Configure MFA for PIV
To enable MFA via PIV in ATIPXpress:
Log into ATIPXpress and Access Administration.
Click on Security on the left-hand navigation panel.
Change the MFA Type to PIV.
Click the Save button.
Configure Users PIV Certificates
For each user, configure the PIV certificate field by performing the following steps:
Access the Administration tab in ATIPXpress.
Click on Organization Setup on the left link panel, the click Users.
Open the user details by selecting that userās row and clicking Edit.
Populate the Certificate Subject field with the value of the user's PIV certificate subject.
This should be in the form "CN=[value]" where [value] is either a name or email address.
This value can be obtained by checking the details of the certificate the user will use.
Click Save once complete.
Once enabled, ATIPXpress users will be prompted by their browser for their PIV certificate when accessing the application. They will then proceed to the login page where they may enter their username and password normally. When attempting to login, the user's certificate will be verified in addition to their username and password.
PAL PIV Card MFA Configuration
Configure MFA for PIV in PAL Configuration
To configure setup MFA via PIV :
Log into PAL Configuration.
Click on Security on the left-hand navigation panel.
Change the MFA Type for PAL Admin Login to PIV. Note: This option was formerly called OTP Type For Pal Login
Click the Save button.
Configure Users PIV Certificates
For each user, configure the PIV certificate field by performing the following steps:
Log into PAL Configuration
Click on Users on the left-hand navigation panel.
Open the user details by clicking the Login cell for the row, or selecting the row and clicking Edit.
Populate the Certificate Subject field with the value of the user's PIV certificate subject.
This should be in the form "CN=[value]" where [value] is either a name or email address.
This value can be obtained by checking the details of the certificate the user will use.
Click Update once complete.
Once enabled, PAL Config users will be prompted by their browser for their PIV certificate when accessing the site. They will then proceed to the login page where they may enter their username and password normally. When attempting to login, the user's certificate will be verified in addition to their username and password.