6.5 Configuring FIDO for Two-Factor Authentication

CloudAccess supports FIDO (Fast IDentity Online) for two-factor authentication. FIDO requires that users enter their user name and password. The second factor authentication is a dongle that users must touch to authenticate. For more information, see the FIDO Alliance website.

6.5.1 Requirements for FIDO

Ensure that your system meets the following requirements before you configure FIDO as an authentication method:

  • A CloudAccess appliance, installed and configured.

  • A FIDO supported dongle for each user.

6.5.2 Configuring the FIDO Tool

Before you configure the FIDO tool, ensure that your setup meets the requirements described in Section 6.5.1, Requirements for FIDO.

To configure the FIDO tool:

  1. Log in with an appliance administrator account to the administration console at

    https://appliance_dns_name/appliance/index.html

  2. Drag the FIDO tool from the Tools palette to the Tools panel.

  3. Read the message that there is no configuration required.

  4. Click the Applications tab, then select the check box next to one or more applications that require the specified authentication provider.

    You can enable one or more applications for the specified type of authentication provider. However, you must assign each application to only one type of authentication provider.

  5. Click OK to save the settings and enable the tool.

  6. Click Apply to activate the configuration.

  7. Wait while the service is activated across all nodes in the cluster. Do not attempt other configuration actions until the activation completes successfully.