Using Cisco DUO for Multifactor Authentication for CTE GuardPoints
Integration with Cisco DUO requires creating an OIDC connection in CipherTrust Manager, after creating a DUO account.
On the DUO platform:
- 
Login to your Cisco DUO account as an admin and click Users in the left navbar to create/add one or more users. 
- 
While creating a user, set the Status as Active 
- 
Click Applications in the left navbar. 
- 
Click Protect an Application. 
- 
In the search field, type Web SDK. 
- 
In the Web SDK field, click Protect. 
- 
In the application created, note the values for: - 
Client ID 
- 
Client Secret 
- 
API hostname 
 Note https:// is the value for the URL of the OIDC Provider. 
- 
Create an OIDC Connection with CipherTrust Manager
- 
Log on to the CipherTrust Manager GUI as an administrator. 
- 
In the left pane, click Access Management > Connections. 
- 
In the Connections, click Add Connection. 
- 
Click OIDC and then click Next. 
- 
Provide a name for the connection and click Next. 
- 
Enter values for the configuration information. Note Refer to your Multifactor Authentication provider profile for the values: - URL of OIDC provider:
 - For KeyCloak, select the URL of the OIDC provider
 - 
For Thales SafeNet Trusted Access, select Well Known Configuration URL 
- 
For all other providers, select the URL of the OIDC provider 
 - 
Client-ID as configured for the OIDC client 
- 
Client-Secret as shown for the OIDC client 
 
- 
Click Next and in the Add Products window, select CTE for product. 
- 
Click Add Connection.