Access 301: Ephemeral Authentication > Class - Access 301: Ephemeral Authentication Source |
Module 2 - Implement Priviledged User Access AuthenticationΒΆ
The F5 Privileged User Access (PUA) solution provides an easy way to add CAC/PKI authentication or other strong authentication methods to network infrastructure and systems that do not natively support this functionality. It does this without requiring the addition of client software or agents anywhere in the environment and allows you to fully leverage your legacy or non-compliant systems in a safe and secure manner. It integrates directly into DoD PKI or MFA systems and may be configured to work cooperatively with existing TACACS, Active Directory, AAA servers, or a variety of third-party authentication databases.
F5 PUA is DoD CIO approved as an Identify Federation Service (IFS) for facilitating both privileged and unprivileged user authentication to unclassified and secret fabric DoD Information Systems.
IFS are third-party intermediary services facilitating user-authentication to resources or relying parties. IFS may be used when a system or application does not support direct authentication with PKI or MFA credentials, or the system owner desires a single management framework for a group of heterogeneous systems.
F5 Certifications
- DoD UC APL
- FIPS 140-2 Validated - Level 1, 2, or 3 depending on platform selection. F5 offers software (VE), F5 Full-Box FIPS platforms, integrated (HSM PCI Card), and external (Network HSM) FIPS solutions
- Common Criteria Certification
- NSA Commercial Solutions for Classified (CSfC) Components List
- DISA/JITC PKE (public key enabled)
- United States Government IPv6 Conformance Certification (USGv6)
- Lab 2.1 - Priviledged User Access (PUA) Requirements
- Lab 2.2 - Executing the PUA Script
- Lab 2.3 - Validating the PUA Script Installation
- Lab 2.4 - Creating an APM Policy - PUA Build Script
- Lab 2.5 - Creating an APM Policy - LDAP
- Lab 2.6 - Creating an APM Policy - CAC Authentication
- Lab 2.7 - Creating an APM Policy - Update Initial Access Policy
- Lab 2.8 - Certificate Update
- Lab 2.9 - Adding Devices to the webtop
- Lab 2.10 - Modifying Radius Configurations
- Lab 2.11 - Verification Testing