- Enable OS authentication only: select this option to enable authentication to users configured on the LiveWire operating system.
- Enable third-party authentication: select this option to
enable authentication to users configured on a third-party system. When
selected, a list of authentication servers appears. Select Insert to add a new authentication server or select edit icon next to an existing third-party authentication configuration to edit the settings. Enter the following information:
- Name: enter the name of the authentication server.
- Type: select the type of authentication
server. The type can be Active Directory, Kerberos,
RADIUS, or TACACS+. Depending on the server type,
the following fields appear:Active Directory - Capture Engine (Windows)
- Server address/hostname: enter
the IP address or FQDN with ports of the Active
Directory server.Attention: You must enter this field and the field cannot contain special characters.
- Protocol: select the protocol used for authentication. The protocol can be LDAP, LDAP + SSL, or LDAP + TLS.
- Host CA certificate: this field only appears when the protocol is LDAP + SSL or LDAP + TLS. Drag and drop the host CA certificate bundle or select Upload certificate file.
- Base DN: enter the LDAP base distinguished name.
- Application username: enter the username that will be used by the application to authenticate against the directory service.
- Application password: enter the password that will be used by the application to authenticate against the directory service.
- Follow referrals: select this checkbox to allow clients to automatically follow URLs to retrieve complete results when the LDAP server does not contain the requested data.
- Select Test connection to test the connection with the LDAP server
- Select Test user to test the application username and password with the LDAP server.
Kerberos - Capture Engine (Linux)- Realm: enter the domain of the
Kerberos realm.Attention: You must enter this field and the field cannot contain special characters.
- KDC: enter the domain of the
Kerberos Key Distribution Center.Attention: You must enter this field and the field cannot contain special characters.
RADIUS- Host: enter the IP address or FQDN with ports of the RADIUS server.
- Port: enter the port that will be used to authenticate against the RADIUS server. The default value is 1812
- Secret: enter the shared secret used to encrypt and decrypt packets between the client and the RADIUS server.
TACACS+- Host: enter the IP address or FQDN with ports of the TACACS+ server
- Port: enter the port that will be used to authenticate against the RADIUS server. The default value is 49
- Secret: enter the shared secret used to encrypt and decrypt packets between the client and the TACACS+ server.
- Select Test user to test the connection with the TACACS+ server.
- Server address/hostname: enter
the IP address or FQDN with ports of the Active
Directory server.
Select the delete icon to delete the third-party authenticator or select the arrow icons to change the ordering of authenticators
Note: The order of the authentication settings in the list determines the order an authentication server is authenticated against.Authentication settings are attempted in groups in a top/down order. For example, if the first setting at the top is a RADIUS setting, then all RADIUS settings in the list are attempted first before attempting the next group type in list. If an authentication server can not be reached because of either an incorrect or unreachable server IP, incorrect port, or incorrect shared secret, then the next setting in the group is attempted. If communication with the authentication server is good, but the user cannot be authenticated because of either an incorrect username, password, or a disabled account, then the next group type is attempted (if authenticating a RADIUS or TACACS+ setting), or the next setting in the list is attempted (if authenticating an Active Directory setting).
Note: The Capture Engine operates within the security environment configured in the operating system. Refer to your operating system documentation for instructions on configuring security settings for your operating system. - Enable Single Sign On: select this option to enable
Single Sign On authentication with a third-party provider using SAML2. When
selected, enter the following information:
Identity provider settings
In this section, enter the information related to the identity provider. This can be found within your IDP or within the IDP metadata XML file.Note: You can synchronize IDP settings via the Engine Configuration Sync and Grid when synchronizing Engine Settings.- Entity ID: enter the unique identifier
EntityIDof the identity provider. - Login URL: enter the sign in URL of the identity provider.
- Logout URL: enter the logout URL of the identity provider.
- x509 certificate: enter the contents of the x509 certificate.
- LiveWire group key attribute: enter the name
of the attribute which the IDP must send that contains a list of
groups the user is part of. This field is case-sensitive and only
used when LiveWire ACL is enabled.
For example, if a user is a part of multiple groups “lw_admin”, “offline_access”, and “manage-account”, the IDP would send those groups within that attribute. This allows administrators to name the group key attribute however they want, similar to LiveNX. These groups are then used to define what privileges the SSO user has on LiveWire.
Service provider settings
In this section, enter the information related to the service provider. This can be found within the IDP metadata XML file.- Entity ID: enter the URI of the LiveWire which will be the client entry on the IDP. This must match exactly what is configured on the IDP.
- ACS URL: the external login URL that will be used by the IDP. This field is not configurable through the LiveWire UI.
- SLS URL: the redirected logout URL that you will be redirected to when you log out of the IDP. This field is not configurable through the LiveWire UI.
- Entity ID: enter the unique identifier
- Enable two-factor authentication: select this option to enable two-factor authentication.
- Authentication group secret: the Authentication Group Secret that is used for remote capture engines and LiveWire group engines. Click Generate to generate a new random 32 character Authentication Group Secret, or enter a 32 to 64 character group secret manually (do not click Generate if you enter a group secret manually). All RCEs that you want to communicate with this Capture Engine must use the Authentication Group Secret configured here.
- Send audit log messages to syslog: select this option to send audit log messages to a remote syslog server. When selected, enter the IP address or hostname of the remote syslog server.
- Restrict origin header for web access: select this option
to restrict the origin header for web access. When selected, enter an Allow list
for the HTTP origin header. Note: You can only have one entry per line and a maximum of 32 entries.
Under Security, enter the following information: