Re: Tectia 5 Certificate Authentication



So what I want to do is setup the server to allow authentication by
one of the following methods.

User A - password only
User B - publickey only
User C - keyboard interactive only
User D - gssapi only

User E - publickey, Certificate only, where the certificate method is
qualified by selectors requiring a correct pattern match on the user
certificate subject and required to have been issued by the CA
certificate located in the ssh-server-config.xml file, and that the
user certificate pass the normal revocation checks.

User F - publickey, including both the normal publickey method and the
certificate method, with the user certificate qualified the same as the
User E criteria.

I do not want to limit any given user to a specific method,
require users to have more than one method.

I don't understand; you have requirements which say various users be
allowed to use specific authentication methods "only." How is that
compatible with the last statement above?

--
Richard Silverman
res@xxxxxxxx

.



Relevant Pages

  • Re: How to use publickey from x509 certificate?
    ... > I have the following problem: I want to use publickey authentication by ... > using the publickey of a x509 certificate stored on a java card. ... You will need the private key if you want to do ssh authentication too, ...
    (SSH)
  • Re: Tectia 5 Certificate Authentication
    ... Yes, I have publickey enabled, with the associated certificate ... selectors in the ssh-server-config.xml file, however I cannot get it to ... publickey or keyboard-interactive or gssapi or certificate/with ...
    (comp.security.ssh)
  • Signature verification from signer´s PKCS7 contained cert
    ... I need to verify a PKCS7 signature against the signer certificate contained ... build a publickey to be used in CryptVerifySignature using the PKCS7 cert.? ...
    (microsoft.public.platformsdk.security)
  • Re: Engrish Proficiency ;)
    ... certificate with the new required ICOA wording of "English Proficient" ... certificate and selected my reason as the "English Proficiency". ... The FAA at its finest? ... ICAO Rule Requiring Proof Of English Proficiency Not Likely To Be ...
    (rec.aviation.piloting)
  • Re: Digital Certificate Implementation TN3270
    ... Requiring a client certificate is an unnecessary complication. ... up hundreds of SSL connections with TN3270, and none of them required a ...
    (bit.listserv.ibm-main)