Thales Safenet Authentication Service

About the Device

SafeNet Authentication Service (SAS) is an enterprise-class authentication server designed to extend authentication services to users in a single organization or across an unlimited number of entities. These entities can be almost anything, from divisions or cost centers within a company, to subsidiaries or completely independent organizations. Its multi-tier, multi-tenant structure accommodates just about any hierarchy, reporting structure, business structure, security segregation, or other delineation.

Device Information

 Entity

Particulars

 Entity

Particulars

Vendor Name

Thales (Gemalto)

Product Name

Safenet Authentication Service (SAS) PCE

Type of Device

Hosted

Collection Method

Log Type

 Ingestion label

Preferred Logging Protocol - Format

Log collection method

Log Type

 Ingestion label

Preferred Logging Protocol - Format

Log collection method

Thales MFA

THALES_MFA

Syslog - CEF

CyberHub

Port Requirements

Source

Destination

Port

Source

Destination

Port

Thales Safenet

CyberHub

514 (UDP)

Device Configuration

SafeNet Authentication Service (SAS) logs are generated on the service providers’ servers. The SafeNet Agent for Remote Logging sends the information displayed in the SafeNet Authentication Service Manager window together with Operator Activity information to a configured Syslog Server.

Pre-requisites :

  • SAS Manager should be installed and configured on the machine.

  • SafeNet Agent for Remote Logging should be installed.

To configure Safenet Remote Logging Agent

  1. To configure the Agent. Click Start > All Programs > SafeNet > Agents > Logging Agent. The SafeNet Authentication Service Logging Agent is displayed.

  2. In Current Organization, click Add. Browse to the location of the LoggingAgentConfigFile.bmc and load the file. This file will be available once you configure SAS Manager.

  3. The Current Organization will update information about your Virtual Server.

image-20240520-103851.png
  1. Click Configuration.

  2. In Message Type, select the following:
    • Authentication Message
    • Operator Activity Message

You can only select one message type at a time. You need to configure it and then select second message type and repeat the process.

image-20240520-104052.png
  1. In Configuration > Send To >, select Syslog.

  2. For Configuring syslog do the following:
    a. In Primary, enter the IP: Port of the Syslog server in format as [ CYBERHUB_IP: 514]
    b. In Secondary, keep it blank.
    c. Format - choose ArcSight.
    d. Click Apply.

Secondary Field will be auto populated with some value if kept blank. Regardless please keep it blank.

Once Configuration is saved and done, In Service Status > click Start. Also, for any changes done in SAS manager or remote logging agent, you must restart the Remote Logging Agent for changes to take effect.

Integration Parameters

Parameters required from customer for Integration.

Property

Default Value

Description

Property

Default Value

Description

IP Address

Thales Safenet interface IP address

Hostname or IP address of the device which forwards logs to the CyberHub

About Accenture:
Accenture is a leading global professional services company that helps the world’s leading businesses, governments and other organizations build their digital core, optimize their operations, accelerate revenue growth and enhance citizen services—creating tangible value at speed and scale. We are a talent and innovation led company with 738,000 people serving clients in more than 120 countries. Technology is at the core of change today, and we are one of the world’s leaders in helping drive that change, with strong ecosystem relationships. We combine our strength in technology with unmatched industry experience, functional expertise and global delivery capability. We are uniquely able to deliver tangible outcomes because of our broad range of services, solutions and assets across Strategy & Consulting, Technology, Operations, Industry X and Accenture Song. These capabilities, together with our culture of shared success and commitment to creating 360° value, enable us to help our clients succeed and build trusted, lasting relationships. We measure our success by the 360° value we create for our clients, each other, our shareholders, partners and communities. Visit us at www.accenture.com.

About Accenture Security
Accenture Security is a leading provider of end-to-end cybersecurity services, including advanced cyber defense, applied cybersecurity solutions and managed security operations. We bring security innovation, coupled with global scale and a worldwide delivery capability through our network of Advanced Technology and Intelligent Operations centers. Helped by our team of highly skilled professionals, we enable clients to innovate safely, build cyber resilience and grow with confidence. Follow us @AccentureSecure on Twitter or visit us at www.accenture.com/security.

Legal notice: Accenture, the Accenture logo, and other trademarks, service marks, and designs are registered or unregistered trademarks of Accenture and its subsidiaries in the United States and in foreign countries. All trademarks are properties of their respective owners. This document is intended for general informational purposes only and does not take into account the reader’s specific circumstances, and may not reflect the most current developments. Accenture disclaims, to the fullest extent permitted by applicable law, any and all liability for the accuracy and completeness of the information in this presentation and for any acts or omissions made based on such information. Accenture does not provide legal, regulatory, audit, or tax advice. Readers are responsible for obtaining such advice from their own legal counsel or other licensed professionals.