Symantec Access Management

  • 1.  Multi Factor authentication with CA SSO

    Posted Jan 30, 2017 06:48 AM

    Hi!

     

    Just wanted to know if multi factor authentication is available in a recent version of CA SSO. I am aware of AuthMinder which can be integrated for MFA, but wondering if there is a possibility to do this with CA SSO or any upcoming versions?

     

    Ive read that we can build custom schemes that support strong authentication, is there any such custom scheme that is readily available to be used or it is something that we need to build ?

     

    Thanks,

    Lalitha



  • 2.  Re: Multi Factor authentication with CA SSO

    Broadcom Employee
    Posted Jan 30, 2017 09:08 AM

    Moved to CA SSO for an answer. This has nothing to do with APM



  • 3.  Re: Multi Factor authentication with CA SSO
    Best Answer

    Posted Jan 30, 2017 09:30 PM

    Yes, Multi factor authentication isn't available OOTB.

    It is however achievable using custom authentication scheme. 

    There is no sample available for it.

     

    If you need help in implementation multi factor authentication , you can reach out to CA Services who specialises in developing custom solution.

     

    Cheers,

    Ujwol

    Ujwol's Single Sign-On Blog 



  • 4.  Re: Multi Factor authentication with CA SSO

    Posted Feb 02, 2017 05:01 PM

    Actually, it depends on what kind of multi-factor you want. CA SSO has always supported several strong authentication/multi-factor authentication mechanisms:

       X.509 Client Certificate Plus Forms,

       SecureID

       SafeCard

     

    If by "multi-factor", you mean HTLM Forms plus One-Time-Password, then the answer is no, it is not currently supported by SiteMinder as a built-in-feature.

     

    Someone submitted a OTP solution to the CA Experts forum recently, but I don't think that forum is open to the public, so you would probably have to get someone at CA to make it available to you. Also, it is not supported by CA so it would be up to you to implement it without support. But here is the link: https://communities.ca.com/docs/DOC-231171278?et=watches.email.document

     

    In the past the CA Services Global Deployment team has offered an extra-cost pre-built PWP that implemented OTP, but it is not currently available as a standard offering. CA Services Global Deployment is the team that Ujwol referred to above. We develop tailored solutions for customers and also offer some standard solutions.

     

    CA SSO does provide a publicly available software development kit that includes an API that can be used to develop tailored authentication schemes that plug into the CA SSO policy server. The SDK kit includes a sample auth scheme, but the sample does not do OTP or any kind of multi-factor/strong authentication. Also, it takes a fairly advanced JAVA or C++ developer who has extensive CA SSO experience, or is willing to do very detailed study of the CA SSO documentation, to develop an authentication scheme.

     

    If you describe exactly what features you are looking for in a multi-factor authentication mechanism then a more specific response could be provided to you.

     

    Rick