home *** CD-ROM | disk | FTP | other *** search
- Newsgroups: comp.protocols.appletalk
- Path: sparky!uunet!zaphod.mps.ohio-state.edu!malgudi.oar.net!caen!spool.mu.edu!umn.edu!csus.edu!netcom.com!jkyser
- From: jkyser@netcom.com (Jeff Kyser)
- Subject: Re: ARA and in-line authentication
- Message-ID: <1992Dec17.223819.7304@netcom.com>
- Organization: Netcom - Online Communication Services (408 241-9760 guest)
- References: <brady-161292075059@jbrady.aero.org> <haase-161292215606@mac_dialin1.meediv.lanl.gov>
- Distribution: usa
- Date: Thu, 17 Dec 1992 22:38:19 GMT
- Lines: 39
-
- haase@meediv.lanl.gov (Peter Haase) writes:
-
- >In article <brady-161292075059@jbrady.aero.org>, brady@osiapps.aero.org
- >(John Brady) wrote:
- >>
- >> Has anyone tried using an in-line authentication box (like the
- >> Digital Pathways Defender 5000) with ARA?
- >>
- >> An in-line authentication box would sit between the answering
- >> modem and the ARA server. The user would have to prove his or her
- >> identity before the authentication box would complete the connection
- >> to the ARA server. I guess the real question is can the ARA client
- >> software support this dialog prior to completion of the ARAP connection.
- >>
- >Why would you want to do that since on an ARA dial-in the user has to
- >provide a valid username and password. Seems kind of redundant.
-
- Usernames and passwords do not provide physical authentication of the user
- (i.e. anyone could call up with a valid username and password). Security
- Dynamics makes a product in which each authorized user gets a 'smart card'
- which displays a constantly changing key number. By requiring the user to
- type in the key number along with name and password, the system can be
- assured with a great degree of certainty that the person logging in is in
- posession of the card. Key numbers are only good once, so even if someone is
- eavesdropping and manages to replay the session, the login would still fail.
- There are a number of other options depending on security requirements.
-
- I know that they are planning an ARA interface for this product, but am not
- sure if it has been released yet.
-
- Jeff
-
-
- >*******************************************************************
- >Peter Haase haase@meediv.lanl.gov
- >Los Alamos National Laboratory Applelink: HAASE
- >Mechanical Electronic Engineering Division 505-667-2684
- --
- Jeff Kyser jkyser@netcom.com {amdahl,apple,claris}!netcom!jkyser
-