Re: network-wide client authentication/authorization

From: Joachim Schipper (jDOTschipper_at_math.uu.nl)
Date: 06/21/05

  • Next message: Me: "SSHD per user config"
    Date: 21 Jun 2005 16:02:13 GMT
    
    

    Luke <clairst@uiuc.edu> wrote:
    > I'm looking for some sort of scheme to authenticate my clients to a variety
    > of services across the network.
    >
    > Some of them will be:
    >
    > Wireless access
    > Email
    > Standard login (via PAM/gdm)
    > NFSv4 or Samba (not required)
    >
    > What I want to do is for each client to only need configured once. The
    > user should be able to sign on one time, via a "normal-looking" GDM login,
    > and be authenticated to a variety of services. For instance, wireless VPN
    > protection should be started for only authorized clients automatically.
    >
    > Obviously, Kerberos with LDAP authorization makes sense here, but my
    > external address, though it has an assigned domain name, is not static, thus
    > disabling the use of Kerberos to access network services from outside the
    > netwok.
    >
    > Any thoughts on technologies that might be appropriate here? Some sort of
    > SSL system perhaps?
    >
    > Thanks

    How about having them use a VPN to connect to the internal interface
    instead? This would also secure the clients' communication channel,
    which is always a nice touch.

    Linux has IPSec support. It works well, but isn't terribly
    well-documented. With some additional work, Microsoft's idea of IPSec
    (i.e., IPSec+L2TP) can be implemented as well, though I prefer forcing
    the Windows machines to use IPSec without L2TP (look for ipsec.exe).

    OpenVPN seems to be easier to install, but has the distinct disadvantage
    of tunneling TCP only.

    I cannot comment on Kerberos, as I don't know much about it.

                    Joachim


  • Next message: Me: "SSHD per user config"

    Relevant Pages

    • RADIUS for MAC authentication in WLAN, how doing it?
      ... My issue is that I cannot authenticate my card on this setup. ... shared between the WLAN router/AP and the RADIUS server to the clients ... to the wired network using this setup. ...
      (comp.unix.bsd.netbsd.misc)
    • network-wide client authentication/authorization
      ... I'm looking for some sort of scheme to authenticate my clients to a variety ... of services across the network. ... Wireless access ...
      (comp.os.linux.security)
    • Re: Client and Server NTLM authentication
      ... an IIS6 website. ... there is a time issue in that the clients try to contact a DC in this ... cannot do this due to security lockdown at the network level). ... about 15secs the client gives up trying to authenticate with the DC ...
      (microsoft.public.inetserver.iis.security)
    • IAS authentication and Domain machine policies
      ... I have implemented in my network 802.1x security on all my cisco ... switch and 2 IAS server on my domains controllers configuring PEAP, ... authenticate the user or computer through the network are to long, ... my clients need to apply at start-up domain machine policies and user ...
      (microsoft.public.internet.radius)
    • Re: Convert SBS to Win2003 server
      ... Your clients don't have to authenticate to it.. ... >I have new SBS2003 SE that I want to connect to a network ... > need is file and print services. ...
      (microsoft.public.windows.server.sbs)