Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Secure-Shell
[Top] [All Lists]

RE: SecurID and SSH

Subject: RE: SecurID and SSH
Date: Thu, 2 Mar 2006 18:59:45 -0700

Thanks Cornelius,

I did try the pam solution, RSA has a client on their website and claims to be 
usable with 4.1p1 so I downloaded that and compiled everything together. It all 
 seems to work up until the user enters the passcode, even with known good 
tokens it fails. The Ace server is giving errors saying invalid passcode.

Has anyone on the list used the RSA client with securID rather than radius and 
had any luck? 

Thanks
Doug Leece


-----Original Message-----
From: Cornelius Koelbel [mailto:cornelius.koelbel@gmx.de]
Sent: Thursday, March 02, 2006 3:53 PM
To: secureshell@securityfocus.com
Subject: Re: SecurID and SSH


Hi there,
I have tested two different ways:
The one is to take an OTP-Token - in my case the Aladdin eTokenNG - and
just change the pam config using the pam_radius module.
This works without fiddling around with the code.
But the even nicer way is, to use smartcards to authenticate against the
ssh-server. There is a pkcs11-patch for openssh that enables you to use
the private key from your smartcard.
regards
Cornelius
Doug.Leece@bell.ca schrieb:
Hello,

I have had a request to implement 2 factor authentication for some servers 
running SSH. We already have an extensive RSA SecurID infrastructure so that 
seems the obvious  choice. I have tracked down a patch to the code that 
supports SecurID, http://www.omniti.com/~jesus/projects and I was wondering 
if there is a better way or if anyone has had success implementing SecurID 
authentication for OpenSSH.
Thanks in advance,
Doug Leece

 


--
Diese Nachricht wurde auf Viren und andere gefährliche Inhalte untersucht
und ist - aktuelle Virenscanner vorausgesetzt - sauber.
MailScanner dankt transtec Computer für die freundliche Unterstützung.



<Prev in Thread] Current Thread [Next in Thread>