nFactor concepts, entities, and terminology
Login schema
add authentication loginSchema <name> -authenticationSchema <string> [-userExpression <string>] [-passwdExpression <string>] [-userCredentialIndex <positive_integer>] [-passwordCredentialIndex <positive_integer>] [-authenticationStrength <positive_integer>] [-SSOCredentials ( YES | NO )]
-
SSOCredentialsindicate whether the current factor credentials are the default SSO credentials. Default value is NO. -
By default, the last factor's credentials are used for SSO in nFactor authentication. However, by configuring
SSOCredentials, you can opt to use the current factor's credentials. IfSSOCredentialsis configured in multiple factors, the final factor with this setting takes precedence. -
For nFactor authentication, we recommend enabling
SSOCredentialsonly on the factor that actually validates user credentials (like a password), and not on factors that gather user information or metadata.For example, if your nFactor flow first collects user attributes (such as group membership) and a later factor verifies the password, make sureSSOCredentialsis enabled only on that password verification factor.
Policy label
add authentication policy label mylabel –loginSchema <>
Virtual server label
Next factor
No-Auth policy
No-auth policy can be created by running the following CLI command:
add authentication policy noauthpolicy –rule <> -action NO_AUTHN
no-authentication policy takes a rule that can be any advanced policy expression. Authentication result is always success from NO_AUTHN.
no-auth policy in itself does not seem to add value. However, when used along with passthrough policy labels, it offers great flexibility to make logical decisions to drive user authentication flow. NO_AUTHN policy and passthrough factors offer a new dimension to nFactor's flexibility.
no-auth and passthrough in subsequent sections.
Passthrough factor/label
add authentication policylabel example1
add loginschema passthrough_schema –authenticationSchema noschema
add authentication policylabel example2 –loginschema passthrough_schema
-
When the user is presented two password fields, after the first factor, the second factor does not need user intervention.
-
When authentication of a type (say certificate) is done, and the administrator must extract groups for that user.
NO_AUTH policy to make conditional jumps.
nFactor authentication flow
Example of using passthrough factor and no-auth policies to make logical decisions
add authentication policylabel group check
add authentication policy admingroup –rule http.req.user.is_member_of("Administrators") –action NO_AUTHN
add authentication policy nonadmins –rule true –action NO_AUTHN
bind authentication policy label group check –policy admingroup –pri 1 –nextFactor factor-for-admin
bind authentication policy label groupcheck –policy nonadmins –pri 10 –nextfactor factor-for-others
add authentication policy first_factor_policy –rule <> -action <>
bind authentication vserver <> -policy first_factor_policy –priority 10 –nextFactor groupcheck