Re: s/key authentication for Apache on FreeBSD?

From: Andrew Kenneth Milton (akm_at_theinternet.com.au)
Date: 12/11/03

  • Next message: bruce_at_nikkel.com: "Re: s/key authentication for Apache on FreeBSD?"
    Date: Thu, 11 Dec 2003 18:33:37 +1100
    To: Brett Glass <brett@lariat.org>
    
    

    +-------[ Brett Glass ]----------------------
    | An excellent reason to use SSL together with S/key.

    I'm not sure about the physical setup you have, but, here goes.

    Why don't you issue certificates to each user, that have a fixed life span,
    say a week (or day or a few hours), and avoid the password thing altogether?

    If you can generate pieces of paper to hand out, you can generate a
    certificate per user that get assigned / refreshed before they leave.

    You could even just revoke the certificate if/when lost, if the assignment
    of a new certificate is overly burdensome.

    Once the certificate is revoked even having physical possession of the palm
    pilot won't give you access. There's no passwords to write down, and there's
    no user interactions to sniff/log.

    You should be able to use a certificate at a cafe via floppy/cd/USB key (I
    guess, I've never been to one), if this is the normal usage pattern, I'd be
    making the lifespan of the certs very small.

    -- 
    Totally Holistic Enterprises Internet|                      | Andrew Milton
    The Internet (Aust) Pty Ltd          |  M:+61 416 022 411   |
    ACN: 082 081 472 ABN: 83 082 081 472 |akm@theinternet.com.au| Carpe Daemon
    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
    

  • Next message: bruce_at_nikkel.com: "Re: s/key authentication for Apache on FreeBSD?"

    Relevant Pages

    • Re: Certificate revokation
      ... Is there a way to revoke a certificate and that the revokation will be ... > delta CRL that can be published every few hours with only the changes ... As long as it is valid clients can cache it and use ...
      (microsoft.public.windows.server.security)
    • Re: SMS 2003 SP1 Client Install Problem or Policy Retreival Problem?
      ... The MP is setup and thousands of other clients have access. ... Failed to find the certificate in the store, retry 1. ... > see if there are errors connecting and finding site assignment. ...
      (microsoft.public.sms.admin)
    • Re: How to revoke the root CA certificate ?
      ... This is why protecting the root CA's priv key is so vital. ... have issued any certs for use from the root, so first revoke all certs for ... >>>I have a standalone certificate authority on Windows Server 2003, ... But what certificate is used to sign the CRL... ...
      (microsoft.public.windows.server.security)
    • Re: Revoked Security Certificates
      ... The owner of a certificate can often revoke it him/her self, ... the company no longer wants the certificate to be used, ... > I was trying to purchase a product at a website. ... > alert stating that the site had a revoked security ...
      (microsoft.public.security)
    • Question on autoenrollment process with revoked certificate.
      ... I have an issue on autoenrollment which I need ... If I revoke one such certificate using the MMC snap-in, ... at the backend and gets refreshed in the revoked certificate area of the ...
      (microsoft.public.security)

  • Quantcast