Secret Server integration and two-factor

Secret Server integration and two-factor

avatar

We're using RDM with Secret Server. Works great, but we're wanting to protect Secret Server with two-factor authentication.

Is this guaranteed to break our SS integration? Or maybe there's some way for API "stuff" to be excluded from two-factor requirements or leverage some sort of expiring token type system?

We'll check with Thycotic as well but curious if any of you out there are doing integrations with SS or other password managers with two-factor in the middle.

All Comments (8)

avatar

Hmm.... may come down to whether or not RDM is using the AuthenticateRADIUS call and can provide the RADIUS password via user prompt....

avatar

Hello,

I would have to look at SecretServer to confirm but isn't it a popup that you get upon initial access?

Maurice

avatar

Yes, RDM throws a popup... however it only asks for Org, Domain, Username and Password.

With that said, perhaps it's smart enough to prompt for additional fields if SS requests them? If RDM is using AuthenticateRADIUS:

https://secretserveronline.com/webservices/sswebservice.asmx?op=AuthenticateRADIUS

... and additional radiusPassword field is reqeusted.

We may have to just give this a try.

avatar

I had a look and we call Authenticate, not AuthenticateRadius

We have a licence of SecretServer that Thycotic is graciously allowing us to use, this allows us to implement our integration with them.

Maybe you could visit our Feature Request forum and ask for that feature?

http://forum.devolutions.net/forum17-remote-desktop-manager--feature-request.aspx

Maurice

avatar

Done.

Do you guys offer any sponsored RFE type work? Perhaps as a PS engagement?

avatar

I'm afraid we're not good with acronyms, well not these ones anyway, can you expand some more?

Maurice

avatar

Sure, sorry about that! RFE = Request for Enhancement (what I just posted in your feature request form) and PS = Professional Services (thinking you guys could prioritize the implementation via a paid engagement from either us or other interested customers).

avatar

ok, thank you for clarifying.

Well the RFE is taken care of, as for Professional Services we havent needed to do that yet.

Obviously if other customers go add their +1 to your feature request, it will show us how "desired" this feature is, but as you can see in these forums, we tend to listen A LOT to our community.

Best regards,

Maurice