Using Cisco DUO for Multifactor Authentication for CTE GuardPoints
Integration with Cisco DUO requires creating an OIDC connection in CipherTrust Manager, after creating a DUO account.
On the DUO platform:
-
Login to your Cisco DUO account as an admin and click Users in the left navbar to create/add one or more users.
-
While creating a user, set the Status as Active
-
Click Applications in the left navbar.
-
Click Protect an Application.
-
In the search field, type Web SDK.
-
In the Web SDK field, click Protect.
-
In the application created, note the values for:
-
Client ID
-
Client Secret
-
API hostname
Note
https://
is the value for the URL of the OIDC Provider. -
Create an OIDC Connection with CipherTrust Manager
-
Log on to the CipherTrust Manager GUI as an administrator.
-
In the left pane, click Access Management > Connections.
-
In the Connections, click Add Connection.
-
Click OIDC and then click Next.
-
Provide a name for the connection and click Next.
-
Enter values for the configuration information.
Note
Refer to your Multifactor Authentication provider profile for the values:
- URL of OIDC provider:
- For KeyCloak, select the URL of the OIDC provider
-
For Thales Safenet Trusted Access, select Well Known Configuration URL
-
For all other providers, select the URL of the OIDC provider
-
Client-ID as configured for the OIDC client
-
Client-Secret as shown for the OIDC client
-
Click Next and in the Add Products window, select CTE for product.
-
Click Add Connection.