RSA Product/Service Type: Authentication Agent for PAM
The RSA MFA Agent 9.0 for PAM - Installation and Configuration Guide for Oracle Linux RHEL Ubuntu CentOS and Rocky Linux instructs administrators to comment all auth modules in the protected service and keep pam_securid.so as the only available auth module. This is shown in the example below:
#%PAM-1.0 auth required pam_securid.so #auth required pam_sepermit.so #auth substack password-auth #auth include postlogin
That is acceptable if the environment is dealing with internal Linux users, as pam_securid.so can handle both SecurID authentication and Linux authentication. However, when it gets to Active Directory users, pam_securid.so cannot handle Active Directory authentication.
This configuration authenticates the SecurID passcode first then the AD password for challenged users and only the AD password for unchallenged users. In this example, assume that AD integration is using WinBind.
- In /etc/sd_pam.conf, change both PAM_IGNORE_SUPPORT_FOR_USERS and PAM_IGNORE_SUPPORT to 1, as shown in bold:
#PAM_IGNORE_SUPPORT_FOR_USERS # :: 1 to return PAM_IGNORE if a user is not SecurID authenticated due to user exclusion support # :: 0 to UNIX authenticate a user that is not SecurID authenticated due to user exclusion support # default value is 0 PAM_IGNORE_SUPPORT_FOR_USERS=1 #PAM_IGNORE_SUPPORT # :: 1 to return PAM_IGNORE if a user is not SecurID authenticated due to their group membership # :: 0 to UNIX authenticate a user that is not SecurID authenticated due to their group membership # default value is 0 PAM_IGNORE_SUPPORT=1
- In the protected module (for example, sshd /etc/pam.d/sshd), change the auth config to be as follows.
auth required pam_securid.so not_set_pass auth required pam_windbind.so #auth required pam_sepermit.so #auth substack password-auth #auth include postlogin
auth [success=done ignore=ignore default=die] pam_securid.so not_set_pass auth required pam_windbind.so #auth required pam_sepermit.so #auth substack password-auth #auth include postlogin
Related Articles
Unable to authenticate with Authentication Agent for PAM for SSH due to SELinux 206Number of Views Authentication to restricted agents with Active Directory users fail in Authentication Manager 8.1 146Number of Views Unable to Resolve User by Login ID and/or Alias or Authenticator Not Assigned to User When Attempting to Authenticate via … 2.17KNumber of Views How To Test The RSA Authentication Agent for PAM Module 1.29KNumber of Views How to verify that RSA Authentication Agent for Windows can perform challenge user lookups across different Active Directo… 485Number of Views
Trending Articles
How to manipulate imported RSA SecurID Software Token(s) on an iPhone or iPad device Reporting on RSA Authentication Manager 8.x users with On-Demand Token, a fixed passcode or a hardware/software token assi… How to Download OTP Token Seed Files from myRSA Anomalix idGenius - SAML Relying Party Configuration - RSA Ready Implementation Guide RSA MFA Agent 2.5 for Microsoft Windows Installation and Administration Guide