Company LOGO January 24 th, 2007 PC Manager Meeting.

Slides:



Advertisements
Similar presentations
Single Sign-On with GRID Certificates Ernest Artiaga (CERN – IT) GridPP 7 th Collaboration Meeting July 2003 July 2003.
Advertisements

Chapter 14 – Authentication Applications
Authentication Applications. will consider authentication functions will consider authentication functions developed to support application-level authentication.
Digital Certificate Installation & User Guide For Class-2 Certificates.
Digital Certificate Installation & User Guide For Class-2 Certificates.
Cryptography and Network Security Third Edition by William Stallings Lecture slides by Lawrie Brown.
Kerberized Credential Translation Olga Kornievskaia Peter Honeyman Bill Doster Kevin Coffman Center for Information Technology Integration University of.
Grid Computing Basics From the perspective of security or An Introduction to Certificates.
Cryptography and Network Security Third Edition by William Stallings Lecture slides by Lawrie Brown.
Cross Platform Single Sign On using client certificates Emmanuel Ormancey, Alberto Pace Internet Services group CERN, Information Technology department.
Computer Security: Principles and Practice EECS710: Information Security Professor Hossein Saiedian Fall 2014 Chapter 23: Internet Authentication Applications.
Chapter 14 From Cryptography and Network Security Fourth Edition written by William Stallings, and Lecture slides by Lawrie Brown, the Australian Defence.
Password?. Project CLASP: Common Login and Access rights across Services Plan
DESIGNING A PUBLIC KEY INFRASTRUCTURE
Password?. Project CLASP: Common Login and Access rights across Services Plan
National Center for Supercomputing Applications Integrating MyProxy with Site Authentication Jim Basney Senior Research Scientist National Center for Supercomputing.
WAP Public Key Infrastructure CSCI – Independent Study Fall 2002 Jaleel Syed Presentation No 5.
16.1 © 2004 Pearson Education, Inc. Exam Planning, Implementing, and Maintaining a Microsoft® Windows® Server 2003 Active Directory Infrastructure.
Certificates, Browsers & You: What is all this certificate crud? Frank J. Nagy God of Kerberos And Associates...
70-293: MCSE Guide to Planning a Microsoft Windows Server 2003 Network, Enhanced Chapter 9: Planning and Managing Certificate Services.
Introduction to PKI Seminar What is PKI? Robert Brentrup July 13, 2004.
Use of Kerberos-Issued Certificates at Fermilab Kerberos  PKI Translation Matt Crawford & Dane Skow Fermilab.
CAMP - June 4-6, Copyright Statement Copyright Robert J. Brentrup and Mark J. Franklin This work is the intellectual property of the authors.
Christopher Chapman | MCT Content PM, Microsoft Learning, PDG Planning, Microsoft.
Configuring Active Directory Certificate Services Lesson 13.
PC Manager Meeting January 25, Today Updates –Next Meeting –Meeting Maker Upgrade –Windows Policy –Training –Licensing –Security –Tool Of The Month.
Masud Hasan Secure Project 1. Secure It uses Digital Certificate combined with S/MIME capable clients to digitally sign and.
Introduction to Active Directory December 10th, pm Daniels 407.
MCSE Guide to Microsoft Exchange Server 2003 Administration Chapter Four Configuring Outlook and Outlook Web Access.
Digital Certificates Made Easy Sam Lutgring Director of Informational Technology Services Calhoun Intermediate School District.
Hands-On Microsoft Windows Server 2008
Introduction to Secure Messaging The Open Group Messaging Forum April 30, 2003.
Hands-On Microsoft Windows Server Security Enhancements in Windows Server 2008 Windows Server 2008 was created to emphasize security –Reduced attack.
KX509: Leveraging Kerberos to Obtain Digital Certificates for Web Client Authentication University of Michigan Kevin Coffman Bill Doster.
Configuring and Troubleshooting Identity and Access Solutions with Windows Server® 2008 Active Directory®
Section 1: Introducing Group Policy What Is Group Policy? Group Policy Scenarios New Group Policy Features Introduced with Windows Server 2008 and Windows.
PC MANAGER MEETING January 23, Agenda  Next Meeting  Training  Windows Policy  Main Topic: Windows AV Service Review.
Computer Security: Principles and Practice First Edition by William Stallings and Lawrie Brown Lecture slides by Lawrie Brown Chapter 22 – Internet Authentication.
Configuring Directory Certificate Services Lesson 13.
Chapter 23 Internet Authentication Applications Kerberos Overview Initially developed at MIT Software utility available in both the public domain and.
Module 9: Fundamentals of Securing Network Communication.
Secure Messaging Workshop The Open Group Messaging Forum February 6, 2003.
Introduction to Public Key Infrastructure January 2004 CSG Meeting Jim Jokl.
W2K and Kerberos at FNAL Jack Mark
Scaling NT To The Campus Integrating NT into the MIT Computing Environment Danilo Almeida, MIT.
1 DCS 835 – Computer Networking and the Internet Digital Certificate and SSL (rev ) Team 1 Rasal Mowla (project leader) Alvaro Restrepo, Carlos.
15.1 Copyright © The McGraw-Hill Companies, Inc. Permission required for reproduction or display. Key Management.
Module 9: Designing Public Key Infrastructure in Windows Server 2008.
One Platform, One Solution: eToken TMS 5.1 Customer Presentation November 2009.
Windows 2000 Certificate Authority By Saunders Roesser.
W2K and Kerberos at FNAL Jack Schmidt Mark Kaletka.
Cryptography and Network Security Chapter 14 Fourth Edition by William Stallings Lecture slides by Lawrie Brown.
Security fundamentals Topic 5 Using a Public Key Infrastructure.
Deploying Software with Group Policy Chapter Twelve.
Configuring and Troubleshooting Identity and Access Solutions with Windows Server® 2008 Active Directory®
Active Directory. Computers in organizations Computers are linked together for communication and sharing of resources There is always a need to administer.
X509 Web Authentication From the perspective of security or An Introduction to Certificates.
Project Status: Computer Security June 26, Agenda Background, Technical Going Forward.
Fermilab supports several authentication mechanisms for user and computer authentication. This talk will cover our authentication systems, design considerations,
PC Manager Meeting February 23, Today Updates Next Meeting Windows Policy Security This Month: Lessons Learned: Building the Symantec Patch (Andy.
Public Key Infrastructure (PKI)
SSL Certificates for Secure Websites
Grades4sure PDF Dumps CompTIA Security + Certification Exam
Cryptography and Network Security
Authentication Applications
Lesson #7 MCTS Cert Guide Microsoft Windows 7, Configuring Chapter 7 Configuring Devices and Updates.
CLASP Project AAI Workshop, Nov 2000 Denise Heagerty, CERN
Scott Miller TSM Team Lead Ray Mah Architect, Foundation
Scott Miller TSM Team Lead Ray Mah Architect, Foundation
Presentation transcript:

