Native Certificate Finder Begin Site Configuration Guide
Introduction
Use this guide to enable a SecureAuth IdP realm to utilize a Native Certificate Finder begin site.
At this begin site, SecureAuth IdP can access the browser's certificate store (Internet Explorer only) and extract the native certificate and use it as the end-user's user ID. From there, the end-user follows the SecureAuth IdP workflow configured in the realm (e.g. Multi-Factor Authentication) without requiring to enter the user ID, and is asserted to the Post Authentication target.
Prerequisites
1. Have Internet Explorer with ActiveX controle
2. Have a native certificate or a realm in which end-users can enroll for a native certificate
3. Create a New Realm or edit an existing realm to which Native Certificate Finder applies in the SecureAuth IdP Web Admin
4. Configure the following tabs in the Web Admin before configuring for Native Certificate Finder:
Overview – the description of the realm and SMTP connections must be defined
Data – an enterprise directory must be integrated with SecureAuth IdP
Workflow – the way in which users will access the target must be defined
Multi-Factor Methods – the Multi-Factor Authentication methods that will be used to access the target (if any) must be defined
Post Authentication – the target resource or post authentication action must be defined
Logs – the logs that will be enabled or disabled for this realm must be defined
SecureAuth IdP Configuration Steps
Workflow
1. In the Workflow section, set the Invalid Persistent Token Redirect to the SecureAuth IdP realm in which end-users can enroll for a native certificate
If end-users land on the Native Certificate Finder begin site without a valid native certificate, then they are redirected to this realm to enroll for a certificate that can then be used for the begin site
Custom Identity Consumer
2. Select Token from the Receive Token dropdown
3. Select True from the Require Begin Site dropdown
4. Select Native Certificate Finder from the Begin Site dropdown
5. NativeCertFinder.aspx auto-populates in the Begin Site URL field
Warning
Click Save once the configurations have been completed and before leaving the Workflow page to avoid losing changes