CareOnMFA - Multi-Factor Authentication Proxy

CareOnMFA is an LDAP proxy endpoint that provides enhanced security through multi-factor authentication (MFA) for Netcare's authentication infrastructure. The system acts as an intelligent intermediary between client applications and the Netcare LDAP directory, adding an additional layer of security verification when required.

How It Works

CareOnMFA operates as a transparent proxy that:

  1. Receives authentication requests from client applications via standard LDAP protocols (search and bind operations)

  2. Evaluates authentication requirements by checking user attributes and prescription rights in the Oracle database to determine if additional verification is needed

  3. Performs selective MFA verification through integration with Netcare's AES (Authentication & Enhancement System) using the Trust Factory framework

  4. Routes authenticated requests to the downstream LDAP servers once verification is complete

Key Features

Technical Components

Use Cases

CareOnMFA is primarily used for: