立即与支持人员聊天
与支持团队交流

Safeguard Remote Access Hosted - Administration Guide

Introduction Prerequisites Limitations Getting started Administrator-side use cases User-side use cases Appendix Glossary

Introduction

Intended audience

For Administrators, the Administration Guide contains information about how to set up One Identity Safeguard Remote Access (SRA) in One Identity Starling and how to integrate with One Identity Safeguard for Privileged Sessions (SPS).

For Users, the Administration Guide describes the usage and features of SRA .

Overview

SRA is a Cloud Software as a Service (SaaS) that provides a client-less, browser-based secure terminal access to servers via integration with the SPS product.

Figure 1: SRA architecture overview

Prerequisites

To use One Identity Safeguard Remote Access (SRA), you must meet the following prerequisites:

  • One Identity Safeguard for Privileged Sessions (SPS) version 6.9.0 or later is installed. Basic network configuration is completed, and the web administrative interface is available.

  • One Identity Safeguard for Privileged Sessions (SPS) version 6.11.0 or later is installed, if SRA is intended to be used in a SPS cluster environment.

  • A SPS Authentication and Authorization (AA) plugin is selected. For more information, see Using plugins.

  • Administrator role under the SRA product in One Identity Starling.

Limitations

This section introduces the limitations of One Identity Safeguard Remote Access (SRA).

Security-related limitations:
  • The end-user is not required to periodically re-authenticate to a running session. Once the end-user logged in to a terminal session, they stay logged in to SRA.

  • The bandwidth usage of terminal connections is not limited.

Functionality-related limitations:
  • Use Chrome-based browsers for the best user experience. Other browsers are supported on a best effort basis.

  • Only SSH and RDP protocols are fully supported, VNC and Telnet are only supported on a best effort basis.

  • No RDP gateway is supported, SRA itself acts as the gateway.

  • No RDP remote application or SCP over SSH is supported at this time.

  • Only fixed and inband destination selection defined in One Identity Safeguard for Privileged Sessions (SPS) will be picked up by SRA.

  • SPS nodes are not monitored. If SPS fails or unjoined from One Identity Starling, then the related target connections remain visible on SRA.

  • No Copy & Paste support in terminal sessions.

  • The server-side resolution in terminal sessions cannot be changed.

  • Inband target servers provided by the end user are currently not supported, only preset inband targets.

  • Some browser keyword shortcuts are not forwarded to the terminal session, such as Ctrl-T, Ctrl-Shift-N.

  • For Apple users, copy-pasting text in an active remote session with Cmd+C and Cmd+V keyboard shortcuts does not work. Use (Copy to clipboard) and (Paste) on the session window's control panel to copy-paste text to/from the server.

  • Touch device support was tested only using the Safari browser on iPad and iPhone.

  • The Enter fullscreen mode () functionality of the control panel cannot be applied to the session window, if the session was opened on a touch device.

  • The following limitations apply to the next generation SSH client functionality:

    • The new SSH client can handle only SSH policies of the fixed type. Inband SSH policies are currently not supported.

    • Managing sessions with touch devices is not supported.

  • The following limitations apply to the file transfer functionality:

    • SSH file transfer in active remote sessions is not supported on touch devices.

    • File transfer Cancel | Pause | Resume interworking is applicable only to Google Chrome browser (recommended).

Getting started

This section and its subsections describe how to set up One Identity Safeguard Remote Access (SRA) from an Administrator point of view.

Before you can start using SRA, first you have to create a One Identity Starling account. After that, you must access One Identity Safeguard for Privileged Sessions (SPS) to perform preliminary configurations, for example, configuring the authentication and authorization plugin, creating local credential stores, setting up connection and usermapping policies and so on.

自助服务工具
知识库
通知和警报
产品支持
下载软件
技术说明文件
用户论坛
视频教程
RSS订阅源
联系我们
获得许可 帮助
技术支持
查看全部
相关文档

The document was helpful.

选择评级

I easily found the information I needed.

选择评级