Just Added

Manual Schema Additions

By default, AuthLite's installer automatically adds the lastest revision of its own items and attributes to your AD schema. If needed, you can execute these changes manually instead.

Upgrade from ISA to TMG

Most of our ISA filter customers will one day decommission their ISA servers and move to the TMG platform. This article talks about our licensing costs for TMG filters.

Upgrading Server 2003 to 2008

Notes on upgrading Windows Server 2003 to 2008 (including domain controller) when AuthLite is installed.

AuthLite on UAG

Required configuration for using AuthLite OTPs on Microsoft UAG

AuthLite Permission to program Split Keys

By default only Domain Admins are allowed to program split-mode AuthLite keys for other users. You can change a setting to allow other groups this access.

Install AuthLite without GINA/Credential tile

If you are only using Split mode users, there is generally no need to install the logon user interface extension that AuthLite provides.

Install error: The directory service is busy

When installing AuthLite on a Domain Controller, you receive a popup error stating: > Error while executing custom action: The directory service is busy. and the install rolls back.

Share AuthLite key across multiple domains or standalone machines

Describes a procedure to share AuthLite keys between two domains or standalone machines, and the security implications of this configuration.

Configuring Cisco ASA to use MS-CHAPv2 with AuthLite

AuthLite's RADIUS service expects two-factor authentication requests to use the MS-CHAPv2 protocol, but there is no obvious way to turn this on in a Cisco ASA.

Access Denied error on install

When installing AuthLite on the first domain controller in your organization you receive a pop-up "General access denied error"

AuthLite PowerShell provider

Administrators can use Microsoft(r) Windows PowerShell to gain programmatic access to the AuthLite data store.

AuthLite and Citrix

Instructions for using AuthLite to add two-factor security to Citrix through the Citrix Web Interface.

Service marked for deletion

During installation, you receive the message "The specified service has been marked for deletion"

RDP and Network Level Authentication

The RDP client version 6 and later collect credentials before establishing a remote session. AuthLite credentials must be entered into the RDP client before the connection is made.

Program a key over RDP

Normally AuthLite keys can only be programmed when directly connected to the computer running the configuration program, not over remote desktop. There is a work around.

Unattended deployment of AuthLite

In medium/large organizations, visiting each workstation to install the AuthLite software is not practical. This article contains pointers on deploying with Group Policy Objects (GPO)

Installation on Server Core

AuthLite can be installed on 2008 Server Core R2, but not R1 because it lacks the .NET framework

Exclude by IP address

You want to add an IP address to the ClearTunnel Excluded Sites list.

Web filters are not working

You have installed a web filter and it appears to be having no effect even though you configured the settings properly.

SecureNAT connections fail with Captivate

When you configure Captivate to authenticate SecureNAT users, the connections are blocked, or the captive portal screen is never shown.