Great Circle Associates Firewalls
(September 1996)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: RE: S/key & secureid
From: Jüri Kaljundi <jk @ stallion . ee>
Organization: MicroLink OnLine
Date: Wed, 4 Sep 1996 15:26:07 +0300 (EET DST)
To: Firewalls @ GreatCircle . COM
In-reply-to: <199609040800 . BAA07209 @ miles . greatcircle . com>

From: Jon Tegethoff <jet @
 cypher-sage .
 com>
>
> >Again, I strongly advise against using SecurID (or any other authentication-
> >only solution) for incoming Internet connections to an internal system.
> 
>       Since there is a significant reason in many cases to have remote users 
> communicating through a firewall, what do you currently consider the best 
> method with todays technology.  My preference is a combination of two factor 
> authentication (like SecurID or one of the challenge/response cards) used 
> together with an encryption tunnel like Raptor Eagle's).

SSH and F-Secure products are quite good for secure login. SSH forms a
secure tunnel between the remote user and unix host, and SSH does support
SecurID tokens for authentication. It does mean you probably should allow
incoming SSH connections (tcp port 22) and run SSH daemon on the unix
machine. The best part is that SSH does not use some weak breakable
US-export encryption, but strong IDEA or 3DES. 

Have a look at http://www.ssh.fi/ or http://www.datafellows.com/f-secure/

Jüri Kaljundi
AS Stallion
jk @
 stallion .
 ee


Indexed By Date Previous: Queries on HTTP server and firewalls
From: kesavan . p . nair @ bangate1 . tek . com
Next: RE: Subject: C2 certified OS that can run a firewall
From: mcnabb @ argus . cu-online . com (Paul McNabb)
Indexed By Thread Previous: RE: S/key & secureid
From: Jon Tegethoff <jet @ cypher-sage . com>
Next: FW-1 2.0 & FTP Problem
From: "Jefferson M. Mousseau" <jeffm @ io . org>

Google
 
Search Internet Search www.greatcircle.com