Single Sign On was (Re: [opensuse] Results of moving ssh to a high port - Zero scriptkiddies in a 24 hour period.)



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hans Witvliet wrote:
On Sat, 2008-11-29 at 10:30 +0000, G T Smith wrote:
<snip>

What I would like to do is fix up some sort of single sign on, so one
authentication allows access networked resources at a network level, but
unfortunately for *NIX this would be a major project (and getting this
to work with ssh, cups, apache and samba etc could be a major pain). So
one has one strong point of entry rather than several points of varying
strength.



OTOH, using single-sign-on techniques (distributing trusted keys,
kerberos etc etc) removes security barriers. Instead of access to a
specific node, one gets access to all nodes.


The neat concept behind Novells Directory Service (NDS) was the
integration between rights to access services, resources, or even parts
of the NDS database data or schema to an authenticated object on top of
X500. Authenticated objects can only get access to resources and
services that the administrators of those resources and services have
defined at the level they have defined it. AD does do this but it is
still a very poor cripple in comparison to NDS. (Authenticated objects
are users, groups or services BTW).

Unfortunately, *NIX authentication is more loosely federated, with many
different ways of defining access to different functions and resources,
making such integration rather more complex than is ideal. OpenLDAP and
Kerberos are part there but still seem to be a penny short of a full
shilling last time I looked at them, and the later versions of NISS are
not very impressive either.



hw


- --
==============================================================================
I have always wished that my computer would be as easy to use as my
telephone.
My wish has come true. I no longer know how to use my telephone.

Bjarne Stroustrup
==============================================================================
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2.0.9 (GNU/Linux)
Comment: Using GnuPG with SUSE - http://enigmail.mozdev.org

iEYEARECAAYFAkkxRMsACgkQasN0sSnLmgKF3gCgpGva9GVidLCpuz8VJLW/Mctp
aN8AnRioyDNazJLmtnuDq11I+iLXIx3e
=Zqki
-----END PGP SIGNATURE-----
--
To unsubscribe, e-mail: opensuse+unsubscribe@xxxxxxxxxxxx
For additional commands, e-mail: opensuse+help@xxxxxxxxxxxx



Relevant Pages

  • Re: Use login control to limit access to certain pages
    ... Membership Database to store your users and want unauthenticated users to ... The resources are scattered as you said, ... I want to confirm which authentication type you are using? ... without validation when request path is in this XML file. ...
    (microsoft.public.dotnet.general)
  • Re: XP Home on a client/server network
    ... Joining a domain means that the ws can have a computer acct in the domain ... it cannot be used for this type of authentication. ... A user does not "log onto specific resources of a domain", ... domain user acct authentication occurs when the user logs on to ...
    (microsoft.public.windowsxp.general)
  • Total Confusion! - ACLs and Windows authentication with no impersonation
    ... If I have authentication set to "windows", ... Client Requested Resources. ... It uses the original caller's access token and ACL ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: Total Confusion! - ACLs and Windows authentication with no impersonation
    ... permissions are checked, and not in IIS. ... account - regardless of the impersonation settings. ... You have aspx pages..and you have the resources this page wants to get at. ... When anonymous authentication is disabled, yes the page itself MUST have ...
    (microsoft.public.dotnet.framework.aspnet.security)
  • Re: Darwin and his fundamental delusion.
    ... a7f7-7a70d00ab3c9@xxxxxxxxxxxxxxxxxxxxxxxxxxxx>, Ray Martinez wrote: ... gather evidence. ... This is a major project. ... the time and resources to work full time on it. ...
    (talk.origins)