|
person accessing your confidential data is authorized, legitimate, and securely connected. SecureKeyAgent has been tested with the Aladdin eToken, RainBow iKey 2000 series, the GemPlus smart card and the Sony FIU-810 fingerprint/PKI
token.
SecureNetTerm supports the SSH authentication methods of password, public/private key, Kerberos 5, S/Key, OPIE,hostbased and GSI-GSSAPI.
The GSI-GSSAPI method supports the mechanisms of Kerberos 5 external-keyx, Globus gssapi external-keyx, gssapi, and gssapi-with-mic. The gssapi external-keyx mechanism allows the userid to be determined by the SSH server using the users proxy certificate and the Globus grid-mapfile. The Kerberos 5 support is provided by the standard MIT software distribution.
SNetTerm is the advanced GUI replacement for SecureNetTerm. In addition to the authentications listed above, SNetTerm fully supports X509 certificate authentication, including user and host certificates. The SNetTerm
certificate support has been certified to work with the OpenSSH server, as modified by the X.509 patch available from Roumen Petrov) and the SSH Data Communication Tectia 5.x server. Certificate based host keys are verified using standard certificate revocation (CRL) methods including support for LDAP and OCSP responders. The standard SSH known_hosts files can be elimated by the use of a user specified certificate pattern, which the server certificate must meet in order to be accepted. In addition to the internal revocation support, SNetTerm also allows the selection of the standard Microsoft revocation process. This allows those companies that have their own LDAP/OCSP responder plugins to the Microsoft cryptoapi to be utilized.
|