Installation of the Octopus RADIUS Agent provides support for authentication using the RADIUS protocol. The RADIUS Agent changes the local RADIUS call to a secured REST API call, allowing local RADIUS clients to connect to the Octopus Authentication Server.


The Octopus RADIUS Agent can be configured to work with either the Octopus Authenticator, the ForgeRock Authenticator or Okta Verify (through SDO 3rd party authenticator). The ForgeRock integration supports the push notification, OTP or simple (username / password) methods of authentication. The Okta Verify integration supports push notification.


This document describes how to install the Octopus RADIUS Agent on a Windows machine.


Supported Environments

The Octopus RADIUS Agent can be installed on the following operating systems:

  • Windows 10

  • Windows 11

  • Windows Server 2016

  • Windows Server 2019

  • Windows Server 2022

Important: Windows 8.1 and Windows Server 2012 are not supported.


Prerequisites

Before beginning the installation, verify that you have Admin privileges on the target Windows machine. In addition, make sure that you have:

If you plan to use the ForgeRock Authenticator or Okta Verify, make sure that you have properly set up the relevant third-party authenticator in the Octopus Management Console (Configuring Third-party Authenticators).


Octopus Management Console Configuration

The following sections describe how to set up the Management Console to support use of the Octopus RADIUS Agent:

Creating the Active Directory Authentication Service


The following procedure explains how to create an ADPA service in the Octopus Management Console. Some of the service settings will be required later, during installation of the Octopus RADIUS Agent.


To add and configure the ADPA service:

  1. From the Octopus Management Console, open the Services menu and click Add Service. In the ADPA tile, click Add.


    AddServiceADPA.png

    Then, in the dialog that opens, click Create.


    image12.png


  2. Review and configure the following settings in the General Info tab:


    Setting

    Value / Notes

    Service Name

    ADPA

    Issuer

    Secret Double Octopus

    Description

    Notes about the service

    Display icon

    The icon that appears on the Login page for the service. To change the default icon, click and upload the image of your choice (supported size 128x128 pixels).


    ADPA_GeneralInfoTab.png

    Then, click Save.

  3. Open the Parameters tab. Under Login Identifier, select the identifier(s) required to log into the service. (It is recommended to select Email and Username.) Then, click Save.

    ADPA_ParametersTab.png

  4. Open the Directories tab and select the checkbox(es) of the directory / directories to be integrated with the service. Then, click Save.

    Services_DirectoriesTab_v5_8.png

  5. Open the Users tab. In the upper left corner of the tab, click Add.

    A popup opens, with a list of directories displayed on the left.

  6. Expand the directories list and select the checkboxes of the groups and users that you want to add to the service. Then, click Save to close the popup.

    The groups and users you selected are listed in the Users tab.

  7. At the bottom of the Users tab, click Save. Then, from the toolbar at the top of the page, click PUBLISH and publish your changes.

Configuring Third-party Authenticators


If you use Okta Verify or ForgeRock Authenticator, a third-party authenticator needs to be added to the Management Console and selected as an additional authenticator in the settings of the integrated directory. For complete details about adding third-party authenticators, please refer to the Octopus Management Console Admin Guide.


To configure a third-party authenticator:

  1. From the System Settings menu of the Management Console, select the Authenticators tab. Verify that the relevant third-party authenticator has been added, and that it is enabled and connected.

    ThirdPartyAuthenticators.png

  2. From the Directories menu, in the row or card of the relevant directory, click the Edit icon to open the directory settings.

    DirectoriesList.png

  3. Select the Authenticators tab. From the Additional Authenticator list, select the relevant authenticator. Then, select the appropriate Authenticator User Mapping (usually Email).

    AdditionalAuthenticator.png

  4. At the bottom of the Authenticators tab, click Save. Then, from the toolbar at the top of the page, click PUBLISH and publish your changes.

Installing the Octopus RADIUS Agent

Follow the steps below to install the RADIUS Agent. Before you begin, make sure you have access to the following components from the Sign on tab of the ADPA service that you created in the Octopus Management Console:

  • Endpoint URL: Click the Copy icon to copy the URL.

  • Service Key: Click View. Then, from the popup that opens, click the Copy icon to copy the key.

