11-28-2016 12:05 PM
Currently we are using Jabber iPhone/Android/Windows with MRA. Is there any way (or future plans) to support Two-Factor Authentication? Specifically I would like to use either DUO or even certificate based authentication in addition to the LDAP credentials. Our company is implementing a policy where all external applications must require Two-Factor authentication. If there will be no support for this we have no choice but to disable the product/feature company wide.
Solved! Go to Solution.
11-28-2016 12:13 PM
Adam
Yes cert based auth is supported by Cisco/Jabber. IDP can be setup for two factor/biometrics/whatever you need. MRA support for cert based auth is not there yet but is coming in the next few weeks with x8.9
11-28-2016 12:13 PM
Adam
Yes cert based auth is supported by Cisco/Jabber. IDP can be setup for two factor/biometrics/whatever you need. MRA support for cert based auth is not there yet but is coming in the next few weeks with x8.9
11-28-2016 01:16 PM
Thanks Srinivasan.
Currently I am doing SSO using ADFS 3.0 as the IDP for authentication of internal Jabber users. It looks like I should be able to integrate DUO two factor with ADFS. If that's the case, I believe enabling SSO on the collab-edge/MRA should do the trick, correct?
11-28-2016 01:20 PM
If you decide cert based authentication for MRA, you will need to setup a second expressway pair for IP endpoints such as phone and Telepresence endpoints.
Sent from my mobile.
Marcus Casimir | Sr. Collaboration Solutions Architect
Presidio | www.presidio.com<http://www.presidio.com>
One Penn Plaza Suite 2832, New York, NY 10119
D: 212.324.4317 | mcasimir@presidio.com<mailto:mcasimir@presidio.com>
11-28-2016 01:23 PM
Thanks Marcus.
Do you know if I will be able to user cert auth for devices such as a 8800 phones? Or its for Jabber online?
11-28-2016 01:28 PM
Cert based authentication, once turned on for that expressway pair can only facilitate Jabber clients.
Sent from my mobile.
Marcus Casimir | Sr. Collaboration Solutions Architect
Presidio | www.presidio.com<http://www.presidio.com>
One Penn Plaza Suite 2832, New York, NY 10119
D: 212.324.4317 | mcasimir@presidio.com<mailto:mcasimir@presidio.com>
11-28-2016 01:36 PM
Marcus
Where do you see the requirement for a separate expressway pair needed for this? x8.9 docs are not out yet and I don't see anything like that mentioned in the alpha docs.
kroarty Can you please comment on this?
11-28-2016 01:39 PM
Kevin will chime in. The docs have not been updated yet.
Sent from my mobile.
Marcus Casimir | Sr. Collaboration Solutions Architect
Presidio | www.presidio.com<http://www.presidio.com>
One Penn Plaza Suite 2832, New York, NY 10119
D: 212.324.4317 | mcasimir@presidio.com<mailto:mcasimir@presidio.com>
11-28-2016 02:00 PM
Marcus
The statement that you need separate expressway pair is not completely accurate. If you use exclusive mode only then it is dedicated for Jabber. If you set it to On then you can do both cert based auth with IDP and support Phones/TP endpoints
This is confirmed with internal docs
11-28-2016 02:41 PM
Right, it's the usage of SSO Exclusive mode that would require another Expressway pair for non SSO MRA clients.
The new option in X8.9 to allow iOS devices to use safari for MRA authentication with the IdP can be used with SSO = ON or Exclusive.
11-28-2016 02:52 PM
Yes, the exclusive mode is where the expressway pair will only authenticate devices through SSO. The normal username and password will not work. This feature is mainly used to prevent anyone from downloading the jabber client and trying to authenticate by brute force or compromised credentials.
Sent from my mobile.
Marcus Casimir | Sr. Collaboration Solutions Architect
Presidio | www.presidio.com<http://www.presidio.com>
One Penn Plaza Suite 2832, New York, NY 10119
D: 212.324.4317 | mcasimir@presidio.com<mailto:mcasimir@presidio.com>
11-28-2016 03:01 PM
i don't think that's the sole motivation for this feature. It's also for customers who didn't want to be annoyed with form based auth and using cert helps and to add to that it was needed specifically on iOS because safari is the only way to access the key chain store and jabber used the web view kit which didn't have access to the trust store on iOS
MDM policy can prevent access to jabber as an example however capability to enforce role based access without MDM is still on the roadmap.
11-28-2016 04:04 PM
Disregarding certificate authentication for a minute... If I enable SSO for MRA and point it to my IDP (ADFS 3.0 integrated with Duo). This should allow me to enable two-factor authentication today, correct?
11-28-2016 04:07 PM
Right that's my understanding too 11.5 is only needed for cert based auth
Thanks
Srini
12-27-2023 05:06 AM
Hello Adam,
Have you implemnented the MFA or certificate based login ?
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide