Re: 2nd hand RSA SecurID tokens + ACE server

From: cissp (cissp_at_hotmail.com)
Date: 08/29/03


Date: Fri, 29 Aug 2003 05:23:22 GMT


"/dev/null" </dev/null@spamfreeworld.uni> wrote in message
news:3f4ca6f9$0$280$4d4ebb8e@read.news.nl.uu.net...
>
> Hi,
>
> For a small office (my wife can 3 of her colleagues) I like to implement
> one time based token authentication. I'm currently OPIE/S-key for remote
access
> which works ok but is not particularly user friendly.
>
> My thought is to convert these users to token based authentication
possibly
> without paying $ 10k. On Ebay you can buy RSA SecurID Tokens, they are
> reasonably prices ($7 p/token), I still have an old Sun Sparc 20 around
with
> Solaris 2.6 which could run as an SecurID/Ace server.
>
> Does anybody know if it's possible to buy a 2nd hand SecurID/Ace server +
licence
> and configure the tokens bought on E-bay to authenticate against this
server like
> I propose. Or would I run into problems with either the licencing
agreements with
> RSA or with something like the the token seed decryption?
>
> Thanks in advance,
>
> - Brendan
>

It has been awhile since I read through the ACE/Server license. I don't
think it is transferable. The other issue you will have is getting the
token seed data. The token alone is of no value. You must also have the
seed record that defines the token to the ACE/Server.



Relevant Pages

  • Re: RSA SecureID on Solaris
    ... Your tokens are provided with a floppy disk which contains an encrypted ... In fact it depends of the agent and the type of the token. ... SecurID PINPAD and Software SecurID where Pincode is given to ... some of them use securID authentication to ...
    (Focus-SUN)
  • Re: WSE 2.0 Custom Authentication
    ... you may want to look at the Security Context Token (SCT) that is ... ;)) that relates to WS-SecureConversation. ... Symmetric Key Tokens are used ... > My user authentication method is as follows: ...
    (microsoft.public.dotnet.framework.webservices.enhancements)
  • Re: electronic-ID and key-generation
    ... basically electronic-ID is authentication. ... chips supposedly are used in tokens to allow verification of the token ... for instance, x9.84 standard for biometrics ...
    (sci.crypt)
  • [Full-disclosure] Re: RSA SecurID SID800 Token vulnerable by design
    ... 2-factor authentication is not a way to protect against malware. ... login once and the browser will take care of rest. ... of the whole process) marked that OTP as used. ... I think these tokens offer excellent means for authentication. ...
    (Full-Disclosure)
  • Re: Architecture Advice
    ... Kerberos only works if your client application and your service are in the ... WS-Federation with SAML has the following benefits over Kerberos: ... Could you point out the benefits of sts over Kerberos authentication in ... the architecture for an application that uses SAML tokens ...
    (microsoft.public.dotnet.framework.webservices.enhancements)