  • X.509 Certificate: Click the Copy icon to copy certificate contents.

ADPA_SignOnComponents.png

To install the Octopus RADIUS Agent:

  1. Right-click on the OctopusRadiusAgent.exe file and select Run as administrator.


    image19.png


    The installation wizard opens.


    image20.png


  2. On the Welcome screen, click Next.


  3. On the License Agreement screen, accept the terms and then click Next.

  4. On the Custom Setup screen, click Next.


    image23.png


  5. On the Destination Folder screen, click Next.


    image24.png


  6. On the Logon Information screen, enter the user credentials for the account using the SDO RADIUS service. Make sure the syntax for the username is Domain\Username.


    image25.png


  7. On the Agent Parameters page, select either the SDO checkbox OR the ForgeRock checkbox, according to the authenticator that you want to configure. (Only ONE of these checkboxes can be selected.) For Okta integration, select SDO.


    image26.png


    After making your selection, continue as follows:

    • If you selected SDO, continue with Step ‎8.

    • If you selected ForgeRock, go to Step ‎9.

  8. For Octopus Authenticator / Okta Verify: Configure the required settings by copying them from the Sign on tab of the Octopus ADPA service settings.

    Setting

    Setting in Sign on Tab

    Endpoint URL

    Endpoint URL

    API Key

    Service Key

    X.509 Certificate

    X.509 Certificate


    image27.png

    After copying these settings, go to Step ‎10.

  9. For ForgeRock: Configure the required settings by entering the relevant URL and Realm for your ForgeRock environment. In the Journey field, enter the journey / tree value for ONE of the following authentication methods:

    • Push (e.g., pushpass)

    • OTP (e.g., otppass)

    • Simple (e.g., simple)


    image28.png


  10. Review the default values in the Radius Server section and if necessary, change them to match the configuration for your RADIUS server.


    image29.png


  11. Review the settings in the Authenticator section and verify that they match the authenticator type and method that you configured. If necessary, you can correct the Authenticator configuration by selecting the correct settings from the dropdown lists.

    For OTP authentication, select SDONG for the Type and SDONGTotpMfa for the Method.

    OTPAuthenticatorTypeMethod.png

    For Okta Verify, select SDOThirdParty for the Type and Push for the Method.


    image31.png


  12. Click Next.

  13. To begin the installation, click Install.


    image33.png


    A status bar is displayed during the installation process.


    image34.png


  14. To exit the installation wizard, click Finish.


    image35.png


Post-installation Verification Checks

Following installation, it is recommended to carry out the following checks to verify that your environment has been set up as expected:

  • Make sure that the SDO Radius Service is installed and running.


    image36.png


  • Verify that all the folders and files shown in the figure below are installed under C > Program Files > SecretDoubleOctopus > Radius Agent


    image37.png


  • Verify that the log files have been installed in the following location:

    LogFiles.png

Uninstalling the Octopus RADIUS Agent

The RADIUS Agent may be uninstalled at any time via the Control Panel of your Windows machine.

From the Control Panel, navigate to Programs > Programs and Features. Then, select Octopus Radius Agent and click Uninstall.


image38.png


Appendix: Post-installation Configuration

The following sections present optional post-installation procedures.


Changing the RADIUS Secret


After installing the RADIUS Proxy, it is recommended to change the secret used during the installation process. You can change the secret using the ConfigTool that is provided as part of the installation files and folders.


ConfigTool.png

To change the RADIUS secret:

  1. Run the ConfigTool.exe file with CMD. To display a summary of information and instructions, enter --help.

    RunConfigTool.png

  2. Change the secret by running the following command:

    set-secret --secret <new secret>

    For example:

    SetSecret.png

  3. Restart the SDO Radius Service.

    RestartService.png

Passing User Group Membership in the RADIUS Response


You can configure group memberships to be included in the RADIUS response by updating settings in the appsettings.Production JSON file.


To pass group membership in the RADIUS response:

  1. Open the appsettings.Production file for editing.

    AppsettingsProduction.png

  2. In the Groups array, set the Enabled value to true. Then, for the Whitelist value, enter the name(s) of the relevant Active Directory group(s).

    For example:

    image21.png

  3. Restart the SDO Radius Service.

Footer - Secret Double Octopus