RADIUS IntegrationGuide CA SiteMinder RevC
RADIUS IntegrationGuide CA SiteMinder RevC
Revision History
Disclaimer
All information herein is either public information or is the property of and owned solely by Gemalto NV.
and/or its subsidiaries who shall have and keep the sole right to file patent applications or any other kind of
intellectual property protection in connection with such information.
Nothing herein shall be construed as implying or granting to you any rights, by license, grant or otherwise,
under any intellectual and/or industrial property rights of or concerning any of Gemalto’s information.
This document can be used for informational, non-commercial, internal and personal use only provided
that:
The copyright notice below, the confidentiality and proprietary legend and this full warning notice
appear in all copies.
This document shall not be posted on any network computer or broadcast in any media and no
modification of any part of this document shall be made.
Use for any other purpose is expressly prohibited and may result in severe civil and criminal liabilities.
The information contained in this document is provided “AS IS” without any warranty of any kind. Unless
otherwise expressly agreed in writing, Gemalto makes no warranty as to the value or accuracy of
information contained herein.
The document could include technical inaccuracies or typographical errors. Changes are periodically
added to the information herein. Furthermore, Gemalto reserves the right to make any change or
improvement in the specifications data, information, and the like described herein, at any time.
Gemalto hereby disclaims all warranties and conditions with regard to the information contained herein,
including all implied warranties of merchantability, fitness for a particular purpose, title and non-
infringement. In no event shall Gemalto be liable, whether in contract, tort or otherwise, for any indirect,
special or consequential damages or any damages whatsoever including but not limited to damages
SafeNet Authentication Service PCE/SPE and SafeNet Trusted Access(STA): Integration Guide 2
Using RADIUS Protocol for CA SiteMinder
007-012792-001, Rev. C, September 2019 Copyright © 2019 Gemalto
resulting from loss of use, data, profits, revenues, or customers, arising out of or in connection with the use
or performance of information contained in this document.
Gemalto does not and shall not warrant that this product will be resistant to all possible attacks and shall
not incur, and disclaims, any liability in this respect. Even if each product is compliant with current security
standards in force on the date of their design, security mechanisms' resistance necessarily evolves
according to the state of the art in security and notably under the emergence of new attacks. Under no
circumstances, shall Gemalto be held liable for any third party actions and in particular in case of any
successful attack against systems or equipment incorporating Gemalto products. Gemalto disclaims any
liability with respect to security for direct, indirect, incidental or consequential damages that result from any
use of its products. It is further stressed that independent testing and verification by the person using the
product is particularly encouraged, especially in any application in which defective, incorrect or insecure
functioning could result in damage to persons or property, denial of service or loss of privacy.
SafeNet Authentication Service PCE/SPE and SafeNet Trusted Access(STA): Integration Guide 3
Using RADIUS Protocol for CA SiteMinder
007-012792-001, Rev. C, September 2019 Copyright © 2019 Gemalto
Contents
CONTENTS
PREFACE ............................................................................................................................. 6
Third-Party Software Acknowledgement............................................................................................................ 6
Description ......................................................................................................................................................... 6
Applicability ........................................................................................................................................................ 6
Environment ....................................................................................................................................................... 7
RADIUS Prerequisites........................................................................................................................................ 7
Audience ............................................................................................................................................................ 7
Support Contacts ............................................................................................................................................... 7
Customer Support Portal ................................................................................................................................ 7
Telephone Support ......................................................................................................................................... 8
Email Support ................................................................................................................................................. 8
SafeNet Authentication Service PCE/SPE and SafeNet Trusted Access(STA): Integration Guide 5
Using RADIUS Protocol for CA SiteMinder
007-012792-001, Rev. C, September 2019 Copyright © 2019 Gemalto
Preface
PREFACE
Description
SafeNet Authentication Service (SAS (PCE/SPE)) and SafeNet Trusted Access (STA) delivers a fully
automated, versatile, and strong authentication-as-a-service solution.
With no infrastructure required, SAS (PCE/SPE) and STA provides smooth management processes and
highly flexible security policies, token choice, and integration APIs.
The CA SiteMinder solution is a web access management system that provides secure single sign-on and
flexible access management to applications and web services either on-premises, in the cloud, from a
mobile device, or at a partner’s site.
