
AshrafHabashy (Customer) asked a question.
Hi, Now I'm doing RHEL OS Upgrade from 7.9 to 8.10, and there is an RSA_agent version 7.1 now this RSA_Agent still compatible with OS 8.10 ? rsa authentication will keep working , please advise
Salesforce now requires MFA validation for all SSO users. Please read the advisory below for further information on required actions to avoid login failures.
Read the Advisory
AshrafHabashy (Customer) asked a question.
Ashraf: You will need to upgrade your Linux MFA agent to version 9.0 or newer. All currently supported versions of the PAM/Linux agent support RHEL 8.10. We keep an updated list of supported operating systems at this link: https://community.rsa.com/s/article/RSA-MFA-Agent-for-UNIX-Platform-Support-Matrix
Thanks david for your support .Sure, I will install the latest RSA Agent. My concern was to ensure that authentication remains unchanged so that our clients’ access through RSA is not disrupted during the process, after which I will proceed with the upgrade.
I am actually not certain about the best practice: should we upgrade the existing agent before the OS upgrade, or remove the current agent, perform the OS upgrade, and then install the latest RSA Agent MFA afterward?
The 7.1.x PAM agent was never qualified to run on RHEL 8. The current 9.x Linux/PAM MFA agent works on RHEL 7.9. Therefore it would make sense to upgrade the agent before upgrading the OS. However there is more to consider here. The 7.x agent used UDP/sdconf.rec only. The 8.x agent would do either UDP/sdconf.rec or the newer REST API authentication. But the 9.x agent supports REST API only. So even if you upgrade the agent, you would still have to reconfigure it.
I have experience performing a double upgrade from version 7.1 to 8.1.3 and then to 9.0.1 on RHEL OS 8.10, using the package provided by RSA.
I would also like to highlight that, although your said “The 7.1.x PAM agent was never qualified to run on RHEL 8”, in our environment it was running successfully on a RHEL 7.9 VM, which is the VM where I carried out the agent upgrade