assurance - RE: [Assurance] silver and two-factor ...
Subject: Assurance
List archive
- From: "Roy, Nicholas S" <>
- To: "" <>
- Subject: RE: [Assurance] silver and two-factor ...
- Date: Thu, 15 Mar 2012 18:12:05 +0000
- Accept-language: en-US
Thanks David, “I suggest considering cloning your existing username/password technology, probably with the same usernames but different passwords, managing it in a way that
makes you feel comfortable with its Silver-ness.” That’s a solution we’ve considered, but we are trying to “eat our own dog food” when it comes to using a single central campus authentication service for passwords.
If we did that it would be setting a precedent that I don’t think we want to set. There is also the risk (and high likelihood, from other such behavior we’ve observed) that people would manually sync passwords between the two systems. Using a solution like OTP tokens or personal certs is valuable in that it is a completely different type of authentication mechanism, which can be said to provide
a benefit for campus beyond the existing username/password system. It’s then an easier job of selling a new service like that, when we can say that it will benefit lots of other applications around campus that could use the service for enhanced security.
Rooting the registration process for Silver in the issuance of a token or enrollment of a certificate on something like a smart card or secure USB fob also provides a lot of advantages when trying to create the registration process necessary for Silver. Nick From: [mailto:]
On Behalf Of David Walker I think there are two issues here:
A question I have is what kind of authentication services are schools running who feel that they can use passwords to achieve Silver? Specifically, what is your central source of authentication? What will end up providing the verifier role
to your Silver-compliant IdP? What kind of clients of this service do you have (ERPs, *.webapp, workstations (Windows, OS X, Linux, other?), printers, file servers, network appliances, etc.) How tightly controlled is access to the service? What kinds of authentication
endpoints are available (LDAP, LDAPS, Kerberos, RADIUS, web services, etc.) how are those endpoints protected and from what network scope can clients connect to them (only on-campus, off campus, only via a VPN, other?) Do you provision passwords to other authentication
services that aren't your central provider? How do you plan to assess and/or enforce client behavior (for example, use of SSL for web forms that validate passwords against your authentication service), or do you consider that out of scope? |
- RE: [Assurance] silver and two-factor ..., (continued)
- RE: [Assurance] silver and two-factor ..., Jones, Mark B, 03/13/2012
- Re: [Assurance] silver and two-factor ..., Frazier, William S [ITSYS], 03/13/2012
- RE: [Assurance] silver and two-factor ..., Jones, Mark B, 03/13/2012
- RE: [Assurance] silver and two-factor ..., Dunker, Mary, 03/13/2012
- Re: [Assurance] silver and two-factor ..., Christopher Bongaarts, 03/13/2012
- RE: [Assurance] silver and two-factor ..., Jones, Mark B, 03/13/2012
- Re: [Assurance] silver and two-factor ..., Tom Scavo, 03/13/2012
- RE: [Assurance] silver and two-factor ..., Farmer, Jacob, 03/13/2012
- RE: [Assurance] silver and two-factor ..., Jones, Mark B, 03/13/2012
- Re: [Assurance] silver and two-factor ..., Christopher Bongaarts, 03/13/2012
- Re: [Assurance] silver and two-factor ..., Frazier, William S [ITSYS], 03/13/2012
- RE: [Assurance] silver and two-factor ..., Roy, Nicholas S, 03/14/2012
- RE: [Assurance] silver and two-factor ..., David Walker, 03/14/2012
- RE: [Assurance] silver and two-factor ..., Roy, Nicholas S, 03/15/2012
- Re: [Assurance] silver and two-factor ..., David Bantz, 03/15/2012
- RE: [Assurance] silver and two-factor ..., Roy, Nicholas S, 03/15/2012
- RE: [Assurance] silver and two-factor ..., Jones, Mark B, 03/15/2012
- Re: [Assurance] silver and two-factor ..., David Bantz, 03/15/2012
- RE: [Assurance] silver and two-factor ..., Roy, Nicholas S, 03/15/2012
- Re: [Assurance] silver and two-factor ..., Tom Scavo, 03/15/2012
- Re: [Assurance] silver and two-factor ..., Tom Scavo, 03/15/2012
- RE: [Assurance] silver and two-factor ..., Jones, Mark B, 03/15/2012
- RE: [Assurance] silver and two-factor ..., Roy, Nicholas S, 03/16/2012
- RE: [Assurance] silver and two-factor ..., Jones, Mark B, 03/16/2012
- Re: [Assurance] silver and two-factor ..., David Bantz, 03/15/2012
- Re: [Assurance] silver and two-factor ..., David Bantz, 03/15/2012
- RE: [Assurance] silver and two-factor ..., Roy, Nicholas S, 03/15/2012
- RE: [Assurance] silver and two-factor ..., David Walker, 03/14/2012
- RE: [Assurance] silver and two-factor ..., Jones, Mark B, 03/13/2012
Archive powered by MHonArc 2.6.16.