This document describes how to:
Deploy multi-factor authentication (MFA) options in CA SiteMinder using SafeNet one-time password
(OTP) authenticators managed by SAS (PCE/SPE) and STA.
Configure CA SiteMinder to work with SAS (PCE/SPE) and STA in RADIUS mode.
It is assumed that the CA SiteMinder environment is already configured and working with static passwords
prior to implementing the multi-factor authentication using SAS (PCE/SPE) and STA.
CA SiteMinder can be configured to support multi-factor authentication in several modes. The RADIUS
protocol will be used for the purpose of working with SAS (PCE/SPE) and STA.
Applicability
The information in this document applies to:
SafeNet Authentication Service PCE/SPE and SafeNet Trusted Access(STA): Integration Guide 6
Using RADIUS Protocol for CA SiteMinder
007-012792-001, Rev. C, September 2019 Copyright © 2019 Gemalto
Preface
Environment
The integration environment that is used in this document is based on the following software versions:
SafeNet Authentication Service – Private Cloud Edition (SAS-PCE)—only when using this version.
CA SiteMinder—Version 12.5.1
RADIUS Prerequisites
To enable SAS (PCE/SPE) and STA to receive RADIUS requests from CA SiteMinder, ensure the
following:
End users can authenticate from the CA SiteMinder with a static password before configuring the CA
SiteMinder to use RADIUS authentication.
Ports 1812/1813 are open to and from the CA SiteMinder.
A shared secret key has been selected. A shared secret key provides an added layer of security by
supplying an indirect reference to a shared secret key. It is used by a mutual agreement between the
RADIUS server and RADIUS client for encryption, decryption, and digital signatures.
Audience
This document is targeted to system administrators who are familiar with CA SiteMinder, and are
interested in adding multi-factor authentication capabilities using SAS (PCE/SPE) and STA.
Support Contacts
If you encounter a problem while installing, registering, or operating this product, refer to the
documentation. If you cannot resolve the issue, contact your supplier or Gemalto Customer Support.
Gemalto Customer Support operates 24 hours a day, 7 days a week. Your level of access to this service is
governed by the support plan arrangements made between Gemalto and your organization. Please consult
this support plan for further information about your entitlements, including the hours when telephone
support is available to you.
SafeNet Authentication Service PCE/SPE and SafeNet Trusted Access(STA): Integration Guide 7
Using RADIUS Protocol for CA SiteMinder
007-012792-001, Rev. C, September 2019 Copyright © 2019 Gemalto
Preface
support resources, including software and firmware downloads, release notes listing known problems and
workarounds, a knowledge base, FAQs, product documentation, technical notes, and more. You can also
use the portal to create and manage support cases.
NOTE: You require an account to access the Customer Support Portal. To create a
new account, go to the portal and click on the REGISTER link.
Telephone Support
If you have an urgent problem, or cannot access the Customer Support Portal, you can contact Gemalto
Customer Support by telephone at +1 410-931-7520. Additional local telephone support numbers are listed
on the support portal.
Email Support
You can also contact technical support by email at technical.support@gemalto.com.
SafeNet Authentication Service PCE/SPE and SafeNet Trusted Access(STA): Integration Guide 8
Using RADIUS Protocol for CA SiteMinder
007-012792-001, Rev. C, September 2019 Copyright © 2019 Gemalto
CHAPTER 1: Authentication Flow
SAS (PCE/SPE) and STA communicates with a large number of VPN and access-gateway solutions using
the RADIUS protocol.
The image below describes the data flow of a multi-factor authentication transaction for CA SiteMinder.
4 3
SafeNet Authentication Service PCE/SPE and SafeNet Trusted Access(STA): Integration Guide 9
Using RADIUS Protocol for CA SiteMinder
007-012792-001, Rev. C, September 2019 Copyright © 2019 Gemalto
CHAPTER 2: SAS/STA Setup
The deployment of multi-factor authentication using SAS (PCE/SPE) and STA with CA SiteMinder using
RADIUS protocol requires the following:
“Creating Users Stores”, page 10
“Assigning an Authenticator”, page 11
“Adding CA SiteMinder as an Authentication Node”, page 11
SafeNet Authentication Service PCE/SPE and SafeNet Trusted Access(STA): Integration Guide 10
Using RADIUS Protocol for CA SiteMinder
007-012792-001, Rev. C, September 2019 Copyright © 2019 Gemalto
CHAPTER 2: SAS/STA Setup
Assigning an Authenticator
SAS (PCE/SPE) and STA supports a number of authentication methods that can be used as a second
authentication factor for users who are authenticating through CA SiteMinder.