Company LOGO January 24 th, 2007 PC Manager Meeting

Today  Updates  Next Meeting  Training  License  Jinitiator Upgrade  Meeting Maker  Windows Policy  Security  get_cert Replacement, A Look At NetIDMgr– Jack Schmidt

Next Meeting  February 28th  Key Management Service

Training Update  Understanding and Using Digital Certificates (PKI) Feb 15th, 2007 Understanding and Using Digital Certificates (PKI) Feb 15th, 2007  Excel 2003: Advanced Feb. 27 & March 1, 2007 (am only) Excel 2003: Advanced Feb. 27 & March 1, 2007 (am only)  Word 2003: Advanced Feb. 27 & March 1, 2007 (pm only) Word 2003: Advanced Feb. 27 & March 1, 2007 (pm only)

Licensing  EA Training vouchers expire March/April  FNAL Website:  Help redeeming Training Vouchers: Div/SecDaysDiv/SecDays AD16D00 MIS5ESH1 CD17FESS4 CDF1PPD4 TD5

Jinitiator  Update required for DST compliance Feb/Mar 2007 timeframe  See PC Manager archives for detailed .  MIS package available for download or via SMS  Instructions available at:

Meeting Maker MMCO  Microsoft DST patch (KB928388) breaks Outlook connector  The error displayed is "Cannot connect to current session“  Working with vendor. Don’t install DST patch on systems with outlook connector for now.  If the DST patch is already installed on your computer it can be uninstalled to return MMCO functionality.

