PAL PIV Card MFA Configuration
NOTE: The steps in the following section must be completed in sequence and immediately following one another. Once PIV authentication is enabled, you must then immediately add your account credentials to ensure you are able to log in to the application. If you enable PIV but do not configure your account for PIV login, you could inadvertently lock yourself out of the application.
1.Configure MFA for PIV
To enable MFA via PIV in FOIAXpress:
Log into FOIAXpress and Access Administration.
Click on Security on the left-hand navigation panel.
Change the MFA Type to PIV.
Click the Save button.
Immediately move to the next section and complete these steps
2.Configure Users PIV Certificates
For each user, configure the PIV certificate field by performing the following steps:
NOTE: First configure your Administrator account to ensure you can log back into the application now that PIV authentication is enabled.
Access the Administration tab in FOIAXpress.
Click on Organization Setup on the left link panel, the click Users.
Open the user details by selecting that userās row and clicking Edit.
Populate the Certificate Subject field with the value of the user's PIV certificate subject. This should be in the form "CN=[value]" where [value] is either a name or email address. This value can be obtained by checking the details of the certificate the user will use.
Click Save once complete.
Once enabled, FOIAXpress users will be prompted by their browser for their PIV certificate when accessing the application. They will then proceed to the login page where they may enter their username and password normally. When attempting to login, the user's certificate will be verified in addition to their username and password.
2.1 Configure MFA for PIV in PAL Configuration
To configure setup MFA via PIV :
Log into PAL Configuration.
Click on Security on the left-hand navigation panel.
Change the MFA Type for PAL Admin Login to PIV.
NOTE: This option was formerly called OTP Type For Pal Login.
Click the Save button
2.2 Configure Users PIV Certificates
For each user, configure the PIV certificate field by performing the following steps:
NOTE: First configure your Administrator account to ensure you can log back into the application now that PIV authentication is enabled.
Log into PAL Configuration
Click on Users on the left-hand navigation panel.
Open the user details by clicking the Login cell for the row, or selecting the row and clicking Edit.
Populate the Certificate Subject field with the value of the user's PIV certificate subject. This should be in the form "CN=[value]" where [value] is either a name or email address. This value can be obtained by checking the details of the certificate the user will use.
Click Update once complete.
Once enabled, PAL Config users will be prompted by their browser for their PIV certificate when accessing the site. They will then proceed to the login page where they may enter their username and password normally. When attempting to login, the user's certificate will be verified in addition to their username and password.