External MFA Providers via RADIUS Integration
Kron PAM supports integration with third-party Multi-Factor Authentication (MFA) vendors using the RADIUS protocol. In this feature, Kron PAM acts as a RADIUS client, providing a vendor-independent solution for organizations that prefer a centralized authentication mechanism over specific API integrations.
To enable this feature, the mfa.provider system parameter must be set to radius.
Configuration Steps :
1. Navigate to Administration > System Configuration Manager.
2. Set the following parameters :
· mfa.provider : radius
· mfa.external.provider.radius.addresses : Define the RADIUS server(s). You can specify multiple host:port definitions separated by commas for redundancy. If a port is not specified, the default 1812 is used.
· mfa.external.provider.radius.secret : Define the RADIUS secret key. Ensure the "Encryption" checkbox is selected when entering this value.
· mfa.external.provider.radius.timeout (Optional): Timeout of the request in millisecond. Default value is 3000.
· mfa.external.provider.radius.retry-count (Optional) : Number of retry attempts if no response is received within the timeout period. Default value is 3.
· mfa.external.provider.radius.proto (Optional) : Authentication protocol type. Default value is "pap".
· mfa.external.provider.radius.user-field (Optional) : Specify which value of the user will be used for username field in the request packet. Available values are "username", "phone", "email", "UserPrincipalName". Default value is "username".
· mfa.external.provider.radius.nas-id (Optional) : This parameter is for "NAS-Identifier" RADIUS attribute in the request packet. Define when the RADIUS server requires it.
· mfa.external.provider.radius.nas-ip-address (Optional) : This parameter is for "NAS-IP-Address" RADIUS attribute in the request packet. Define when the RADIUS server requires it.
mfa.external.provider.radius.factor (Optional) : Set this parameter to push to utilize MFA with push notifications.