Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Daniel_Kavan
MVP Gold
MVP Gold

MFA documentation question - adding yubikey

Multiple Login Options for Security Gateways

So, in gateway - Mobile Access - Authentication and I can add a pre-built object called Cert_Username_Password.  I want to do something slightly different here (making my own replacing Certificate with a yubikey ingegration ).   Is it just a matter of making a new custom object with something different than Personal cert, username password?  While I do see "Certificate + Username password" in the display name, there is NO checkbox anywhere saying USE both of these methods in Cert_Username_Password object/template.    I'm going to use the FAFO method here. 

Daniel_Kavan_0-1768485655307.png

 

Important - As a best security practice, we recommend to configure another authentication method in addition to username and password. In the next step, click Edit and configure one or more additional authentication methods.

 

0 Kudos
6 Replies
Daniel_Kavan
MVP Gold
MVP Gold

I get an error.  😞  Identity provider authentication factor can not be used with other factors.   ;(

 

 

0 Kudos
the_rock
MVP Platinum
MVP Platinum

Hey Dan,

I can test it in my lab and see if I get the same issue. You are just trying to add what you posted in the screenshot, right?

Best,
Andy
0 Kudos
Daniel_Kavan
MVP Gold
MVP Gold

Correct, yeah it looks like a limitation on the IDP side.   We can integrate yubikey on the IDP side, so it should work out ok.   If you could confirm there is NO checkbox anywhere saying USE both of these methods that would be good to know.   on a side note, you'd think since a certificate AND yubikey are pretty similar Check Point may be able to add a yubikey option without too much additional engineering.

0 Kudos
the_rock
MVP Platinum
MVP Platinum

Will test soon.

Best,
Andy
0 Kudos
the_rock
MVP Platinum
MVP Platinum

Just tried, got the same.

Best,
Andy
0 Kudos
PhoneBoy
Admin
Admin

That's noted in the documentation: https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_RemoteAccessVPN_AdminGuide/Content...

  • SAML authentication cannot be configured with more authentication factors in the same login option. The Machine Certificate Authentication option is supported. To use Multiple Factor Authentication, configure the external Identity Provider to have multiple verification steps. The complexity and number of verification activities depends on the configuration of the Identity Provider.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events