
AshrafHabashy (Customer) asked a question.
Salesforce now requires MFA validation for all SSO users. Please read the advisory below for further information on required actions to avoid login failures.
Read the Advisory
AshrafHabashy (Customer) asked a question.

Ashraf: You will need to upgrade your Linux MFA agent to version 9.0 or newer. All currently supported versions of the PAM/Linux agent support RHEL 8.10. We keep an updated list of supported operating systems at this link: https://community.rsa.com/s/article/RSA-MFA-Agent-for-UNIX-Platform-Support-Matrix

Thanks david for your support .Sure, I will install the latest RSA Agent. My concern was to ensure that authentication remains unchanged so that our clients’ access through RSA is not disrupted during the process, after which I will proceed with the upgrade.
I am actually not certain about the best practice: should we upgrade the existing agent before the OS upgrade, or remove the current agent, perform the OS upgrade, and then install the latest RSA Agent MFA afterward?

The 7.1.x PAM agent was never qualified to run on RHEL 8. The current 9.x Linux/PAM MFA agent works on RHEL 7.9. Therefore it would make sense to upgrade the agent before upgrading the OS. However there is more to consider here. The 7.x agent used UDP/sdconf.rec only. The 8.x agent would do either UDP/sdconf.rec or the newer REST API authentication. But the 9.x agent supports REST API only. So even if you upgrade the agent, you would still have to reconfigure it.

I have experience performing a double upgrade from version 7.1 to 8.1.3 and then to 9.0.1 on RHEL OS 8.10, using the package provided by RSA.
I would also like to highlight that, although your said “The 7.1.x PAM agent was never qualified to run on RHEL 8”, in our environment it was running successfully on a RHEL 7.9 VM, which is the VM where I carried out the agent upgrade

@AshrafHabashy (Customer) ,
Although you may have successfully authenticated using the 7.1 agent on RHEL 8, that combination was never qualified as a supported configuration.
If an issue were determined to result from that unsupported configuration, CE would not develop a fix for it. Instead, we would ask you to reproduce the issue using a supported agent and operating system combination before proceeding with further investigation.
A configuration that appears to work is not necessarily a supported configuration. Successful authentication alone does not establish compatibility or support.
In addition, support for the Authentication Agent for PAM 7.x ended so long ago, it is no longer listed on our end of product support page. the recommendation is to download and configure the MFA Agent for UNIX (formerly the MFA Agent for PAM). Installing the agent on a workstation in dev or prod will not impact any other agents that you have installed so you should be able to complete a full testing cycle in dev before moving to production.
ETA: Any supported version of an agent listed on the end of product support page is compatible with any version of Authentication Manager listed on the same page. The same is true of any supported operating systems related to use of the product as listed in their Setup and Configuration Guides or the Installation and Administration Guide.
Ashraf: You will need to upgrade your Linux MFA agent to version 9.0 or newer. All currently supported versions of the PAM/Linux agent support RHEL 8.10. We keep an updated list of supported operating systems at this link: https://community.rsa.com/s/article/RSA-MFA-Agent-for-UNIX-Platform-Support-Matrix