Link to home
Start Free TrialLog in
Avatar of wanstor
wanstorFlag for United Kingdom of Great Britain and Northern Ireland

asked on

RSA across domains

Hi,

One of our customers are looking to implement RSA across their network.  They have two domains (one for their office and one for their datacentre).  Users that have a datacentre account will have it named the same as their office account.

Obviously we'd prefer it if users only have one fob so I'm wondering how (if possible) we can go about this.

Thanks in advance
Avatar of btan
btan

Was thinking of web access gateway which take in username@domain as username and perform backend ldap and rsa check. It offload the check through such central portal login page. If this something you are interested, I can share more..
ASKER CERTIFIED SOLUTION
Avatar of wanstor
wanstor
Flag of United Kingdom of Great Britain and Northern Ireland image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
Know of F5 access policy mgr which can act as the middle man to performs client side prelogin check and rsathen doa whilesever checks. Ldap, ad and kerberos login and rsa secureid is supported. There is their webtop that can present the authorised resource base on the visual workflow policy builder created. Scripts for customization is available. Importantly all userchecks usingis transparent to it and act as a guardian.

 http://www.f5.com/products/big-ip/access-policy-manager.html
Avatar of wanstor

ASKER

Setting up a one way trust between the two domains seemed to have resolved the issue. Thanks All!