Announcements

SecurID® Discussions

Browse the SecurID discussion board to get product help and collaborate with other SecurID users.
yannickneault
Contributor
Contributor

Security of REST API

Jump to solution

We are in the process of enabling the RSA Secure ID Authentication REST API.  Since this is a fairly new technology, we would like to get confirmation that, even without enabling HMAC for authentication agents, the communication between the client and the RSA infrastructure is encrypted? In our specific case, the client is a VMware UAG appliance that requires both the Access Key and the RSA SSL server certificate to establish connection to the RSA server.  We basically want to confirm that even without enabling HMAC for authentication agents, the network traffic will be encrypted using the provided the RSA SSL server certificate.

Reference : 

https://community.rsa.com/t5/rsa-authentication-manager/deploying-an-authentication-agent-that-uses-the-rest-protocol/ta-p/629348

https://community.rsa.com/t5/rsa-authentication-manager/generate-an-hmac-for-authentication-agents/ta-p/629349

 

Labels (1)
0 Likes
1 Solution

Accepted Solutions
EricaChalfin
Moderator Moderator
Moderator

@yannickneault,

We use the imported root certificate for authentication, not encryption. We use the certificate presented on port 5555 (if you are using Authentication Manager) for encryption or 443 (if you are using the Cloud Authentication Service).


Best regards,
Erica

View solution in original post

1 Reply
EricaChalfin
Moderator Moderator
Moderator

@yannickneault,

We use the imported root certificate for authentication, not encryption. We use the certificate presented on port 5555 (if you are using Authentication Manager) for encryption or 443 (if you are using the Cloud Authentication Service).


Best regards,
Erica