Install and configure RADIUS Extension
After installing and configuring NPS, install and configure RADIUS Extension. To do this:
- Run
AxidianID.EA.RADIUS.Extension-<version number>.x64.en-us.msilocated atAxidian Access <version number>\Axidian NPS RADIUS Extension\<version number>. - Configure RADIUS Extension in the registry or with group policies.
- In registry
- In Group Policy Editor
- Open Registry Editor.
- In the
HKEY_LOCAL_MACHINE\SOFTWARE\Axidian-ID\SrvLocator2section, modify the following parameters:
In the
ServerUrlBasestring parameter, specify the Core Server address in the formathttps://full_dns_server_name/am/core/.NoteFor correct operation, we recommend that you install a client certificate on each Core Server.
In the
IsIgnoreCertErrorsnumeric parameter, specify the value 0 or 1.This parameter stands for ignoring the Core Server authentication certificate errors. With the value 1, certificate errors are ignored.
If required, you can set the session hold period in the
SessionHoldPeriodMsnumeric parameter. This is the period during which the session can be reused in case of short-term connection losses to Core Server. During the specified period, the session is stored in the cache and can be reused when a new server connection is requested. The server availability check is not repeated; the cached check result is used instead. After the period expires, the session is terminated. A new session is created at the next server connection request.The default parameter value is 180,000 ms (3 minutes).
- Add the group policy templates.
- Open Group Policy Editor.
- Go to Computer Configuration → Administrative Templates → Axidian ID → Client Connection.
- Open the properties of the Server connection settings policy.
- Enable the policy.
- In the Core Server URL field, enter the Core Server address in the format
https://full_dns_server_name/am/core/. - If required, enable the Ignore certificate errors option.
- For the Session object hold period setting, leave the default value — 180,000 ms (3 minutes) — or specify a new one.
- Click OK.
For more information about configuring RADIUS Extension with policies and in the registry, see the RADIUS Extension section.
Configure access to applications that have not been added
If applications work through NPS (Network Policy Server) with RADIUS Extension installed, but authentication for them is not performed through Axidian Access, configure access for them in Management Console. Otherwise, login into these applications is not available.
To configure access for RADIUS applications that have not been added to Axidian Access:
- In the Management Console sidebar, open the Configuration section.
- On the Integration modules tab, select NPS RADIUS Extension.
- Allow or deny access in the For RADIUS applications that are not registered in Axidian Access setting.