{"id":622,"date":"2018-09-07T13:04:34","date_gmt":"2018-09-07T08:34:34","guid":{"rendered":"http:\/\/www.enhisecure.com\/isecureblog\/?p=622"},"modified":"2019-05-21T12:33:39","modified_gmt":"2019-05-21T08:03:39","slug":"integrating-cyberarks-pas-solution-with-duos-2fa","status":"publish","type":"post","link":"https:\/\/www.enhisecure.com\/isecureblog\/2018\/09\/07\/integrating-cyberarks-pas-solution-with-duos-2fa\/","title":{"rendered":"Integrating CyberArk&#8217;s PAS Solution With DUO&#8217;s 2FA"},"content":{"rendered":"<p><a href=\"https:\/\/www.cyberark.com\/products\/privileged-account-security-solution\/\">CyberArk&#8217;s PAS<\/a> solution uses the Password Vault Web Access System which provides the method by which users request passwords and high-level administrators approve the requests. Access to this system should be as secure as possible. Integrating with a multi-factor authentication system like <a href=\"https:\/\/duo.com\/\">Duo<\/a> would make the login process more secure by authenticating the user based on <a href=\"https:\/\/en.wikipedia.org\/wiki\/Lightweight_Directory_Access_Protocol\">LDAP<\/a> password as well as the response received by the <a href=\"https:\/\/duo.com\/docs\/authproxy-overview\">Duo Authentication Proxy<\/a> using <a href=\"https:\/\/duo.com\/product\/trusted-users\/two-factor-authentication\/authentication-methods\/duo-push\">Duo Push<\/a> setup on the user&#8217;s mobile device.<\/p>\n<p>In the current demo, an LDAP user with the name &#8220;testuser&#8221; is created on the Active Directory Domain Controller as well as the DUO instance.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-623 aligncenter\" src=\"http:\/\/www.enhisecure.com\/isecureblog\/wp-content\/uploads\/2018\/09\/duopage-300x116.png\" alt=\"\" width=\"466\" height=\"180\" srcset=\"https:\/\/www.enhisecure.com\/isecureblog\/wp-content\/uploads\/2018\/09\/duopage-300x116.png 300w, https:\/\/www.enhisecure.com\/isecureblog\/wp-content\/uploads\/2018\/09\/duopage-1024x395.png 1024w, https:\/\/www.enhisecure.com\/isecureblog\/wp-content\/uploads\/2018\/09\/duopage.png 1101w\" sizes=\"auto, (max-width: 466px) 100vw, 466px\" \/><\/p>\n<p>Once the accounts have been created, the DUO Authentication Proxy is setup and is configured as the primary LDAP host for authentication.<\/p>\n<p>The Duo Authentication Proxy is a service that runs either on <a href=\"https:\/\/www.microsoft.com\/en-in\/windows\">Windows<\/a> or <a href=\"https:\/\/www.linux.org\/\">Linux<\/a>. It is configured by using the file authproxy<em>.cfg\u00a0<\/em><\/p>\n<p>The details of the Duo instance and the details of the LDAP server which is being used for\u00a0primary authentication are configured in authproxy.cfg<\/p>\n<p>The <a href=\"https:\/\/en.wikipedia.org\/wiki\/Firewall_(computing)\">firewall<\/a> must allow outbound traffic to the Duo instance using <a href=\"https:\/\/en.wikipedia.org\/wiki\/HTTPS\">HTTPS<\/a>.<\/p>\n<p>Only on successful primary and secondary authentication, access to the PVWA is granted.<\/p>\n<p><iframe loading=\"lazy\" title=\"ENH iSecure Cyberark 2FA using DUOS\" width=\"640\" height=\"360\" src=\"https:\/\/www.youtube.com\/embed\/tkX9Kq53lw0?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe><\/p>\n","protected":false},"excerpt":{"rendered":"<p>CyberArk&#8217;s PAS solution uses the Password Vault Web Access System which provides the method by which users request passwords and high-level administrators approve the requests. Access to this system should be as secure as possible. Integrating with a multi-factor authentication system like Duo would make the login process more secure by authenticating the user based [&hellip;]<\/p>\n","protected":false},"author":9,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"image","meta":{"footnotes":""},"categories":[18,8,16],"tags":[84,87],"class_list":["post-622","post","type-post","status-publish","format-image","hentry","category-cyberark","category-identity-governance","category-technology","tag-cyberark","tag-two-factor-authentication","post_format-post-format-image"],"_links":{"self":[{"href":"https:\/\/www.enhisecure.com\/isecureblog\/wp-json\/wp\/v2\/posts\/622","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.enhisecure.com\/isecureblog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.enhisecure.com\/isecureblog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.enhisecure.com\/isecureblog\/wp-json\/wp\/v2\/users\/9"}],"replies":[{"embeddable":true,"href":"https:\/\/www.enhisecure.com\/isecureblog\/wp-json\/wp\/v2\/comments?post=622"}],"version-history":[{"count":7,"href":"https:\/\/www.enhisecure.com\/isecureblog\/wp-json\/wp\/v2\/posts\/622\/revisions"}],"predecessor-version":[{"id":643,"href":"https:\/\/www.enhisecure.com\/isecureblog\/wp-json\/wp\/v2\/posts\/622\/revisions\/643"}],"wp:attachment":[{"href":"https:\/\/www.enhisecure.com\/isecureblog\/wp-json\/wp\/v2\/media?parent=622"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.enhisecure.com\/isecureblog\/wp-json\/wp\/v2\/categories?post=622"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.enhisecure.com\/isecureblog\/wp-json\/wp\/v2\/tags?post=622"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}