Go to the table of contents Go to the previous page Go to the next page View or print as PDF
Configuring TRITON Settings > Configuring two-factor authentication
Configuring two-factor authentication
TRITON Manager Help | Web, Data, and Email Protection Solutions | v8.2.x
Use the TRITON Settings > Two-Factor Auth page to manage the use of two-factor authentication for administrator logons.
 
Note 
Two-factor authentication requires administrators to provide 2 forms of identification when logging on to TRITON Manager.
TRITON administrators can be granted single sign-on access to other TRITON management consoles (Appliance Manager and Content Gateway Manager). To use this functionality with two-factor authentication:
*
Appliance Manager: Set up single sign-on permissions for administrator accounts (see Configuring an existing appliance for single sign-on).
*
Content Gateway Manager: Disable password authentication for Content Gateway Manager (see "Configuring Content Gateway for two-factor authentication" in the Content Gateway Help).
Access to TRITON Mobile Security is not covered by two-factor authentication: you must log on to the cloud-based console using your regular username and password.
The following methods are available:
*
*
If you choose to enable RSA SecurID authentication:
*
*
*
*
To set up TRITON Manager RSA SecurID authentication:
1.
Mark Authenticate administrators using RSA SecurID authentication.
2.
Enter a valid Username and Passcode for RSA SecurID logon.
The user must be able to authenticate with RSA Authentication Manager, but does not have to be a TRITON administrator.
3.
Click Test Connection to RSA Manager.
You must successfully test the connection to your RSA Authentication Manager before you can save your changes on this page. The results of the test are displayed next to the Test Connection button; for more information on these results, see Test Connection to RSA Manager results.
1.
Selecting this option means that any administrators configured on the TRITON Settings > Administrators page can log on using their local or network credentials as a fallback. If you do not select this option, RSA authentication is the only option for all administrators except the admin account created during installation.
2.
To set up TRITON Manager certificate authentication:
1.
Mark Authenticate administrators using client certificate authentication.
2.
To enable attribute matching, under Certificate Matching mark Use attribute matching as a fallback method and select whether it applies to all administrators, or only administrators without certificates in TRITON Manager.
To configure the attributes used for matching, click Configure Attribute Matching, then see Setting up attribute matching.
3.
When certificates are successfully imported, a success message is displayed at the top of the page. If any of the certificates are not imported correctly, you can upload a certificate for each network administrator on the TRITON Settings > Administrators > Edit Network Account page.
4.
Click Add under Root Certificates to add a root certificate for signature verification. There must be at least one root certificate in TRITON Manager for two-factor authentication to operate.
5.
6.
7.
To enable password authentication as a fallback method, mark Allow password authentication to log on to TRITON Manager and select whether it applies to all administrators, or only administrators without certificates in TRITON Manager.
 
Note 
The admin account created during installation can always log on from the TRITON Management Server machine using password-based authentication.
8.

Go to the table of contents Go to the previous page Go to the next page View or print as PDF
Configuring TRITON Settings > Configuring two-factor authentication
Copyright 2016 Forcepoint LLC. All rights reserved.