05WS PAS Install Authentication Methods
05WS PAS Install Authentication Methods
AUTHENTICATION METHODS
CyberArk Training
1
OBJECTIVES
By the end of this session you will be able to:
• Describe the various authentication methods supported by CyberArk
• Describe how to configure and combine two different authentication methods to achieve 2 factor
authentication.
2
SUPPORTED AUTHENTICATION METHODS
3 3
SUPPORTED AUTHENTICATION METHODS
4 4
SUPPORTED AUTHENTICATION METHODS
5
PVWA AUTHENTICATION
6
AUTHENTICATION CATEGORIES
CyberArk Authentication • The PVWA sends details to the Vault, which performs the authentication.
Vault Integrated • The PVWA sends the credentials to the Vault, which in turn which in turn
External Authentication forwards the request to the external authentication servers.
• The PVWA sends the credentials to the server’s IIS service. IIS forwards the
IIS Integrated
request to the external authenticating server, and confirms authentication to
External Authentication the PVWA web application, which confirms authentication to the vault.
7
CYBERARK AUTHENTICATION FLOW
1 4
PVWA
2 App 3
End User
PVWA IIS Vault
Browser
Server
8 8
VAULT INTEGRATED AUTHENTICATION FLOW
3 6
1 5
PVWA
2 App 4
End User External
PVWA IIS Vault Authentication
Browser
Server Server
9
IIS INTEGRATED AUTHENTICATION FLOW
6
1 7 5
PVWA
App
3 External
End User 2 PVWA IIS Vault Authentication
Browser
Server Server
10
CYBERARK AUTHENTICATION
11
CYBERARK AUTHENTICATION
12
CYBERARK AUTHENTICATION
• Passparm.ini is stored
locally on the Vault server
and uploaded to the
System safe automatically
13
CYBERARK AUTHENTICATION
• Authentication method:
Password means
CyberArk authentication
14
CYBERARK AUTHENTICATION
• Enable “CyberArk”
authentication in the
PVWA as shown
15
LDAP AUTHENTICATION
16
LDAP AUTHENTICATION
17
CONFIGURATION
18
CONFIGURATION
19
CONFIGURATION
3. Enable “LDAP”
Authentication in the
PVWA
20
RADIUS AUTHENTICATION
21
RADIUS AUTHENTICATION
• Remote Authentication
Dial-In User Service
(RADIUS) is a networking
protocol that provides
centralized authentication,
Authorization and
Accounting (AAA).
• The Vault allows users to
log on through RADIUS
authentication using logon
credentials that are stored
in the RADIUS server. The
Vault also supports
RADIUS challenge-
response authentication if
enabled by the RADIUS
Administrator.
22
CONFIGURATION (1)
23
CONFIGURATION (2)
24
CONFIGURATION (3)
25
CONFIGURATION (4)
26
WINDOWS AUTHENTICATION
27
WINDOWS AUTHENTICATION
• In Windows
authentication, the client
browser sends a strongly
hashed version of the
password in a
cryptographic exchange to
the web server.
• In CyberArk, Windows
Authentication allows a
Single Sign On solution for
PVWA by authenticating to
the vault via the user’s
Windows credentials.
28
CONFIGURATION (2)
1. Enable “Windows”
authentication in the
PVWA
29
CONFIGURATION (3)
1. Enable “Windows”
authentication in the
PVWA
30
PKI AUTHENTICATION
31
PKI CONFIGURATION
32
PKI CONFIGURATION
33
PKI CONFIGURATION
3. Enable “PKI”
authentication in the When “UseVaultAuthentication” is set to NO,
the authentication method set for the user in
PVWA
the vault is ignored
34
RSA SECURID
ORACLE SSO
SAML
GOOGLE AUTH
AMAZON COGNITO
35
RSA SECURID
Prerequisites:
36
ORACLE SSO
Prerequisites:
37
SAML
Prerequisites:
• Configure SAML authentication in IIS.
• Enable SAML authentication in PVWA.
38
GOOGLE AUTHENTICATION
Prerequisites:
39
AMAZON COGNITO AUTHENTICATION
40
TWO FACTOR AUTHENTICATION
(2FA)
41
TWO FACTOR AUTHENTICATION
• Two-factor authentication (also known as 2FA) is a method of confirming a user's claimed identity
by utilizing a combination of two different components (something a user knows; and something a
user has).
• Using two-factor authentication enables you to mitigate common credential theft techniques, such as
basic key loggers or more advanced attack tools that are capable of harvesting plaintext passwords.
• CyberArk recommends that customers deploy two-factor authentication to the CyberArk Digital Vault,
preferably over RADIUS protocol.
42
USING 2FA IN CYBERARK
• In the PVWA you can combine ONE PVWA method with ONE Vault Method to create a multi-factor
authentication, as shown in the table.
IIS Vault
PKI (certificate) LDAP (password)
Windows (password) RADIUS (token)
RSA (token) CyberArk (password)
• RADIUS and RSA secureID can provide native 2FA without having to combine two authentication
methods
43
EXAMPLE: PKI + LDAP (1)
Configure PKI as primary authentication method and LDAP as secondary authentication method
44
EXAMPLE: PKI + LDAP
45
EXAMPLE: PKI + LDAP (3)
46
EXAMPLE: PKI + LDAP (4)
47
SUMMARY
48
SUMMARY
49
QUIZ
1. How can I enable 2 factor authentication with CyberArk?
• Enable RADIUS. RADIUS is inherently 2 factor and is the only way to achieve 2 factor integration with PSMP.
• Combine a PVWA level authentication method with a Vault level authentication method, e.g., PKI + LDAP
2. What is the difference between Vault authentication and Vault Integrated authentication methods?
• With Vault authentication, the Digital Vault is the authenticating server.
• With Vault Integrated authentication, the Digital Vault sends the authentication request to the authenticating authority, such as a RADIUS
or LDAP server.
3. The RADIUS Administrator will define the Digital Vault Server as a RADIUS Client and assign a RADIUS Secret. How can
we provide the Digital Vault the RADIUS Secret to use to establish a secure connection to the RADIUS Server?
• A Vault Administrator must save the RADIUS Secret to an encrypted file on the Digital Vault, using the CAVaultManager utility, and
reference the encrypted file in the DBPARM.INI file.
4. I want my users to login using their digital certificates. How do I enable PKI and configure it as the default authentication
method?
• In the PVWA, navigate to Administration > Configuration Options > Options > Authentication Methods > PKI. Set the parameter Enabled =
Yes.
• In the PVWA, navigate to Administration > Configuration Options > Options > Authentication Methods > GeneralSettings. Set the
parameter DefaultMethod = pki (case sensitive).
50
THANK YOU
51