RE: RADIUS PAP-SecurID Access-Challenge

This is a discussion on RE: RADIUS PAP-SecurID Access-Challenge within the FreeRADIUS Users forums, part of the Networking and Network Related category; I'm sorry, The other day I said that there is nothing "unusual" about SecurID RADIUS authentication. I'...


Go Back   Usenet Forums > Networking and Network Related > FreeRADIUS Users

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 11-28-2006
david@mitton.com
 
Posts: n/a
Default RE: RADIUS PAP-SecurID Access-Challenge

I'm sorry,
The other day I said that there is nothing "unusual" about SecurID
RADIUS authentication. I'm so used to EAP, I forgot about the PAP auth
with a SecurID value as a password.

If the RSA Authentication Manager, finds that the token is in New Pin
or Next Tokencode mode, it will issue an Access-Challenge message with
the Reply-Message attribute explaining the next step.
The client is expected to display the text, and prompt the user, then
send another Access-Request with the response in the password
attribute. This exchange can continue through several steps, until an
Access-Accepted or -Rejected is received.

Only a few RADIUS test clients can actually deal with this. I don't
know (off the top of my head) which production clients we recommend.

Of course, for the best security the EAP-POTP method is our
recommended authentication protocol.

Dave.
-
List info/subscribe/unsubscribe? See http://www.freeradius.org/list/users.html
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 06:45 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0