lhs-panel Click here to expand

Smart card Authentication

If you have a smart card authentication system enabled in your environment, you can configure Log360 to authenticate users through it, bypassing other first factor authentication methods.

This feature provides an additional authentication option for Log360 login by enabling the use of smart cards/ PKI/ certificates to grant access to the tool. Smart card authentication strengthens the security further because getting access to Log360 shall then require the user to possess the smart card and know the personal identification number (PIN) as well.

When a user attempts to access Log360's web-interface, they would be allowed to proceed further only after completing smart card authentication in the machine, i.e., by presenting the smart card and subsequently entering the PIN. Log360's web-interface supplements smart card technology with SSL communication. So, the user is prompted to specify the X.509 certificate for getting access.

Users can choose to provide the certificate from the smart card or the local certificate store, in which case Log360 performs the steps to authenticate the user with the certificate. The users can also choose to decline providing the certificate and the tool takes them to the usual login page for authentication.

Steps to configure smart card authentication settings:

  • Click the Admin tab.
  • SSL port must be enabled for configuring smart card authentication settings. To check your SSL port settings, click Product Settings provided under General Settings. If not enabled already, select the radio button against HTTPS, and specify the port number in the field. Click Save.
  • Navigate to Admin → Administration → Logon Settings → Smart Card Authentication.
  • In the Import CA Root Certification field, click Browse and import the required Certification Authority root certification file from your computer. Connect to http://CertificateAuthorityServerName/certsrv/ to download CA root certification.
  • In the Mapping Attribute in Certificate field, specify the certificate attribute for mapping. The user details need to be mapped between the smart card certificate and the Log360 database. This denotes that the attribute in the smart card certificate that uniquely identifies the user should match with the corresponding value in the Log360 user database. This mapping involves specifying which attribute in certificate should be taken up for comparison with which attribute in Log360 user store. Log360 provides the flexibility to specify any attribute of the smart card certificate that you feel uniquely identifies the user in your environment. You may choose any attribute among SAN.OtherName, SAN.RFC822Name, SAN.DirName, SAN.DNSName, SAN.URI, email, distinguishedName and CommonName. In case if any other attribute is used to uniquely identify the user in your environment, contact Log360 support to add that attribute.
  • In the Mapping Attribute in AD field, specify the LDAP attribute that should be matched with the specified certificate attribute. Here you need to specify the particular LDAP attribute that uniquely identifies the user in Log360 user store, e.g., sAMAccountName. During authentication, Log360 reads the value corresponding to the certificate attribute that you specified in Mapping Attribute in Certificate and compares it with the specified LDAP attribute in Mapping Attribute in AD.
  • In the Linked Domains field, select the appropriate domains from the drop down menu.
  • Click the arrow sign next to the section OCSP Settings to expand the menu. During authentication, Log360 checks for certificate revocation status against an Online Certificate Status Protocol (OCSP) server, with details available in the certificate. If the certificate does not have the OCSP information, the information provided in the settings here will be used.
    • In the OCSP Server Name field, specify the name of the OCSP server.
    • In the OCSP Server Port filed, mention the OCSP server port number.
  • Click Save.

After you have added a smartcard for authentication, you can perform any of the following functions:

  • Add a new smartcard
  • Edit a configured smartcard
  • Enable/Disable a smartcard
  • Delete a configured smartcard

Add a new smartcard

To add a new smartcard, follow the steps given below:

  • Navigate to Admin → Administration → Logon Settings → Smart Card Authentication.
  • Click the Add a New Smartcard button at the top-right corner of the screen.
  • Enter all details required and click Save

Edit a configured smartcard

To edit a configured smartcard, follow the steps given below:

  • Navigate to Admin → Administration → Logon Settings → Smart Card Authentication.
  • Click the corresponding to the smartcard whose configuration you wish to edit.
  • Modify the settings you wish to change.
  • Click Save

Enable/Disable a smartcard

  • Navigate to Admin → Administration → Logon Settings → Smart Card Authentication.
  • To enable/disable a configured smartcard, click on the / icon located in the action column of the particular smartcard.

Delete a configured smartcard

  • Navigate to Admin → Administration → Logon Settings → Smart Card Authentication.
  • Click the corresponding to the smartcard which you wish to delete.
  • Click Yes to confirm the deletion.

Copyright © 2020, ZOHO Corp. All Rights Reserved.

Get download link