Home > Ask the Security Experts > Identity Management and Access Control Questions & Answers > Can enterprise single sign-on (SSO) provide authentication for remote logons?
Ask The Security Expert: Questions & Answers
EMAIL THIS

Can enterprise single sign-on (SSO) provide authentication for remote logons?

Joel Dubin EXPERT RESPONSE FROM: Joel Dubin

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 02 December 2006
I am accessing multiple applications through a remote Citrix server, which has three or four applications that I use regularly. Can I use enterprise single sign-on (SSO) to provide authentication for the remote application as well?

>
EXPERT RESPONSE
There are two ways to implement enterprise single sign-on (SSO) for remote logons. One is to use Citrix itself, which you already have, and the other is to set up an SSL VPN with another provider.

Citrix Password Manager lets users sign on whether they're already in the network and behind the corporate firewall, or whether they're off-site and remotely logging in from outside the firewall. The product uses the Citrix Presentation Server to manage passwords, and users can access their accounts with the Citrix Web Interface. Password Manager has been enhanced for SSO, too, and integrates with Active Directory.

Password Manager is fully automated, and users can set themselves up and reset passwords on their own without having to call the help desk.

Another approach for remote user authentication is an SSL VPN. An SSL VPN allows specific remote users to connect to particular internal applications, which is what you're trying to do here. This contrasts with a traditional IPsec VPN, which connects a workstation to a network.

As for combining SSO with an SSL VPN, Aventail Corp. now offers SSO access in its beefed- up ST2 platform. Aventail is a leading vendor in the SSL VPN market and integrates with Active Directory, LDAP and RADIUS, an authenticating server for remote users.

Another top player in the SSL VPN arena is Juniper Networks Inc. Juniper joined forces with RSA Security (which is now owned by EMC Corp.) to add SSO functionality to its SSL VPN offering. The RSA Federated Identity Manager handles the SSO side of the application and integrates into existing corporate directories.

The key point to remember with SSO is that it cuts both ways. With a single user ID and password for multiple applications, it provides real ease of use for your employees. That ease of use, however, extends equally to malicious users trying to get into your system. In one stroke, an entire network can be compromised.

Whichever SSO solution you choose, make sure it's secure, harden all SSO hardware and software and educate users in safe password handling practices.

More information:

  • Set up endpoint security features on a Juniper SSL VPN.
  • Learn more about VPNs in our Network Access Control Learning Guide.


  • Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Identity Management and Access Control
    What are the pre-requisites for implementing single sign-on (SSO) in an organization?
    To what exactly would a request for biometric data from an insurance provider pertain?
    Is it possible to support users to have their own IDs with root privilege so they aren't sharing a root password?
    What is the purpose of RFID identification?
    CardSpace vs. user IDs and passwords
    Biometrics vs. biostatistics
    What are the dangers of using radio frequency identification (RFID) tags?
    What are the risks of connecting a Web service to an external system via SSL?
    What should an internal support model for identity management look like?
    How are biometric signatures more than a fingerprint scanner?

    SSL
    Debian: A niche OS with a not-so-niche security flaw
    The Shortcut Guide to Extended Validation SSL Certificates
    Product review: Array Networks SPX2000
    How to test the security of personal details submitted to a website
    Should enterprises implement a mandatory iPhone VPN?
    Should iPhone email be sent without SSL encryption?
    How to secure an FTP connection
    Can Trojans and other malware exploit split-tunnel VPNs to infiltrate a network?
    What are the risks of connecting a Web service to an external system via SSL?
    What is the most secure way for application developers to manage cookies?

    Enterprise Single Sign-On (SSO)
    What are the pre-requisites for implementing single sign-on (SSO) in an organization?
    Startup Symplified delivers SSO in the cloud
    SaaS Offering Handles SSO
    Kerberos security evolves for B2B, mobile tech
    IBM acquires Encentuate for single sign-on software
    Security360: Identity management market
    Top 10 access-related controls for PCI compliance
    What type of protections should security question and answer authentication credentials have?
    Traditional single sign-on (SSO) products versus federated identities
    Best practices for deploying enterprise single sign-on (SSO)
    Enterprise Single Sign-On (SSO) Research

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    SSL VPN  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice



    Find Security Solutions for Your Business
    Targeted Security Channel Tips for Resellers, Integrators and Consultants
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts