Re: SecurID and FreeS/WAN GW
From: Bennett Todd (bet@rahul.net)Date: 03/22/02
- Previous message: Kee Hinckley: "Re: SecurID and FreeS/WAN GW"
- Maybe in reply to: RussellJ@louisdreyfus.com: "SecurID and FreeS/WAN GW"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Date: Thu, 21 Mar 2002 18:54:41 -0500 From: Bennett Todd <bet@rahul.net> To: Kee Hinckley <nazgul@somewhere.com>
2002-03-20-20:14:18 Kee Hinckley:
> >[ re web page to auth for IPSec ]
> >Sorry? It'd be possible with any web browser and a standard IP
> >stack, as opposed to impossible without a specific, proprietary,
> >vendor client.
>
> Quite true. But that has nothing to do with ease of use.
Sure. That's below.
> >And if you had some specific behaviour you wanted --- e.g. a
> >commandline or gui that prompted for the username and auth
> >credentials, then fired them off at the server and started up IPSEC,
> >it'd be easy to script in any reasonable language; all the
> >interactions are at least standardized.
>
> Yes, but if something goes wrong, debugging it is not fun.
Why do you believe this would be more fragile than a similar, but
undocumented, non-standard hack by a vendor?
> You have to worry about firewalls, proxy servers and many other
> things.
Always. But at least with this approach you know exactly what you
have to [try to] fix.
> At some large companies external web access isn't allowed for all
> users, those users wouldn't be able to use the VPN.
I'm missing something here. I have great difficulty picturing an
environment where you couldn't visit a web page to auth, but you
could make a VPN work. When web browsing is blocked off, so are
other internet protocols --- else the web browsing block is awfully
easy to knock through.
If you're talking about weirdness in client browser config, that's
no more problem for this hack than for a vendor's; if you can
require the user to have a vendor proprietary connect program to
pre-auth for IPSec, you could instead require the user to have your
homebrew program that does the pre-auth --- using a standard
protocol.
> All in all it sounds like a hack.
Sure it is, no question. The only point of discussion is whether a
closed vendor hack is preferable to a straightforward hack using
standard protocols.
> Far better to simply propose an extension to the standard and get
> it approved.
I've heard that that's current work in progress.
> In the meantime, from an administrative standpoint, I'd rather
> deal with an integrated, proprietary vendor solution than try and
> debug something using multiple protocols.
Multiple protocols in any case, the only question is how much info
you have to assist in debugging.
-Bennett
- application/pgp-signature attachment: stored
- Previous message: Kee Hinckley: "Re: SecurID and FreeS/WAN GW"
- Maybe in reply to: RussellJ@louisdreyfus.com: "SecurID and FreeS/WAN GW"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|
|