Working with Host-Based Shared-Secret

Describes the procedure to Host-Based Shared-Secret

Host-based shared-secret allows a common shared-secret for all users, which can be specified and distributed to the users by the Security Officer. Host-based shared-secret method is useful to force the same secret code for multiple appliances in clustered environments.

Configuring Two Factor Authentication with Host-Based Shared-Secret

The following section describes how to configure two factor authentication using host-based shared-secret.

Perform the following steps to configure Two Factor Authentication with Host-based shared-secret.

  1. On the ESA Web UI, navigate to Settings > Security > Two Factor Authentication.
  2. Check the Enable Two-Factor-Authentication check box.
  3. Select Host-based shared-secret from Authentication Mode.
  4. Click Modify.
    The Host-based shared-secret key appears.
    If required, click Generate to modify the Host-based shared-secret key. Ensure that you note the Host-based shared-secret key to generate TOTP.
  5. You can apply the following logging-settings in order to specify what to log:
    • Log failed log-in attempts
    • Log any successful log-ins
  6. Click Apply to save the changes. A confirmation message appears.

Logging in to the Web UI

Before beginning, be aware of time limits. When entering codes from the authenticator there is a time limit. Ensure codes are entered in the authenticator code box within the displayed time limit

The following section describes how to log in to the Web UI after configuring host-based shared-secret.

To login to the Web UI:

  1. Navigate to the ESA Web UI login page.

  2. In the Username and Password text boxes, enter the user credentials.

  3. Click Sign in.

    The 2 step authentication screen appears.

    2 step authentication screen

  4. Use the Host-Based Shared-Secret key obtained from the configuration process to generate authentication code.

  5. Enter the Host-Based Shared-Secret key in the authentication app to generate authentication code.

  6. In the authenticator code box, enter the authentication code, and click Verify.

After the code is validated, the ESA home page appears.

Last modified : September 04, 2024