Great Circle Associates Firewalls
(August 1997)
 

Indexed By Date: [Previous] [Next] Indexed By Thread: [Previous] [Next]

Subject: Re: PPTP & FW-1
From: Michel Lavondes <lavondes @ tidtest . total . fr>
Date: Fri, 08 Aug 1997 15:17:24 +0100
To: Eric Vyncke <evyncke @ cisco . com>
Cc: Russ <Russ . Cooper @ rc . on . ca>, "'firewalls @ GreatCircle . COM'" <firewalls @ greatcircle . com>, "'Chris Brenton'" <cbrenton @ pccmis . com>
In-reply-to: Your message of "Fri, 08 Aug 1997 10:42:50 -0000." <3 . 0 . 32 . 19970808103524 . 007412e8 @ brussels . cisco . com>

[Warning - I'm jumping in the middle of this thread and may have missed
something that was said before - so please take this post w/ a big grain
of salt]

In message <3 .
 0 .
 32 .
 19970808103524 .
 007412e8 @
 brussels .
 cisco .
 com>, Eric Vyncke wri
tes:
> 
> [Discussion about MS-CHAP snipped]
> 
> Not sure for SecurID, but, beware that most token card servers
> must receive the user password in clear text to do the authentication
> testing... so the only PPP authentication method is PAP (i.e. in clear
> text) and 
> neither CHAP nor MS-CHAP.

Hmm, are you sure ? I thought that most password-activated access tokens
worked by performing some kind of hard-to-reverse computation on the user's
password (and/or login name) and either a challenge value sent by the
server or a time-synchronous value computed independently by the server and
the token (this is how securid tokens work AFAIK). If you're right, I may
have to revise my opinion of access tokens downward :-). Granted, even if I
understand it right, it means it's not exactly CHAP, but it still looks
closer to it than to PAP.

Michel Lavondes (lavondes @
 tidtest .
 total .
 fr), speaking only for himself

Myself when young did eagerly frequent
Doctor and Saint, and heard great argument
about it and about, but evermore
came out by the same door as in I went.

-- Omar Khayaam


References:
Indexed By Date Previous: RE: FW1 & PPTP
From: Russ <Russ . Cooper @ RC . on . ca>
Next: Re: IP spoofing using an ilegal IP address
From: pnash @ hanshan . bbnplanet . com
Indexed By Thread Previous: RE: PPTP & FW-1
From: Eric Vyncke <evyncke @ cisco . com>
Next: Installation of Failover Gateway in FW-1 3.0a...
From: Cihan Subasi <csubasi @ garanti . com . tr>

Google
 
Search Internet Search www.greatcircle.com