Search the web
Sign In
New User? Sign Up
securid-users · RSA SecurID Users
? Already a member? Sign in to Yahoo!

Yahoo! Groups Tips

Did you know...
Want to share photos of your group with the world? Add a group photo to Flickr.

Best of Y! Groups

   Check them out and nominate your group.
Having problems with message search? Fill out this form to ensure your group is one of the first to be migrated to the new message search system.

Messages

  Messages Help
Advanced
securid for remote users   Message List  
Reply | Forward Message #130 of 179 |
Re: [securid-users] securid for remote users

Hello
I have implemented such a solution for a major oil company .
and i totally disagree with Didier Arenzana .
First You dont need to create local users with Auth manager. You can import
your users from active Directory to your Auth Manager.
Yes the RSA agent EAP should be installed on the remote clients, and this is
more secure.The purpose of using a RSA SecurID is to only be sure that who are
logging remotely are who they really are and that is why you have to use 2
factor authentication for the remote users. They have to be authenticated by
Auth manager before they can login in to the network.
If you need more details you can always email me

Regards
Bhagat Panwar
ISS, CISSP , RSA SecurID , CCIE


Didier Arenzana <darenzana@...> wrote:
Hi,

2006/7/5, speedy_1s <speedy_1s@...>:
> Hi has anyone used securid for remote logins to an active directory?,
> most of my users will dialin via adsl, here are some questions i have:

I haven't used such a feature, but I think I can help anyway :

> 1) should user accounts (within auth manager) be local or remote (i
> really would like to avoid having to use realms unless completely
> neccesary)

Your user accounts within auth manager will be local. Remote accounts
is only used when you want users from another realm to be able to
authenticate through yours. If all your users are within your
resposability, meaning you are the only one to provide them SecurID
cards, then you don't need to use remote accounts.

> 2) does the client software need to be installed on the remote pc
> (keeping in mind that the user will be entering their passscode in the
> dialup networking screen not the windows gina).

I don't think so. That would mean the remote PC itself is contacting
your auth manager to check the passcode, which would be a very bad
idea, since that would mean you trust the remote PC's security.

Regards,
Didier.






Thu Jul 6, 2006 7:35 am

bhagat_panwar
Offline Offline
Send Email Send Email

Forward
Message #130 of 179 |
Expand Messages Author Sort by Date

Hi has anyone used securid for remote logins to an active directory?, most of my users will dialin via adsl, here are some questions i have: 1) should user...
speedy_1s
Offline Send Email
Jul 5, 2006
5:16 am

Hi, ... Your user accounts within auth manager will be local. Remote accounts is only used when you want users from another realm to be able to authenticate...
Didier Arenzana
darenzana
Online Now Send Email
Jul 5, 2006
8:01 pm

Hello I have implemented such a solution for a major oil company . and i totally disagree with Didier Arenzana . First You dont need to create local users with...
Bhagat Panwar
bhagat_panwar
Offline Send Email
Jul 7, 2006
5:56 am

Hi thanks for the reply, Well at the moment, i have an ldap query running to pull the users out of AD (and that works).. the main problem here is auth manager...
speedy_1s
Offline Send Email
Jul 10, 2006
10:46 pm

Thanks for the reply Didier, I am pretty sure the last time i was troubleshooting this problem i could login through a vpn with my windows -password but not...
speedy_1s
Offline Send Email
Jul 7, 2006
6:13 am

You need to install an agent on the remote pc. Otherwise, if you have remote users, you could opt to use SSL VPN and then use the SSL VPN NAS to prompt for...
andoks84
Offline Send Email
Sep 7, 2006
6:50 am
Advanced

Copyright © 2009 Yahoo! Inc. All rights reserved.
Privacy Policy - Terms of Service - Guidelines - Help