5.2. Client RADIUS Authentication

InControl RADIUS authentication allows clients to have their login credentials authenticated against an external RADIUS server via the InControl server.

[Note] Note: The API does not support RADIUS authentication

The InControl API does not support user authentication using RADIUS.

The following list summarizes the RADIUS authentication setup steps:

  1. Configure a suitable external RADIUS server to authenticate InControl user credentials. This is described in more detail later in this section. The server might be running the Clavister EasyAccess software product and may also provide multi-factor authentication such as using Clavister OneTouch.

  2. Open the InControl server manager interface and configure the RADIUS server to use. This is also described in more detail towards the end of this section.

  3. When a user now opens the InControl client and tries to log in using credentials, InControl will try to authenticate the credentials against the configured RADIUS server.

The following should be noted about RADIUS authentication:

[Caution] Caution: Always have one non-RADIUS administrator

If RADIUS authentication is used extensively, do not delete all non-RADIUS administrator users in the local user database. At least one should exist otherwise the administrator could get locked out if RADIUS authentication is not working for some reason.

Enabling Client RADIUS Authentication in the InControl Server

RADIUS authentication is enabled in InControl by opening the InControl server settings interface, selecting RadiusAuthentication and setting the property EnableRadiusAuthentication to a value of True and entering the other details for communicating with the RADIUS server.

Finally, save the new settings and restart the server.

The following should be noted about the values entered for RADIUS configuration:

If, after enabling RADIUS authentication, the InControl server will not run, carefully check all of the RADIUS values entered in the InControl server settings. In addition, check the server log file for messages that may indicate the source of the problem.

Configuring the RADIUS Server

The following should be noted when configuring the external RADIUS server itself:

The Need to Re-authenticate After Client/Server Communication Loss

Should communication between the InControl client and server be lost then in certain circumstances, a warning will be displayed that the user is longer authenticated. Following the warning, the user will have to re-authenticate. This might happen if, for example, the RADIUS server authenticated using Clavister OneTouch. It could also happen if the password has changed since the original authentication.