cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Edward2
Level 7
Report Inappropriate Content
Message 1 of 4

Centralized authentication for CLI/SSH access on the MWGs

Jump to solution
Hello, Does the MWGs support a mechanism to authenticate against a central server such as LDAP or Active Directory? We're aware that the MWGs run Linux and we could use PAM, but want to know if there's a supported or recommended method we could use. Thanks,
1 Solution

Accepted Solutions
aloksard
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 2 of 4

Re: Centralized authentication for CLI/SSH access on the MWGs

Jump to solution

Hi,

 

Hope you are doing well.

 

You can install and configure a pam-radius module on Web Gateway to enforce RADIUS authentication for users when logging on to Web Gateway remotely with SSH or running sudo commands in an unprivileged mode.

 

More information in below link:-

 

https://docs.mcafee.com/bundle/web-gateway-9.0.x-product-guide/page/GUID-53DBBFA6-A63F-42CB-BE16-53D...

 

 

 

Below is an example which was done for LDAP authentication which you can use as reference:-

 

 

"LDAP authentication for SSH CLI Login".

 

 

# yum install pam_ldap* nss_ldap* openldap-clients

# authconfig-tui

     This will open a text-based user interface.

              -- Under "User Information" select "Use LDAP" option

              -- Under "Authentication" select "Use LDAP Authentication". and click Next

              -- Under "LDAP Settings" specify "Server" and "Base DN" (Do not select Use TLS)

                   Example:

                                     Server: ldap://mylabldap.com/

                    Base DN: dc=mylabldap,dc=com

# service nscd restart

 

 

Was my reply helpful? If you find this post useful, Please give it a Kudos! Also, Please don't forget to select "Accept as a solution" if this reply resolves your query!
 
 
Regards
Alok Sarda

View solution in original post

3 Replies
aloksard
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 2 of 4

Re: Centralized authentication for CLI/SSH access on the MWGs

Jump to solution

Hi,

 

Hope you are doing well.

 

You can install and configure a pam-radius module on Web Gateway to enforce RADIUS authentication for users when logging on to Web Gateway remotely with SSH or running sudo commands in an unprivileged mode.

 

More information in below link:-

 

https://docs.mcafee.com/bundle/web-gateway-9.0.x-product-guide/page/GUID-53DBBFA6-A63F-42CB-BE16-53D...

 

 

 

Below is an example which was done for LDAP authentication which you can use as reference:-

 

 

"LDAP authentication for SSH CLI Login".

 

 

# yum install pam_ldap* nss_ldap* openldap-clients

# authconfig-tui

     This will open a text-based user interface.

              -- Under "User Information" select "Use LDAP" option

              -- Under "Authentication" select "Use LDAP Authentication". and click Next

              -- Under "LDAP Settings" specify "Server" and "Base DN" (Do not select Use TLS)

                   Example:

                                     Server: ldap://mylabldap.com/

                    Base DN: dc=mylabldap,dc=com

# service nscd restart

 

 

Was my reply helpful? If you find this post useful, Please give it a Kudos! Also, Please don't forget to select "Accept as a solution" if this reply resolves your query!
 
 
Regards
Alok Sarda
Edward2
Level 7
Report Inappropriate Content
Message 3 of 4

Re: Centralized authentication for CLI/SSH access on the MWGs

Jump to solution

Thanks aloksard!

I successfully implemented centralized auth using pam ldap as you suggested, but I am facing a couple of issues with Radius. We are leaning towards Radius because it seems to be the supported solution as it is documented on the admin guide. Do you think we might face issues later if we use an "unsupported" solution such as pam ldap?

Thanks again!

timode
Level 9
Report Inappropriate Content
Message 4 of 4

Re: Centralized authentication for CLI/SSH access on the MWGs

Jump to solution

Hi,

I also try to auth ssh with ldap. Could you please provide some more information how to set this up? I had no luck so far. I have to use TSL for ldap (ldaps).

cheers

Timo

You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community