Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

PowerScale OneFS 9.8.0.0 Web Administration Guide

Multifactor authentication (MFA)

Multi-factor authentication (MFA) is a method of computer access control in which you are only granted access after successfully presenting several separate pieces of evidence to an authentication mechanism. Typically, authentication uses at least two of the following categories: Knowledge (something you know); possession (something you have), and inherence (something you are).

MFA is a great way to increase the security of a cluster. Increasing the security of privileged account access (For example, administrators) to a cluster is the best way to prevent unauthorized access.

MFA enables the LSASS daemon to require and accept multiple forms of credentials other than a username or password combination for some forms of authentication. There exist many ways to implement MFA with the most common being public or private key authentication.

The MFA feature adds PAPI support for SSH configuration using public keys that are stored in LDAP and Multi-Factor Authentication support for SSH through the Duo security platform. Duo MFA supports the Duo App, SMS, and Voice.

The use of Duo requires an account with the Duo service. Duo provides a host, ikey, and skey to use for configuration (skey should be treated as a secure credential).

Duo MFA is on top of existing password and/or public key requirements. If the SSH configuration type is set to any or custom, Duo cannot be configured. Only specific users or groups may be enabled to bypass MFA if specified on the Duo server. Duo enables the creation of one time or date/time limited bypass keys for a specific user. Also, the bypass keys can be permanent.


Rate this content

Accurate
Useful
Easy to understand
Was this article helpful?
0/3000 characters
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please select whether the article was helpful or not.
  Comments cannot contain these special characters: <>()\