Home > Security Tips > Security Buyer's Guide > Two-factor authentication with RSA SecurID 6.0 for Windows
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

SECURITY BUYER'S GUIDE

Two-factor authentication with RSA SecurID 6.0 for Windows


Scott Sidel
01.01.2005
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RSA SecurID 6.0 for Windows
RSA Security
Price: RSA SecurID tokens: $50-60/user; Authentication Manager: $45-55/user

With the newest version of its venerable SecurID, RSA Security addresses the inherent weakness of password-based security using a key fob that generates unique one-time passcodes every minute. SecurID has been around since the mid-'80s, but, for the first time, RSA SecureID 6.0 for Windows extends two-factor authentication to domain resources and offline users.

Passwords are an administrative headache and a security risk. Static passwords can be used repeatedly if they're stolen, but strong passwords are difficult to remember -- they're long and filled with combinations of numbers, letters and characters. The common result is help desks swamped with calls about forgotten passwords. With SecurID, the user only needs to remember a four-digit PIN combined with their SecurID's one-time passcode to gain access.

In the background, an authentication agent verifies the password, and the RSA Authentication Manager (formerly called the RSA ACE/Server) decrypts the actual Windows password, and supplies it and the UserID to Active Directory.

SecurID 6.0 adds two-factor authentication for systems that are offline from the network, such as laptops. This is enabled by the Authentication Manager, which provides a series of precalculated authentication codes securely hashed and stored on the mobile device. The authentication agent acts as a mini-ACE/ Server and will compare the user-supp...



lied information to the stored codes. The offline module decrypts the locally stored Windows password and passes it to the Windows logon mechanism. The administrative console logs are updated the next time the user logs on to the network to provide an audit trail. Organizations can also set the maximum number of days a mobile, offline device can be authenticated before the user has to synchronize with the network. However, this has to be applied globally to be effective. RSA says the next version will allow this to be set by group.

Security managers will like RSA's improved support for AD, which was somewhat lacking in the previous version. During testing, we validated its ability to allow/deny login both offline and online, and received warnings when we were running out of the allowed offline days. As a security admin, we were able to provide emergency access when users ran out of offline login days or when they "lost" the fob that generates their one-time passwords. The system "recharged" the number of offline days allowed once the device reconnected to the domain. One change we did have to make on each Windows XP client with SP2 using Microsoft's Windows Firewall was to open port 2334 inbound to allow SecurID's authentication to work. This presents a potential vulnerability, especially for remote users.

Soon, RSA will support a USB key that will allow Windows users to authenticate without entering a one-time code.

With SecurID 6.0 for Windows, RSA provides the kind of authentication that networks and mobile-users need to secure today's enterprise environments.


Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




BROWSE BY TAG
Technology,   Authentication,   Compliance,   Security Buyer's Guide,   Security Token and Smart Card Technology,   Enterprise Identity and Access Management,   User Authentication Services,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Authentication
Strong authentication for businesses large and small
Keystroke dynamics makes BioPassword Internet Edition a viable authentication option
2006 Products of the Year: Authentication
Review: Newest OneSign is 'SSO for the rest of us'
Products of the Year: Authentication and authorization

Security Buyer's Guide
Keystroke dynamics makes BioPassword Internet Edition a viable authentication option
Access security with KoolSpan's SecurEdge
NetChk Protect 5.5
Biometrics: Best practices, future trends
2006 Products of the Year: Emerging Technologies
Secure Sphere 2.0
Scan & Deliver: SLAs force service providers and outsources to hit the mark ... or hit the road
Secure remote access: SSH Tectia Manager
Spycatcher Enterprise 3.2
Configuresoft's Enterprise Configuration Manager v4.7

Security Token and Smart Card Technology
First Data, RSA push tokenization for payment processing
How to log in to multiple servers with federated single sign-on (SSO)
Best Authentication Products
Are 'strong authentication' methods strong enough for compliance?
Risk management must include physical-logical security convergence
RSA researcher Ari Juels: RFID tags may be easily hacked
Portable security storage device could replace OTP devices
Can you combine RFID tag technology with GPS to track stolen goods?
Security token and smart card authentication
Embedded smart card chips are open to hack attacks

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
authentication server  (SearchSecurity.com)
Chameleon Card  (SearchSecurity.com)
key chain  (SearchSecurity.com)
key fob  (SearchSecurity.com)
key string  (SearchSecurity.com)
national identity card  (SearchSecurity.com)
security token  (SearchSecurity.com)
smart card  (SearchSecurity.com)
tokenization  (SearchSecurity.com)
two-factor authentication  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts