RE: TTY Login

From: JM (jm_at_mindless.com)
Date: 11/27/03

  • Next message: Todd Gorman: "RE: Log Management Software"
    To: "'Thiago Lima '" <thiagolima@webforce.com.br>, <security-basics@securityfocus.com>
    Date: Thu, 27 Nov 2003 18:04:53 -0000
    
    

    Ideally use strong authentication where possible.

    Or..Use a similar password across the board, i.e. Password

    So for ABC LTD password = ABCPasswordLTD
    For EXY Corporation password = EXYPasswordLTD

    Replace Password with something a little stronger, or, you must have some
    sort of client reference for them, i.e. The client is rich (TCIRPassword) or
    The client is useless (TCIUPassword)

    But, ideally strong authentication, and use ssh....

    -----Original Message-----
    From: Thiago Lima [mailto:thiagolima@webforce.com.br]
    Sent: 27 November 2003 14:57
    To: security-basics@securityfocus.com

        Hi Folks,

        Let me explain my problem :

        I have several machines in many locations, they're firewalls for my
    clients. I don't like idea for writing down all root passwords for 2
    reasons :
            1) security
            2) Every time I went to a client I would have to bring the root
    password with me

        So I thougth about those securitycards that can generate root
    passwords on the fly based on some algoritmh. If I went to the client I
    could just see a PIN (right?) on screen and then calculate the root
    password. I know there's some "CARDS" that can do that, even if I don't
    really know the name of one, but there's any that gives me the same
    thing without a card? That I could calculate using other software?

            If you guys could point me to some urls or texts that would be
    great.

    regards
    thiago

     

    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------

    ---------------------------------------------------------------------------
    ----------------------------------------------------------------------------


  • Next message: Todd Gorman: "RE: Log Management Software"

    Relevant Pages

    • Re: Windows Authentication, Single sign on and Active Directory
      ... service proxy client fails to connect due to authentication failure and then ... Co-author of "The .NET Developer's Guide to Directory Services Programming" ... The server is always in the domain. ...
      (microsoft.public.dotnet.framework.aspnet.security)
    • Re: BASIC authentication Issues with IE - Part II - Solved but WHY?
      ... it does not know the difference between a request from IE or from ... some other HTTP client. ... Some other authentication schemes are more ... IIS can sometimes remember the token for a particular set of credentials so ...
      (microsoft.public.inetserver.iis.security)
    • Re: Sporadic IAS Authentication problems
      ... * Some times however, a physical reboot of the client laptop is required, ... *The remote access policy in IAS is set to grant access to the group 'Domain ... Proxy-Policy-Name = Use Windows authentication for all users ...
      (microsoft.public.internet.radius)
    • Re: ISAPI Authentication
      ... The job of your authentication filter is to accept ... non-Windows credentials from the client and then map them to a Windows ...
      (microsoft.public.inetserver.iis.security)
    • Re: WCF security advice (and clarification) needed
      ... You, the client, resolve the foo.mycompany.com hostname within your ... TCP/IP) with that ticket as the security token. ... There are two parties participating in a security scenario, the server ... HTTP supports other authentication ...
      (microsoft.public.dotnet.framework.webservices)