VascoメーカーDigipass Plug-In Novell NMASの使用説明書/サービス説明書
ページ先へ移動 of 33
Using Digipass Strong User Authentication with Novell NMAS and ICHAIN.
Using Digipass Strong User Authentication with Novell NMAS and ICHAIN Contents Contents ...................................................................................................................................................................
Overview This document shows you how Novell IChain and NMAS optimizes its authentication by integrating VASCO Digipass for strong user auth entication and offering several secure web and RADIUS access solutions.
Technical Concept Topology Concept – Fig www.vasco.com ∙ Using Digipass Strong User Authenti cation with Novell NMAS and ICHAIN ∙ 4.
Novell Components Description NMAS Novell® Modular Authentication Service is an extensible security product that offers you an easy way to centrally manage multiple authentication methods across your network.
• • • Proxy-server clustering Server fault tolerance Support for Remote Authentication Dial-I n User Service protocol (RADIUS) Novell iChain is the ideal product to secure and accelerate your company's transformation to eBusiness. It is also a key component of Novell Secure Access™, Novell's comprehensive security suite.
• • • • User-managed passwords are the single largest cause of incorrect authentication VASCO delivers strong authentication and guar antees data integrity for electronic transactions by means of the Digipass Family of Tokens. In the concept, we implemented the cures for the weak areas of authentication and data in tegrity.
our Digipass Family of tokens. These mode s are the Response-Only mode, the Challenge- Response mode and the Digital Signature mode. But first we will start by showing you the complete application cycle of the Digipass token usage.
(Fig 1b) Once this is done, the application ow ner will assign those Digipass secrets to their end-users. This assignment is done based on th e serial number of the Digipass token and the name of the end-user. The Digipass token is th en shipped to the end-user together with a manual and the protected PIN-co de on a secure PIN-mailer.
Airlines site (web server 10.0.0.1), two subnets ar e configured. As the lo cal data or e-business applications resides on the 10.0.0.0 subnet (Fig 3), address translation will enable transparent access. Fig 3 Radius will be the Protocol used for Authentication, as such, a Radius profile needs to be configured.
Fig 3a Select auth entication, then sel ect radius aut hentication. Fig 3b Configure th e IP Address of the R adius Server www.vasco.com ∙ Using Digipass Strong User Authenti cation with Novell NMAS.
Configuration of NMAS NMAS System Settings In this section we need to configure the type of services to be u sed in order to access its’ resources. The services are user-related. Configuring Radius Access is done in two steps : 1. Add the Radius Dial Access Service 2.
Services represents the Radius Dial Access Protocol. Double click on Services www.vasco.com ∙ Using Digipass Strong User Authenti cation with Novell NMAS and ICHAIN ∙ 13.
Select the RADIUS_DAS Service. www.vasco.com ∙ Using Digipass Strong User Authenti cation with Novell NMAS and ICHAIN ∙ 14.
We finished configuring the Radius_DAS Service. Now we need to specify the Radius Protocol . For example Callback , ….. Click Add to configure. www.vasco.
Once again select Services. www.vasco.com ∙ Using Digipass Strong User Authenti cation with Novell NMAS and ICHAIN ∙ 16.
Select RADIUS_DAP and click OK. You can rename it to Radius Dial Access Protocol. When no method is specified, adds `default` . Example. Radius Dial Access Protocol.
NMAS VASCO Digipass import Configure VASCO Digipass container Fig 5 As NMAS has VASCO integrated, there is only th e need to co nfigure th e service and activate it.Configuration of a container for Digipasse s is done through creating a new object in Services.
Fig 6 VASCO Digipass container will contain the VA SCO Digipass token object, for which you can give a friendly name. Fig 6 www.vasco.com ∙ Using Digipass Strong User Authenti cation with Novell NMA.
Fig 7 For importing tokens, a VASCO Digipass token object is created. This object will contain all Digipasses and their functions conform the initializ ation sheet. This is also the location where a user will be assigned a Digipass. Fig 7. In order to import tokens, the location of the dpx file and its’ encryption key need to be provided.
Import Dpx files Fig 8. This is also the location where a user will be a ssigned a Digipass. Fig 8. In order to import tokens, the location of the dpx file and its’ encryption key need to be provided.
