Best practices for installing, configuring and using the RSA MFA Agent 9.x for PAM/Unix
Originally Published: 2026-06-17
Article Number
Applies To
RSA MFA Agent 9.x for PAM/Unix
Tasks
To be successful with installing, configuring and using the MFA for Unix agent, please follow these best practices:
- Make sure your firewall allows bidirectional traffic on 5555 between the agent and all Authentication Manager servers.
- Be sure to open 5555 on all Authentication Manager servers in your deployment via the Security Console under Settings > Authentication API.
- Before installing, be sure that SELinux is disabled. Following the steps on page 24 of the MFA Agent 9.1 for UNIX Installation and Configuration Guide for RHEL and Ubuntu, you can reenable it after the agent is installed.
- Turn off fapolicyd. It has not been qualified for use with the MFA Agent for PAM/Unix.
- Disable Trellix as it can restrict access to the file system until decryption or security policies are fully applied. The MFA Agent requires uninterrupted access to certain files and libraries during authentication. If Trellix blocks or delays this access, it causes authentication to fail. Hence, environments with Trellix installed and active are not supported.
- As mentioned on page 16 of the MFA Agent 9.1 for UNIX Installation and Configuration Guide for RHEL and Ubuntu, be sure the certificate is in .pem format.
- You can enable ENABLE_USER_SUPPORT OR ENABLE_GROUP_SUPPORT, but not both.
- For users, ensure that the user that you want challenged is a local user on the box. Edit /etc/sd_pam.conf to add the user. For example,
LIST_OF_USERS=root:administrator:sroberts
- To add local users, run the useradd command (sudo useradd sroberts). Failure to do this step will result in errors when testing authentication.
- For groups, ensure that the group that you want challenged is a local group on the box. Edit /etc/sd_pam.conf to add the group. For example,
LIST_OF_GROUPS=admins:secops:security
- To add local groups, run the groupadd command (sudo groupadd secops). Failure to do this step will result in errors when testing authentication.
- Please review these documents for additonal information:
- Editing the RSA MFA Agent 9.0 on RHEL 9.4 to enable ChallengeResponseAuthentication (Note that on RHEL 9 the file called 50-redhat.conf in /etc/ssh/sshd_config.d).
- RSA MFA Agent 9.1 for UNIX Installation and Configuration Guide for RHEL and Ubuntu.
Related Articles
How to install and configure the SecurID PAM 8.1.3 agent on Ubuntu 18.04 269Number of Views Ivanti Pulse Connect 9.1 - RADIUS with CAS Configuration - SecurID Access Implementation Guide 25Number of Views RSA MFA Agent 9.0.1 for PAM Release Notes 69Number of Views RSA Announces the Release of RSA MFA Agent 9.1 for UNIX 15Number of Views AAOP in tomcat 6 'Unable to connect to the DB connection for the image service'<DATASTORE_ERROR ' Unable to get DB connect… 93Number of Views
Trending Articles
Download RSA SecurID Access Cloud User Event audit logs using Cloud Administration REST API CLU RSA Authentication Manager 8.9 Release Notes (January 2026) AFX Server Fails to Start with 'Could Not Build a Validated Path' and 'Timed Out Waiting for AFX Applications to Start' in… AFX Server stuck in 'Not running' State, with error 'timed out waiting for AFX applications to start' Quick Setup Guide - Passwordless Authentication in Windows MFA Agent for Active Directory
Don't see what you're looking for?