Meeting Maker 8.6  MM Upgrade mandatory?  Does it correct DST problem with MMCO?  Required for DST time change?  Full upgrade:  MM server, MM Native client, MM web server, MM MMCO server, MM MMCO client  MM Upgrade changes Sync tool. Requires a new server with a Web component and database component  Working with Meeting Maker and Notify link to answer questions.

Windows Policy Committee  Vista Update  Updating baseline  KMS up and validating systems!  Working out issues (documentation, SRV records)  Testing new GPOs in Fermibeta  Vista-users mail list  Next Meeting Feb 7 th 1:30-2:30pm, WH5SW

Security Updates  MANDATORY Patches:  MS  Due Date:  RECOMMENDED Patches:  Due Date:  The following is a link to the January Microsoft list of critical and important patches. bulletin/ms07-jan.mspx bulletin/ms07-jan.mspx

Security Updates  New Fermi Windows CD available soon!

Main Topic  NetIDMgr – Jack Schmidt

Agenda  Background  Definitions  Requirements  Solution  Demo  Rollout

Background  Kerberos has provided good central supported service for telnet, ftp, etc  Unfortunately many applications are unlikely to be Kerberized  Multiplicity of passwords not solved by Kerberos, still need some single sign on mechanism for applications  We need to choose a mechanism to establish identity for other apps

Definitions (sorry)  Public Key Encryption  Asymmetric encryption: public key and private key  PKI Public Key Infrastructure  A system of public key encryption using digital certificates from Certificate Authorities that verify and authenticate the validity of each party involved in an electronic transaction.  Digital Certificate  Includes your name, serial number, expiration dates, your public key, digital signature of the CA

Definitions  CA: Certificate Authority  verify the identity of entities and issue digital certificates attesting to that identity.  X.509 is the international standard for Digital Certificates (not all conform)

Definitions  KCA: Kerberos Certificate Authority  Leverages Kerberos authentication infrastructure  Short-lived (current ticket lifetime up to 7 days)  Requires FNAL realm Kerberos principal  kx509 is a client program that talks to the KCA to obtain a short-lived X.509 certificate

Motivation To Use Certificates  Single sign on for applications  Eliminate application passwords in clear  Attacks are moving more toward applications rather than OS  Central revocation of authorization  Allows centralized auditing of user accounts  Next slide indicates scope of problem with clear passwords

Inbound passwords in clear text

Benefits  KCA Certs  Strong identity verification  Read or publish information  User privileges can be revoked  No password vulnerability  Restricts usage to FNAL only  Requires frequent renewal

Strategy  Move to single sign on by adopting certificates for all applications  Build get_cert tools for each OS

Get_cert  Windows users find current implementation a bit klunky  Issue with logon name

Replacement Tool Requirements  On login to FERMI domain or via  Automatically get FNAL.GOV ticket  Automatically get KCA certificate and load into supported browsers*  Use existing krb5.conf  One place to change passwords  Ease of credential renew  Code must be supportable

Solution  Pay Company to build new tool  Use existing NetIDMgr/KFW software  Create kca plugin  Comes with AFS plugin!  Maintained Opensource  W2000/XP/Vista support  Terminal Server support

Take a spin…

Rollout  FNAL package available on pseekits \\pseekits\desktoptools\netidmgr  SMS package available for distribution  Requires AFS  MSI can be installed via SMS  Issue if existing version installed via.EXE

AFS Tip!  Don’t mount drives via AFS Control Panel!  Map Network Drive and UNC path \\afs\fnal.gov \\afs\fnal.gov

References  Cd-doc CD Briefing on SSL Certificates, March 2006, Mark Leininger & Jack Schmidt Cd-doc-1380  NetIDMgr User Documentation (pdf) NetIDMgr User Documentationpdf  Kerberos For Windows Kerberos For Windows  OpenAFS for Windows OpenAFS for Windows