-Service console is a web-based workflow system that provides two components:

Self-ServiceAllows end users to basic troubleshooting and token maintenance tasks.
Some of this includes, changing PIN, requesting replacement tokens, performing a token resynchronization, seeking emergency access and so on.


ProvisioningAllows users to request for RSA SecurID tokens (hard or soft) based on their requirement. The system then automates the workflow, which once approved by the Administrator, offers the token to the users.
The Self-Service console (SSC) can be made available to external users (users from outside the internal network), by using a Lightweight Application Server called The Web Tier.​

The Web Tier application hosts several Authentication Manager services securely in the network DMZ, thus offering the following benefit:
  1. All external traffic is bound to pass through the web tier thus protecting the internal network from any unfiltered internet (external) traffic.
  2. The Authentication Managers are safely isolated and protected inside a firewall in the private network.
Figure A below presents a schematic overview of the Web-Tier:
 
User-added image

 Making the self service console accessible for external users is a two-fold process:
  1. Configuring Web Tier
  2. Exposing the Self Service Console
Configuring Web Tier:
  • A web tier can be deployed in the DMZ or inside the firewall.
  • Configuring a Web Tier requires to first configure a Virtual Host.
  • The Virtual Hostname must be configured on the RSA Authentication Manager as follows:
  1. Primary AM 8.1 Server Operations Console > Deployment Configuration > Virtual Host & Load Balancing
  2. Select “Configure a virtual host and load balancers
  3. Enter the “Virtual Hostname
  4. Ensure the Port Number is 443.
  5. Click “Save
  • The Web Tier can then be configured as follows:
  1. Primary AM 8.1 Server Operations Console > Deployment Configuration > Web-Tier Deployments > Add New
  2. Provide the appropriate details.
  3. Select “Save & Generate Web-Tier Package
Exposing the Self Service Console:
  • Once the Web Tier is configured successfully, next would be to expose the SSC to external users for access.
  • External Users can access the SSC using the following URL: 
User-added image