SurePassID OVA File README

SurePassID On-Prem MFA

SurePassID OVA File README

Table of Contents

SurePassID On-Prem MFA

This OVA file installs a proof-of-concept (POC) instance of SurePassID with Microsoft SQL Server Express. The OVA was generated using VMware Workstation with ESX 6.5 hardware compatibility.

What you need to know about your OVA file

  • The POC license file has 10 not-for-resale user licenses that expire quarterly.
  • If you have questions or need technical support, contact support@surepassid.com.

Initial login to the SurePassID Authentication Server (SPAS) administrator portal

When you first log in to SurePassID, you will not have a second-factor (2FA) authentication method provisioned for your account.

Provision an OTP token and enable mandatory 2FA

  1. Log in with the provided username and password at https://mfa.surepasidas.local.

    • You can change the password in the portal using the New icon next to the password field when editing the user account.
    • The system generates a complex password, but you can overwrite it with a new password and press Enter to save it.
    • A complex password is required. If you do not enter one, the system generates another password.
  2. Provision an OTP token for your account. This example uses a Google Authenticator Compliant soft token. The default username is Administrator.

    • Go to the Users tab.
    • Edit the Administrator account.
    • Click Add New Token in the Tokens section near the bottom right of the user edit screen.
    • Under Token Type, choose Google Authenticator Compliant.
    • To test offline 2FA authentication, under OTP Type, choose Event (Oath).
    • Click Add.
    • After the screen updates, go to the Token ID line and click the QR code icon on the right.
    • Scan the QR code in a compatible mobile authenticator app, such as the SurePassID Authenticator App.
    • Use Check OTP to validate the token.

Change the MFA Server's web.config to require 2FA when logging in to the admin portal:

  • Make a backup copy of C:\Program Files (x86)\SurePassID Corp\SurePassID Authentication Server 24.2\MfaServer\web.config, copy the original to your desktop, and open it in Notepad.
  • Change <add key="System.AllowPortalSingleFactorLogin" value="true"/> to <add key="System.AllowPortalSingleFactorLogin" value="false"/>. Save the file, then copy it back to the original path and replace the existing file.
  • You will now be required to provide a second factor when logging in to the portal.
    • The change will force you to sign in again.
  • To test OTP with Windows login, lock and unlock the Windows session, then use your new OTP in the passcode field instead of the bypass code.

Test Windows Logon Manager (WLM) on other Windows test system(s)

Deploy WLM to other Windows systems

  • Copy the C:\installs\Deploy folder to the Windows system you want to test

  • Import the SurePassID TLS certificate on each Windows device that will run WLM, so the device trusts the SPAS without certificate warnings:

    • Right-click the .cer file from the deploy folder and select Install Certificate.
    • Choose Local Machine as the store location, click Next, and approve the User Account Control prompt if shown.
    • Select Place all certificates in the following store, click Browse, choose Trusted Root Certification Authorities, and click OK.
    • Click Next, then Finish, and confirm the The import was successful message.
  • Add an entry to C:\Windows\System32\drivers\etc\hosts that points to the SPAS IP address so the device can resolve mfa.surepassidas.local without certificate errors.

  • You may need to copy the file to the desktop, edit it, ensure the filename is hosts rather than hosts.txt, and copy it back to the etc folder.

    • This allows the Windows device to connect to the SPAS without certificate prompts and ensures TLS connections work.

Configure WLM on the Windows device to match the SPAS settings. The settings are available in:

  • WLM Configuration Manager on the SPA or C:\installs\Deploy\Sp Reg Settings.reg on the server or the Deploy folder you copied from there to the test system.
    • You can copy the Sp Reg Settings.reg file to the system you are setting up and double-click it to import the settings into the new client, then run the installer to verify the settings using the configuration tool.
  • Run the Windows Logon Manager installer on the Windows device.
    • See the [Windows Logon MFA Guide](C:\installs\Documentation\SurePassID WLM\SurePassID_Windows_Logon_MFA_Guide.pdf).

Configure a test user in the SPAS:

  • Add the test user (windows login name) for the Windows device in the SurePassID admin portal (https://mfa.surepassidas.local).
    • See the [Administration Guide](C:\installs\Documentation\SurePassID Server\SurePassID_Administration_Guide.pdf) for more details as needed.
  • Provision an OTP token for that user in the SurePassID admin portal.
  • Use the Google Authenticator Compliant token process described previously.
  • The user can now test signing in to Windows using the Sign On Options link on the login screen.
  • The user will use their normal Windows username and password as the first factor, plus an OTP from their token as the second factor.
  • Enforcement is not enabled yet, so the user can still sign in with a single factor using the standard Windows login provider, represented by the key icon in the Sign On Options section on the Windows logon screen.
  • Keep in mind that for SPAS to validate a Windows/PAM/RADIUS user's MFA, their username must exist in the SPAS directory with a valid token (or bypass MFA enabled for their account which is only applicable to standard/non-admin accounts in the SPAS).
  • After a successful login to Windows using the Sign On Options link on the login screen-->the SurePassID WLM Icon on the login screen using your Windows username/password/OTP:
    • Test with Enforcement enabled: (ONLY AFTER A SUCCESSFUL TEST WITH THE WLM)
      • Import the EnforceSurePassIDMFA.reg file to enable the credential provider filter
      • (C:\installs\Deploy\Post Testing - Enforcement\EnforceSurePassIDMFA.reg)
    • The above will mask the standard provider on the login screen so you will be signing in with the SurePassID WLM only.
    • This also means that if you connect via RDP you will be forced to use the WLM to sign on.

Now that your SurePassID admin portal (https://mfa.surepassidas.local) is secured with 2FA, you can extend SurePassID identity and access security to meet your use cases in the POC with the capabilities we support:

Multi-Factor Authentication Methods

  • Phishing-resistant MFA: FIDO2 PIN, FIDO2 Biometric, FIDO2 Passwordless, FIDO2 Mobile Push, PIV Smart Card, X.509 Certificate
  • Non-phishing-resistant MFA: OATH HOTP (Event-Based) RFC 4226, OATH TOTP (Time-Based) RFC 6238, OATH OCRA (Challenge-Response) RFC 6286, Mobile Push

Domain and Operating System Logins

  • Windows + RDP MFA with offline 2FA
  • macOS + SSH MFA with offline 2FA
  • Linux + SSH MFA with offline 2FA (RHEL, SUSE, CentOS, Ubuntu, etc.)

Cloud and On-Prem Apps

  • Generic: SAML2 IdP, OIDC IdP, RADIUS IdP, LDAP IdP, API IdP
  • Microsoft: Entra ID IdP, ADFS IdP, M/O365 IdP

Directory Integration

  • Entra ID, Active Directory, SurePassID built-in directory, LDAP, third-party (Workday, Oracle, SAP, IBM, etc.)

API

  • RESTful API, full SDK, Swagger library, Postman library