Release Notes

Web Filter for Authentication for RSA SecurID
(Microsoft Internet Security and Acceleration Server 2000 Feature Pack 1)


Contents

1.0 Introduction
2.0 System Requirements
3.0 Installing the Web Filter for Authentication for RSA SecurID
4.0 Removing the Web Filter for Authentication for RSA SecurID
5.0 Limitations and Known Issues
6.0 RSA SecurID Feature Differences: IIS Server vs. ISA Server

1.0 Introduction

Using the Web filter for authentication for RSA SecurID, you can authenticate users, based on authentication credentials from the SecurID product from RSA. In this way, ISA Server can secure IIS servers that have Web sites requiring authentication credentials from RSA SecurID.

Back to Contents


2.0 System Requirements

Authentication for RSA SecurID is supported on computers with the following:

Authentication for RSA SecurID was tested for ISA Server with RSA ACE/Server v5.0 and with RSA ACE/Server 5.0 Patch 03.

Back to Contents


3.0 Installing the Web Filter for Authentication for RSA SecurID

Before installing the Web filter for authentication for RSA SecurID, perform the following steps on each ISA Server computer in the array:

  1. On the RSA ACE/Server computer, click Start, click Programs, click RSA ACE Server, and then click Database Administration - Host Mode.
  2. On the Agent Host menu, click Add Agent Host....
  3. In Name, type the name of the ISA Server computer.
  4. In Network address, type the IP address of the ISA Server computer, if it did not appear.
  5. Copy the Sdconf.rec file, located in the ACE\data folder on the RSA ACE/Server computer, to the %windir%\system32 folder on the ISA Server computer.
  6. On the ISA Server computer, create a registry value type of REG_SZ in the HKEY_LOCAL_MACHINE\Software\SDTI\ACECLIENT folder named PrimaryInterfaceIP. Set its value to the IP address by which the ACE Server recognizes the host computer.
  7. Close all instances of ISA Server management.

To install the Web filter for authentication for RSA SecurID, type the following at a command prompt

To install the Web filter for authentication for RSA SecurID in unattended mode, type the following at a command prompt

Note:

Back to Contents


4.0 Removing the Web Filter for Authentication for RSA SecurID

To uninstall the Web filter for authentication for RSA SecurID

  1. Click Start, click Control Panel, and then click Add or Remove Programs.
  2. Select Microsoft ISA Server 2000 Updates, and then click Remove.
  3. In ISA Hot Fixes Uninstall, select Web Filter for RSA SecurID, and then click Remove.

To remove the Web filter for authentication for RSA SecurID in unattended mode, type the following at a command prompt

Note:

Back to Contents


5.0 Limitations and Known Issues

  1. Although the Web filter for authentication for RSA SecurID (a component of ISA Server Feature Pack 1) can be installed on a computer that previously had an RSA ACE/Agent installed, this scenario has not been tested.
  2. After using the Web filter for authentication for RSA SecurID extensively, stopping the Web Proxy service may take several minutes.
  3. When a Web filter fails to load properly, an appropriate event message is logged to the event viewer. All ISA Server services are restarted, despite the failure. If you want an additional precaution for specific Web filters (including the Web filter for authentication for RSA SecurID) that monitor for security, create an alert for the Missing installation component or Component load failure event. This will stop the ISA Server services. For instructions on configuring alerts, see ISA Server on-line Help.
  4. You must install the Web filter for RSA SecurID on all array members. Otherwise, when the filter is enabled, if you restart services on array members on which the feature pack is not installed, this event message appears, once every hour:
    ISA Server failed to load some_Web_Filter.DLL. The error code shown in the data area of the event properties indicates the cause of the failure.
  5. Configuration information for the Web filter for authentication for RSA SecurID installed in array configurations is stored in Active Directory. Active Directory replicates the information to all other domain controllers. The configuration is updated when the relevant domain controller is replicated.
    After you install Web filter for authentication for RSA SecurID on the first array member, it is recommended that you wait for the Active Directory replication process to complete before installing on other array members.

Back to Contents


6.0 RSA SecurID Feature Differences: IIS Server vs ISA Server

This section lists differences between standard RSA SecurID functionality on IIS Server and the functionality provided with the Web filter for authentication for RSA SecurID, which is installed on the ISA Server computer:

Back to Contents


Information in this document, including URL and other Internet Web site references, is subject to change without notice. Unless otherwise noted, the example companies, organizations, products, people, and events depicted herein are fictitious and no association with any real company, organization, product, person, or event is intended or should be inferred. Complying with all applicable copyright laws is the responsibility of the user. Without limiting the rights under copyright, no part of this document may be reproduced, stored in or introduced into a retrieval system, or transmitted in any form or by any means (electronic, mechanical, photocopying, recording, or otherwise), or for any purpose, without the express written permission of Microsoft Corporation.

Microsoft may have patents, patent applications, trademarks, copyrights, or other intellectual property rights covering subject matter in this document. Except as expressly provided in any written license agreement from Microsoft, the furnishing of this document does not give you any license to these patents, trademarks, copyrights, or other intellectual property.

© 2002 Microsoft Corporation. All rights reserved.

Microsoft, Outlook, and Windows are either registered trademarks or trademarks of Microsoft Corporation in the United States and/or other countries/regions.

Back to Contents