Microsoft Active Directory back-end authentication

Prev Next

OneSpan Authentication Server can be configured to query Active Directory via an LDAP connection for back-end authentication. This is typically used if a supported Windows operating system is not available on the OneSpan Authentication Server machine.

You need to set up and use SSL for connections between OneSpan Authentication Server and the Active Directory back-end server. Unencrypted connections to an Active Directory back-end server do not work, unless you have a very old and specially configured version of Windows Server. OneSpan Authentication Server does not support unencrypted connections to Active Directory via LDAP!

OneSpan Authentication Server also supports site awareness for Global Catalog-based Active Directory domain controller lookup. OneSpan Authentication Server queries the Global Catalog for all domain controllers serving the user currently in process of back-end authentication and contacts the relevant domain controllers according to their priority in the Global Catalog. In this context, OneSpan Authentication Server identifies the network site to which the machine that is running OneSpan Authentication Server belongs. Those domain controllers that share the same site with OneSpan Authentication Server during back-end authentication take precedence over others.

For site awareness to work, OneSpan Authentication Server needs to be restarted, if the Active Directory sites configuration has been changed.

When deploying Microsoft Active Directory with OneSpan Authentication Server for back-end authentication, ensure the following:

  • The domain controllers are running Windows Server 2016 or later.

  • If the global catalog is set up (via Back End > Settings in the Administration Web Interface) and no back-end components have been defined, domain discovery will be used to search for a user and identify the Active Directory server to authenticate the user.

    • If domain discovery via the global catalog is to be used, users must be set up in the same domain on Active Directory as they are on OneSpan Authentication Server.

    • After domain discovery, communication to the Active Directory server containing the user credentials will use SSL if and only if Enable SSL for Back-End Servers is set in the Global Catalog Domain Discovery setting. You can also use the SSL Port option in this section to override the port to be used for SSL communication. If not specified, OneSpan Authentication Server will determine the port number from DNS or the global catalog.

  • OneSpan Authentication Server must be configured to use the DNS server containing the DNS records of the Active Directory server or an entry has to be present in the host file that maps the IP of the Active Directory domain controller to the fully qualified domain name of the domain controller. On Linux this has to be configured on the host OS.

  • The user ID that is used to log in to the Active Directory back-end system during authentication must have both search and update permissions for the data that is to be accessed.

For more information about Active Directory user name resolution, see Active Directory user name resolution.

To enable back-end authentication for Active Directory using LDAP

  1. Identify the Active Directory server based on the Active Directory back-end server records in OneSpan Authentication Server. If no Active Directory back-end server records are defined, then OneSpan Authentication Server will attempt to identify the Active Directory domain controller using the Global Catalog.

  2. Bind to Active Directory using the security principal ID and password defined for the Active Directory back-end server if principal details specified. The format of the security principal ID will be the DN, for example: cn=Administrator, cn=User, dc=vasco, dc=com.

  3. Search Active Directory for the attributes of the user to be authenticated.

  4. OneSpan Authentication Server will bind to the directory server that handles the authentication request and use the user ID and the password specified in the authentication request received. If the bind succeeds, the user authentication is deemed to be successful. If the bind fails, the authentication is deemed to have failed.

If authentication fails, the attributes retrieved during the search will be used to determine the cause of the failure.

When upgrading Active Directory domain controllers, the following rule must be obeyed:

  • If a server with Windows group users is promoted to an Active Directory domain controller, you must reset the Active Directory password for any user that existed on the server before it was promoted.

Configuring OneSpan Authentication Server for Active Directory back-end authentication via LDAP

Defining the organizational structure

To configure OneSpan Authentication Server for Active Directory back-end authentication via LDAP, you need to define an organizational structure consisting of domains and organizational units in OneSpan Authentication Server. This is done with the Administration Web Interface via ORGANIZATION > Add domain.

Afterward define an Active Directory server in the Administration Web Interface via BACK-END > Register Active Directory Back-End. This opens the Create new Microsoft Active Directory Back-End Server page where you can supply the required information.

Configuring SSL for back-end authentication (via Active Directory)

When using Microsoft Active Directory with OneSpan Authentication Server for back-end authentication, the back-end server should be configured accordingly. As such, if Active Directory is configured to communicate via SSL, then OneSpan Authentication Server must also be configured to use SSL with Active Directory.

