<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity Awareness with RSA SecurID in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-with-RSA-SecurID/m-p/181508#M33220</link>
    <description>&lt;P&gt;Pretty sure Captive Portal does not support this authentication flow.&lt;BR /&gt;As such, it would be an&amp;nbsp;RFE that would need to be discussed with your local Check Point office.&lt;/P&gt;
&lt;P&gt;However, it appears SecurID supports SAML per&amp;nbsp;&lt;A href="https://community.rsa.com/t5/securid-cloud-authentication/saml-applications-idr/ta-p/623025" target="_blank"&gt;https://community.rsa.com/t5/securid-cloud-authentication/saml-applications-idr/ta-p/623025&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;We support SAML from R80.40 and above, which allows the authentication flow to happen entirely in the Identity Provider.&lt;BR /&gt;Therefore, this authentication flow should work.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 19 May 2023 20:13:41 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2023-05-19T20:13:41Z</dc:date>
    <item>
      <title>Identity Awareness with RSA SecurID</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-with-RSA-SecurID/m-p/181488#M33217</link>
      <description>&lt;P&gt;so, I've been tasked with migrating off the no longer supported Client Authentication feature to Identity Awareness.&amp;nbsp; We use RSA SecurID Tokens as part of that browser-based authentication.&lt;/P&gt;&lt;P&gt;I have it working for users that were existing Client Auth users, but I'm having issues with new employees that are authenticating for the first time.&lt;/P&gt;&lt;P&gt;The issue stems from the fact that new users have to create a unique PIN number as part of the first login process which is then combined with the RSA generated token code on future login sessions. So, when using Client Auth a new user will login with their username and the code that's generated by the RSA Token. The system then presents them with a screen that asks them to create a PIN and once that's created all future logins are username with a password of PIN + TOKEN CODE.&amp;nbsp;&amp;nbsp;Identity Awareness is treating that first login as a password failure instead of recognizing that it's a first-time login.&lt;/P&gt;&lt;P&gt;What I'm assuming is that there's some additional configuration necessary to get Identity Awareness to handle this login flow correctly, but I can't seem to find documentation on how to implement this.&amp;nbsp; Can anyone point me in the right direction to get this done?&amp;nbsp; I've asked through the normal support case, but they claim they only handle break/fix issues and not configuration assistance. I've escalated to my accounts team, but thought I'd post here in case someone has had to do this in their environment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 19 May 2023 18:26:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-with-RSA-SecurID/m-p/181488#M33217</guid>
      <dc:creator>MauriceM</dc:creator>
      <dc:date>2023-05-19T18:26:08Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness with RSA SecurID</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-with-RSA-SecurID/m-p/181508#M33220</link>
      <description>&lt;P&gt;Pretty sure Captive Portal does not support this authentication flow.&lt;BR /&gt;As such, it would be an&amp;nbsp;RFE that would need to be discussed with your local Check Point office.&lt;/P&gt;
&lt;P&gt;However, it appears SecurID supports SAML per&amp;nbsp;&lt;A href="https://community.rsa.com/t5/securid-cloud-authentication/saml-applications-idr/ta-p/623025" target="_blank"&gt;https://community.rsa.com/t5/securid-cloud-authentication/saml-applications-idr/ta-p/623025&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;We support SAML from R80.40 and above, which allows the authentication flow to happen entirely in the Identity Provider.&lt;BR /&gt;Therefore, this authentication flow should work.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 19 May 2023 20:13:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-with-RSA-SecurID/m-p/181508#M33220</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-05-19T20:13:41Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness with RSA SecurID</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-with-RSA-SecurID/m-p/181677#M33257</link>
      <description>&lt;P&gt;Appreciate the response&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;I don't think the SAML option will work for my RSA appliance, but I'll see if this can be handled via an Enhancement.&lt;/P&gt;</description>
      <pubDate>Mon, 22 May 2023 20:30:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-with-RSA-SecurID/m-p/181677#M33257</guid>
      <dc:creator>MauriceM</dc:creator>
      <dc:date>2023-05-22T20:30:14Z</dc:date>
    </item>
  </channel>
</rss>