The following authenticators are supported:
eToken PASS
RB-1 Keypad Token
KT-4 Token
SMS Token
MobilePASS
SafeNet Authentication Service PCE/SPE and SafeNet Trusted Access(STA): Integration Guide 11
Using RADIUS Protocol for CA SiteMinder
007-012792-001, Rev. C, September 2019 Copyright © 2019 Gemalto
CHAPTER 2: SAS/STA Setup
SafeNet Authentication Service PCE/SPE and SafeNet Trusted Access(STA): Integration Guide 12
Using RADIUS Protocol for CA SiteMinder
007-012792-001, Rev. C, September 2019 Copyright © 2019 Gemalto
CHAPTER 3: Configuring CA SiteMinder Setup
(The screen image above is from CA Technologies. Trademarks are the property of their respective owners.)
SafeNet Authentication Service PCE/SPE and SafeNet Trusted Access(STA): Integration Guide 13
Using RADIUS Protocol for CA SiteMinder
007-012792-001, Rev. C, September 2019 Copyright © 2019 Gemalto
CHAPTER 3: Configuring CA SiteMinder Setup
(The screen image above is from CA Technologies. Trademarks are the property of their respective owners.)
(The screen image above is from CA Technologies. Trademarks are the property of their respective owners.)
3. In the lower tab row, click Authentication. In the left pane, click Authentication Schemes. The
Authentication Schemes window is displayed.
(The screen image above is from CA Technologies. Trademarks are the property of their respective owners.)
4. In the right pane, click Create Authentication Scheme. The Create Authentication Scheme window
is displayed.
SafeNet Authentication Service PCE/SPE and SafeNet Trusted Access(STA): Integration Guide 14
Using RADIUS Protocol for CA SiteMinder
007-012792-001, Rev. C, September 2019 Copyright © 2019 Gemalto
CHAPTER 3: Configuring CA SiteMinder Setup
(The screen image above is from CA Technologies. Trademarks are the property of their respective owners.)
5. Select Create a new object of type Authentication Scheme and then click OK. The Create
Authentication Scheme window is displayed.
(The screen image above is from CA Technologies. Trademarks are the property of their respective owners.)
SafeNet Authentication Service PCE/SPE and SafeNet Trusted Access(STA): Integration Guide 15
Using RADIUS Protocol for CA SiteMinder
007-012792-001, Rev. C, September 2019 Copyright © 2019 Gemalto
CHAPTER 3: Configuring CA SiteMinder Setup
7. Click Submit.
The new Authentication Scheme is added and is displayed in the list of schemes.
(The screen image above is from CA Technologies. Trademarks are the property of their respective owners.)
8. Click Close.
(The screen image above is from CA Technologies. Trademarks are the property of their respective owners.)
SafeNet Authentication Service PCE/SPE and SafeNet Trusted Access(STA): Integration Guide 16
Using RADIUS Protocol for CA SiteMinder
007-012792-001, Rev. C, September 2019 Copyright © 2019 Gemalto
CHAPTER 3: Configuring CA SiteMinder Setup
2. In the SiteMinder Administrative UI window, in the upper tab row, click Policies.
(The screen image above is from CA Technologies. Trademarks are the property of their respective owners.)
3. In the lower tab row, click Domain, and then, in the left pane, click Domains.
(The screen image above is from CA Technologies. Trademarks are the property of their respective owners.)
4. To modify your domain, under User Directories, click the pencil icon next to the domain’s name.
(The screen image above is from CA Technologies. Trademarks are the property of their respective owners.)
SafeNet Authentication Service PCE/SPE and SafeNet Trusted Access(STA): Integration Guide 17
Using RADIUS Protocol for CA SiteMinder
007-012792-001, Rev. C, September 2019 Copyright © 2019 Gemalto
CHAPTER 3: Configuring CA SiteMinder Setup
(The screen image above is from CA Technologies. Trademarks are the property of their respective owners.)
SafeNet Authentication Service PCE/SPE and SafeNet Trusted Access(STA): Integration Guide 18
Using RADIUS Protocol for CA SiteMinder
007-012792-001, Rev. C, September 2019 Copyright © 2019 Gemalto
CHAPTER 3: Configuring CA SiteMinder Setup
(The screen image above is from CA Technologies. Trademarks are the property of their respective owners.)
(The screen image above is from CA Technologies. Trademarks are the property of their respective owners.)
SafeNet Authentication Service PCE/SPE and SafeNet Trusted Access(STA): Integration Guide 19
Using RADIUS Protocol for CA SiteMinder
007-012792-001, Rev. C, September 2019 Copyright © 2019 Gemalto
CHAPTER 3: Configuring CA SiteMinder Setup
(The screen image above is from CA Technologies. Trademarks are the property of their respective owners.)
(The screen image above is from CA Technologies. Trademarks are the property of their respective owners.)
SafeNet Authentication Service PCE/SPE and SafeNet Trusted Access(STA): Integration Guide 20
Using RADIUS Protocol for CA SiteMinder
007-012792-001, Rev. C, September 2019 Copyright © 2019 Gemalto
CHAPTER 3: Configuring CA SiteMinder Setup
(The screen image above is from CA Technologies. Trademarks are the property of their respective owners.)
3. In the lower row, click Domain and then, in the left pane, click Domains.
4. Click the pencil icon next to the domain’s name to modify your domain.
(The screen image above is from CA Technologies. Trademarks are the property of their respective owners.)
5. In the lower tab row, click the Policies tab and then click the Create button.
SafeNet Authentication Service PCE/SPE and SafeNet Trusted Access(STA): Integration Guide 21
Using RADIUS Protocol for CA SiteMinder
007-012792-001, Rev. C, September 2019 Copyright © 2019 Gemalto
CHAPTER 3: Configuring CA SiteMinder Setup
6. Click the General tab. In the Name field, enter a name for the policy.
(The screen image above is from CA Technologies. Trademarks are the property of their respective owners.)
7. On the lower tab row, click the Users tab and then select the users to whom you want to apply the
policy (either by clicking Add Members and choosing specific users, or by clicking Add All, which will
add all users).
(The screen image above is from CA Technologies. Trademarks are the property of their respective owners.)
8. On the lower tab row, select the Rules tab and then, in the Rules section, click Add Rule.
SafeNet Authentication Service PCE/SPE and SafeNet Trusted Access(STA): Integration Guide 22
Using RADIUS Protocol for CA SiteMinder
007-012792-001, Rev. C, September 2019 Copyright © 2019 Gemalto
CHAPTER 3: Configuring CA SiteMinder Setup
(The screen image above is from CA Technologies. Trademarks are the property of their respective owners.)
9. In the Available Rules section, select the RADIUS rule created in the Configure a RADIUS-protected
Realm section, page 16, and then click OK.
(The screen image above is from CA Technologies. Trademarks are the property of their respective owners.)
SafeNet Authentication Service PCE/SPE and SafeNet Trusted Access(STA): Integration Guide 23
Using RADIUS Protocol for CA SiteMinder
007-012792-001, Rev. C, September 2019 Copyright © 2019 Gemalto
CHAPTER 3: Configuring CA SiteMinder Setup
(The screen image above is from CA Technologies. Trademarks are the property of their respective owners.)
SafeNet Authentication Service PCE/SPE and SafeNet Trusted Access(STA): Integration Guide 24
Using RADIUS Protocol for CA SiteMinder
007-012792-001, Rev. C, September 2019 Copyright © 2019 Gemalto
CHAPTER 4: Running the Solution
The following demonstrates how to authenticate to a website protected by CA SiteMinder using a SAS
(PCE/SPE) and STA OTP authenticator.
2. Bob enters his user name and then uses his OTP authenticator to generate an OTP, which he will
enter into the Password field.
3. After successful authentication, Bob will be redirected to the requested website or web application.
SafeNet Authentication Service PCE/SPE and SafeNet Trusted Access(STA): Integration Guide 25
Using RADIUS Protocol for CA SiteMinder
007-012792-001, Rev. C, September 2019 Copyright © 2019 Gemalto