Integration of Dell EMC Data Domain with RSA Authentication Manager REST API
Article Number
Applies To
RSA Product Set: SecurID
RSA Product/Service Type: Authentication Manager
RSA Version/Condition: 8.x
Issue
This article provides the steps to integrate Dell EMC Data Domain with RSA Authentication Manager through the REST API.
Resolution
Authentication Manager Configuration
- Enable the REST API on the instances where the Data Domain will be connected.
- Create two users in the internal database users: one named secofficer and the other named sysadmin. These are default users in the Dell Data Domain.
- Login to the Security Console and navigate to Identity > Users > Add New.
- Create a new user for secofficer. The only information needed is the the user ID and last name. Click Save and repeat for sysadmin.
- Assign a token to each user.
Data Domain Configuration
Set the following information on the Data Domain:
- Server URL: https://<am_fqdn>:5555/mfa/v1_1/authn
- Client ID: RSA Agent name “apidd" for example
- Client Key: RSA Access Key
- The certificate is the root certificate from the Security Console:
-
- Launch Internet Explorer, and go to https://server_name/sc.
- Right-click on the lock and select Properties.
- In the Properties dialog box, click Certificates.
- In the Certificate dialog box, select the Certification Path tab.
- Click the top item in the certificate path.
- Click View Certificate.
- In the Certificate dialog box, click the Details tab.
- Click Copy to File.
- On the Certificate Export Wizard page, click Next.
- On the Export File Format page, select Base 64 encoded binary X.509 (.CER).
- Click Next.
- On the File to Export page, click Browse.
- Browse to a location to store the root certificate, enter am_root.cer in the File Name field.
- Make sure that the Save As type is set to Base-64 encoded X.509.CER.
- On the File to Export page, click Next.
- On the Completing the Certificate Export page, click Finish.
- Click OK.
- Edit the certificate file with the .cer extension in a text editor.
- Copy the entire text, including the lines of BEGIN CERTIFICATE and END CERTIFICATE and add it to the Data Domain-certificate part.
- Add the usernames secofficer and sysadmin with the password created.
Notes
The Client ID (apidd) is the TCP agent name that is configured on the Security Console.
Related Articles
Splunk integration with RSA Authentication Manager using REST API 606Number of Views VMWare Unified Access Gateway (UAG) Integration Guide with the Authentication Manager using REST API 303Number of Views Authenticate with On-Demand Authentication (ODA) using REST API authentication on RSA Authentication Manager 8.x 307Number of Views How to calculate the RSA REST API Authentication Response Time 210Number of Views How to authenticate to an RSA Authentication Agent for Windows as user@domain.com with NTLM to UPN name mapping 509Number of Views
Trending Articles
RSA Authentication Manager Upgrade Process RSA Release Notes for RSA Authentication Manager 8.8 RSA RADIUS Server service failed to start in the RSA Authentication Manager 8.1 Operations Console Microsoft Entra ID External MFA - Relying Party Configuration Using OIDC - RSA Ready Implementation Guide RSA Release Notes: Cloud Access Service and RSA Authenticators
Don't see what you're looking for?