Fig 9 Fig 9 represents the DNS structure where Digital Airlines is the applicationas well as the container where all users accessing it, will be re gistered and given permissions, levels of access and type of authentication. Fig 10. By selecting the properties of a newly created user, a Digipass is assigned to that user.
Activation Authenti cation Method – VASCO Digipass Authentication Fig 12 For each user select the authentication method . Here we select the VASCO token. Fig 12 Configuration of Radius Novell For detailed configuration of Radius within th e Novell Radius Service, we refer you to visit http://www.
Configuration of Web Novell For more information regarding configuration or product details, we refer to http://www.novell.com Other web servers, services In the current scenario we used the Novell web server. To find other web solutions VASCO has fully support on Apache or IIS.
Appendix A – Delta Airlines Access Examples Authentication – Authoriz ation over IChain secured www.vasco.com ∙ Using Digipass Strong User Authenti cation with Novell NMAS and ICHAIN ∙ 25.
www.vasco.com ∙ Using Digipass Strong User Authenti cation with Novell NMAS and ICHAIN ∙ 26.
www.vasco.com ∙ Using Digipass Strong User Authenti cation with Novell NMAS and ICHAIN ∙ 27.
Appendix B Local Netw ork Log on VASCO – Challenge Response Authentication Novell NMAS will present you the VASCO challeng e which needs to be entered into a token in order to enter the correct response into the `Enter password` field. Once authenticated by VASCO, NMAS presen ts the NDS stat ic password as second verification.
www.vasco.com ∙ Using Digipass Strong User Authenti cation with Novell NMAS and ICHAIN ∙ 29.
Appendix C – The V ASCO VRM & T ok ens w ork with BM (BMAS) VPN Ser vices VPN Secure Authentication with The Digipass 300 and the Digipass Go-1 with PIN+RESPONSE When defining the Login Policy Rule for VPN, the External Login Service Method must be defined as MANDATORY.
Founded: 1997 Web: www.VASCO.com CEO Ken Hunt President and COO: Jan Valcke Employees: 80 Worldwide Headquarters: 1901 South Meyers Road, Suite 210, Oakbrook Terrace, Illinois, USA European Headquarte.
• • • • • • • • • Digipass Pro 700 offers sophisticated and yet use r-friendly strong authentication services with extended digital signature capability.
www.vasco.com ∙ Using Digipass Strong User Authenti cation with Novell NMAS and ICHAIN ∙ 33 • • VACMAN Server for Networks provides strong user authentication and access control management for RADIUS and LAN environments in a fully integrated system.
デバイスVasco Digipass Plug-In Novell NMASの購入後に(又は購入する前であっても)重要なポイントは、説明書をよく読むことです。その単純な理由はいくつかあります:
Vasco Digipass Plug-In Novell NMASをまだ購入していないなら、この製品の基本情報を理解する良い機会です。まずは上にある説明書の最初のページをご覧ください。そこにはVasco Digipass Plug-In Novell NMASの技術情報の概要が記載されているはずです。デバイスがあなたのニーズを満たすかどうかは、ここで確認しましょう。Vasco Digipass Plug-In Novell NMASの取扱説明書の次のページをよく読むことにより、製品の全機能やその取り扱いに関する情報を知ることができます。Vasco Digipass Plug-In Novell NMASで得られた情報は、きっとあなたの購入の決断を手助けしてくれることでしょう。
Vasco Digipass Plug-In Novell NMASを既にお持ちだが、まだ読んでいない場合は、上記の理由によりそれを行うべきです。そうすることにより機能を適切に使用しているか、又はVasco Digipass Plug-In Novell NMASの不適切な取り扱いによりその寿命を短くする危険を犯していないかどうかを知ることができます。
ですが、ユーザガイドが果たす重要な役割の一つは、Vasco Digipass Plug-In Novell NMASに関する問題の解決を支援することです。そこにはほとんどの場合、トラブルシューティング、すなわちVasco Digipass Plug-In Novell NMASデバイスで最もよく起こりうる故障・不良とそれらの対処法についてのアドバイスを見つけることができるはずです。たとえ問題を解決できなかった場合でも、説明書にはカスタマー・サービスセンター又は最寄りのサービスセンターへの問い合わせ先等、次の対処法についての指示があるはずです。