Using STA for Multifactor Authentication for CTE GuardPoints
Prerequisites
-
Have a CipherTrust Manager set up with:
-
Integrate with Safenet Trusted Access by creating and managing your access controls in Safenet Trusted Access.
Selecting the Proper Template
Make sure that, in Safenet Trusted Access, you choose the custom template: CTE_OIDC.
If the CTE_OIDC template is not available in your account:
-
Create an app using the Generic Template.
-
For the Integration Protocol, select OIDC.
-
Configure VALID REDIRECT URL as: http://127.0.0.1:5560/auth/callback.
Port 5560 is the default CTE OIDC login port. If the CTE admin changes it through the
voradmin mfa
command, you must chang that value in the redirect URL.
Create an OIDC Connection with CipherTrust Manager
-
Log on to the CipherTrust Manager GUI as an administrator.
-
In the left pane, click Access Management > Connections.
-
In the Connections, click Add Connection.
-
Click OIDC and then click Next.
-
Provide a name for the connection and click Next.
-
Enter values for the configuration information.
Refer to your Multifactor Authentication provider profile for the values:
-
URL of OIDC provider:
-
For Thales Safenet Trusted Access, select Well Known Configuration URL
-
For other providers, select the URL of the OIDC provider
-
-
Client ID
-
Client Secret
-
-
Click Next and in the Add Products window, select CTE for product.
-
Click Add Connection.
Next, Enable Multifactor Authentication
For more on the Safenet Trusted Access OIDC template, see OIDC applications.