This involves the following steps:

  1. Generating and exporting the required certification authority (CA) certificate.

  2. Converting the CA certificate and importing it into OneSpan Authentication Server.

To configure SSL for Active Directory back-end authentication via LDAP and export the enterprise root CA certificate

  1. If not already available, install Certificate Services on the LDAP back-end server.

    This is a Windows component, and should be available on your Windows operating system installation media.

  2. Generate an enterprise root CA certificate.

    You may need to wait several minutes to allow the domain controllers to enroll for domain controller certificates.

  3. After setting up SSL on the LDAP back-end server, export the CA certificate:

    1. Start the Windows Certification Authority application (typically via Start > Administrative Tools > Certification Authority).

    2. Right-click a certification authority (CA) and select Properties from the context menu.

    3. In the Properties window, click View Certificate.

    4. In the Certificate window, switch to the Details tab and click Copy to File.

    5. In the Certificate Export wizard, click Next.

    6. Select DER encoded binary (.CER) and click Next.

    7. Specify the path and name of the CA certificate file and click Next.

    8. Click Finish to export the certificate.

After exporting the certificate, convert and import it to OneSpan Authentication Server, depending on your platform.

To convert a DER-encoded certificate and import it to OneSpan Authentication Server

  1. Convert the binary DER-encoded certificate file (.cer) to an ASCII-armored certificate file (.pem) using the following command:

    openssl x509 ‑inform DER ‑outform PEM ‑in certname.cer ‑out certname.pem

    where certname is the name of the self-signed CA certificate.

    OneSpan Authentication Server ships with a specific version of the OpenSSL utility. We recommend that you use this version for any procedures involving the openssl command.

    By default, this specific version of OpenSSL is located in %PROGRAMFILES%\VASCO\IDENTIKEY Authentication Server\bin on Windows and in /opt/vasco/ias/bin on Linux, respectively.

  2. Depending on your platform, do one of the following:

    • If you are using Ubuntu Server:

      1. Change the extension of the certificate file to .crt and copy it to the CA certificate store:

        mv certname.pem certname.crt

        cp certname.crt /usr/local/share/ca-certificates

      2. Update the CA certificate store:

        update-ca-certificates

    • If your are using another Linux distribution or Microsoft Windows:

      1. Obtain the hash of the .pem file:

        openssl x509 ‑in certname.pem ‑noout ‑subject_hash

      2. Rename certname.pem to hashvalue.0, where hashvalue is the hash value calculated by the openssl command.

        For example, if the hash result is 54321, the file name would be 54321.0.

      3. Copy the renamed certificate file (hashvalue.0) to the following location, depending on the platform:

        • /etc/ssl/certs (Linux)

        • %PROGRAMFILES%\VASCO\IDENTIKEY Authentication Server\certs (Windows, default).

      4. On Linux, ensure that the run user of OneSpan Authentication Server can access the certificate file. If required, change access rights and/or file ownership with the chmod and chown commands.

  3. Restart the OneSpan Authentication Server service or daemon, respectively.

    The new certificate files are read only when the service/daemon starts.

Enabling nested groups for Windows group check

OneSpan Authentication Server supports the concept of nested groups for Windows group checks in the context of Active Directory. This method of grouping allows for a simplified administration of domain trees. For more information about nested groups, refer to the Microsoft documentation.

To enable nested groups for Windows group check

  1. Open the Administration Web Interface.

  2. Navigate to POLICIES >List.

  3. Select the respective policy.

  4. Navigate to the User tab and click EDIT.

  5. Set Nested Groups to Yes.

Enabling nested groups can cause performance issues in OneSpan Authentication Server in the following cases:

  • There are too many groups in one domain.

  • Active Directory is not optimally configured. For more information, refer to the Microsoft documentation.

Nested groups are disabled (No) by default. The value is inherited from the Base Policy policy.

When upgrading to a newer version of OneSpan Authentication Server, the administrator must re-add local domain groups.

Defining a back-end server record

For more information about setting up a back-end server record for an Active Directory server, see Setting up a Microsoft Active Directory back-end server using LDAP.