Ho do I present custom evidence of authentication to a server?

From: Danny van Kasteel (Kasteel_at_discussions.microsoft.com)
Date: 06/29/04


Date: Tue, 29 Jun 2004 05:33:01 -0700

Hi,

First off, I'm developing a multi-tier application framework.

I'm trying to have client applications perform authentication using a biometrics device (or any other method that does not check my login server for credentials).

The problem after the authentication succeeds, is that the client now may be fully aware of the legitimacy of the user, but the server needs to be notified of this as well. So how do I present evidence of this fact to the server, i.e. say to the server "Joe here has been authenticated using biometrics, so please add a biometrics authorization to his session"?

The problem is that I'm communicating to the server under the assumption that the user may be hostile. (i.e. an attacker could be trying to trick the server into believing he was fingerprint-authenticated when he never was).

So the real question is: how can I verify that a message the server is receiving is actual PROOF of the successful authentication?

Many thanks in advance,
Danny van Kasteel



Relevant Pages

  • Re: Kerberos machine authentication - apparent authentication fail
    ... > until logon), the wireless connection can kick off when it is ready. ... > was confirmed in the server event logs with IAS (i set that up as the radius ... > as an ordinary user kicks in and takes over from the machine authentication. ... > while the network sorts itself out and a double click on a network link of ...
    (microsoft.public.windows.server.security)
  • Re: Basic Authentication + IIS 5 + Windows 2000 + Frontpage 2002 = failure?
    ... SYSTEM account. ... In IIS I took the virtual server that I was testing, ... Authentication premise. ... From a website perspective, I ...
    (microsoft.public.inetserver.iis.security)
  • Need help configuring Wireless Connection profile
    ... I have an SBS 2003 server and a Server 2003 member server set up using RADIUS ... Windows authentication for all users,4129,LRG\ryanv,4149,Wireless WPA2 PEAP ... Certificate Services ...
    (microsoft.public.windowsxp.general)
  • Re: Remote Web Workplace Issues-Please help!
    ... Open the Server Management Console, ... client after Authentication" right. ... permissions, and Microsoft Windows user rights according to the KB 812614. ... Download the IIS Resource Kit tools from the following page: ...
    (microsoft.public.windows.server.sbs)
  • [REVS] NTLM HTTP Authentication is Insecure By Design
    ... in front of a web server, and that proxy server shares a single TCP ... These are attacks that make use of non-RFC HTTP requests (HTTP Request ... the authentication is associated with the ...
    (Securiteam)