Securing the Net: Web Authentication Using SecureLogin

Slides:



Advertisements
Similar presentations
automated single login access to Novell storage resources
Advertisements

Omni eControl. New Features in Version 2.x - Manage Mixed Networks: eDirectory, Active Directory, GroupWise, Exchange eControl Version 2.0 New Features.
Chapter Five Users, Groups, Profiles, and Policies.
WEB CONNECT FOR EASYNVR : WEB CONNECT INCREASES YOUR PROFITABILITY BY REDUCING INSTALLATION LABOR COSTS WHILE SIMULTANEOUSLY CREATING NEW REVENUE.
Novell eDirectory™ Deployment at Hydro Quebec Richard Cabana Enterprise Technology Account Manager Novell Canada Ltd.
15.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 15: Configuring a Windows.
Novell iChain ® 2.x Configuration Using the Web Server Accelerator Wizard Cary Andrews Senior Software Engineer Novell, Inc.
1 Chapter Overview Creating User and Computer Objects Maintaining User Accounts Creating User Profiles.
Securing Your GroupWise ® System Morris Blackham Software Engineer Novell, Inc. Danita Zanrè Senior Consultant Caledonia.
Microsoft Windows 2003 Server. Client/Server Environment Many client computers connect to a server.
Upgrading to Novell ® SecureLogin 3.5 Rod Tietjen,
Classroom User Training June 29, 2005 Presented by:
1 Guide to Novell NetWare 6.0 Network Administration Chapter 13.
6.1 © 2004 Pearson Education, Inc. Exam Managing and Maintaining a Microsoft® Windows® Server 2003 Environment Lesson 6: Administering User Accounts.
5.1 © 2004 Pearson Education, Inc. Lesson 5: Administering User Accounts Exam Microsoft® Windows® 2000 Directory Services Infrastructure Goals 
Log on to Digital Locker Website You should be able to log on using Internet Explorer browser at the campus. You may need to log in using Mozilla FireFox.
Using Novell iChain ® 2 to Deliver Internal Network Access without a VPN Brian Six Technical Account Manager Novell, Inc.
Security Planning and Administrative Delegation Lesson 6.
Novell iManager Introduction and Overview James Whitchurch Director—Software Engineering Novell, Inc. Karl Ford Engineering.
iChain ® 2.1: Introduction and Overview Lee Howarth Product Manager Novell, Inc.
Upgrading Legacy Novell Directory Services ® to Novell eDirectory ™ 8.6 Rick Killpack WSS Engineer Novell, Inc. Connie.
Beginning Programming with Novell GroupWise ® C3POs John Cox DSE Worldwide Developer Support Novell, Inc.
Introduction to Novell SecureLogin Single Sign-on Bob Bentley Product Manager Novell, Inc. John Clark Development Manager.
Using Novell GroupWise ® 6 Monitor Duane Kuehne Software Engineer Novell, Inc. Danita Zanre Senior Consultant NSC Sysop,
Keeping Your Business Online with eDirectory ™ Backup and Restore Brian Hawkins Software Engineer Novell, Inc. Roger.
Introduction to Novell GroupWise ® Administrative Object API Glade Monson Software Engineer Novell, Inc.
Beginning Programming with the Novell GroupWise® Object API
Intermediate Programming with the Novell GroupWise ® Object API John Cox DSE Worldwide Developer Support Novell, Inc.
Expose the Power of Novell eDirectory ™ Using Novell eGuide: Advanced Configuration and Customization Nathan Jensen Software Engineer Novell,
Integrating Active Directory with eDirectory ™ Using Novell Account Manager Reid Oakes Technical Team Manager Novell, Inc.
The Shaw Group Inc. WebVPN - Access Anywhere Users Manual.
Creating Custom User Management Plug-ins for iManager Eugene Baron Consultant III Novell, Inc. Adam Ruth Senior Software.
Passwords New Policies and You. New Password Policies Passwords Must Be Unique. (cannot be reused within 1 year) Minimum Password Length: 6 Maximum Password.
Discover How You Can Increase Collaboration with External Partners While Reducing Your Cost in Managing an Extranet from the Azure Cloud MICROSOFT AZURE.
Web-based Storage Access John Pugh Corp Technology Strategist Novell, Inc. Scott Villinski Corp Technology Strategist
Chapter Objectives In this chapter, you will learn:
NDMS AMS Authentication
Intermediate Programming with GroupWise® C3POs™
Configuring and Troubleshooting Routing and Remote Access
Programming with NetWare® XPlat APIs
Novell Account Management Introduction and Overview
Novell BrainShare 200 Simplifying Workstation Management Using Novell ZENworks® for Desktops Prometheus Martin Buckley Product Manager ZENworks for Desktops.
Creating Novell Portal Services Gadgets: An Architectural Overview
Introduction to Java Servlets on Jakarta Tomcat
Novell BrainShare 2002 Success in the City: Implementing Novell Solutions at the City of Los Angeles Bob Gillette Information Systems Manager City of Los.
Novell Workspace Introduction and Overview
Novell BorderManager® 3.7: Technical Overview
Upgrading Legacy Novell Directory Services® to Novell eDirectory™ 8.6
Jumpstart Solution: Novell Active Information Portal
Novell BrainShare 2002 Novell Consulting’s Best Practices for Planning Successful NetWare® Upgrades Stuart Proffitt Novell Consultant Novell, Inc.
Extending the Net: Novell Portal Solutions Overview
An Early Look at MySQL™ on Novell NetWare®
Novell iPrint Deployment Strategies
Novell Government Solutions
Novell Workspace™ Architecture and Developer Concepts
Novell BrainShare 2002 Installing, Configuring, and Administering Novell Modular Authentication Service (NMAS™) Reed Haslam Sr. Software Engineer Novell,
Introducing Novell IPv6 Stack
Six Reasons to Get NetWare® 6 over Windows
Introduction to Novell SecureLogin Single Sign-on
It’s one Net for Mac Users Too
Automating Mainframe Authentication Using SecureLogin
NFX Q-Port on-boarding guide
Cloud Connect Seamlessly
Unit 7 NT1330 Client-Server Networking II Date: 7/26/2016
Novell eDirectory™ Competitive Comparisons
Introduction to Novell GroupWise® Token API
FitnessGram® 2015 Student Information System (SIS) Extract Import Training for Georgia School Year.
Security Planning and Administrative Delegation
Test Automation For Web-Based Applications
Web portals-B2B-B2C-B2E TRAVELOPRO
Presentation transcript:

Securing the Net: Web Authentication Using SecureLogin Novell BrainShare 2002 Securing the Net: Web Authentication Using SecureLogin Keith Lewis Consultant Novell, Inc. kalewis@novell.com Tony Merritt Engagement Partner tmerritt@novell.com TUT244—Securing the Net: Web Authentication Using SecureLogin

The Password Crisis: Typical User Tony, the typical end user, has run out of sticky notes He must fly to 3M headquarters in Northridge, CA He must rent a car and a hotel while his order is processed He must ship the order back by FedEx If he cannot complete his mission, no one will be prepared for the upcoming, mandatory password change Will he make it??

The User’s Password Crisis Defined Growing number of passwords Stringent security requirements Complex Internet applications using Java, Frames, and CGI Scripting End users are not always at the office desktop, so access to sticky notes may be limited Proliferation of shared desktops—browser-remembered passwords will not work

Management’s Password Crisis Defined Growing number of applications to support Corporate standards require customization of solution Difficult to introduce or enforce username and password policies Help desk must be able to manage solution Corporate cost of sticky notes

Password Crisis Studies Novell BrainShare 2002 Password Crisis Studies Help desk reset costs (hard costs) Gartner—$300-340 per user per year Large customer—$35 per reset Password reset account for 25-40% of help desk calls 70-80% of these calls are forgotten passwords Productivity increases (soft costs) 25-45 hours a year logging on per user 14-22 hours with Single Sign-On TUT244—Securing the Net: Web Authentication Using SecureLogin

The Password Crisis: Smart User Keith, the smart user, does not need sticky notes He gracefully enters one password for all systems he needs to work with He books travel to Florida for a vacation with the bonus he received from saving the company money on sticky notes He is able to book a car, hotel, airfare, and verify that he has enough time off with one login How did he do that??

SecureLogin User Features Provides a single password experience for the user Provides biometrics support and graded authentication for additional security and ease of use Helps provide a consistent user interface for password changes, warnings, errors, corporate messages, etc. Provides support for Internet applications using Java, Frames, and CGI Scripting Stores encrypted passwords in Novell eDirectory™, allowing the end user roaming access to Single Sign-on capability Since passwords are in eDirectory, NOT in the browser, a typical desktop upgrade will NOT put the user out of work for several days

SecureLogin Management Features Uses the Novell SecretStore® technology to secure credentials Provides a robust scripting language to simplify user experience and requires minimal training Uses Novell ConsoleOne® and eDirectory to ease the distribution and management of scripts into the corporate environment Eases the introduction of new or the enforcing of existing password policies Provides a common solution for different access methods including desktop with thick client, thin clients, web-based, kiosk-based, etc.

Enabling a Web Application: Profiling Initial authentication when no credentials exist Authentication once credentials have been set Authentication with incorrect password Changing the password

Enabling a Web Application: Flow Identify the URL that presents Internet page with the login dialog boxes Determine functionality built into the Internet page Determine if a username or password policy is needed Identify the URL or text that indicates a successful login as well as a failed one Determine if solution will require Novell Modular Authentication Services (NMAS™), statistics, or logging

Enabling a Web Application: Configuring There are three different mechanisms for configuring applications Invoking the wizard on SecureLogin console Auto-capture on login by wizard Manually adding the application and script

SecureLogin Application Wizard

SecureLogin Application Wizard (cont.)

SecureLogin Auto Capture Wizard

SecureLogin Auto Capture Wizard (cont.)

Manually Adding the Application and Script

Sample SecureLogin Script Dialog Title "Enter Network Password" Ctrl "#1218" Ctrl "#1219" ctrl #1041 EndDialog Setplat "novell" readtext #1041 ?website if ?website eq "mail.myrealbox.com" displayvariables else endscript endif Type "$Username"#1218 Type "$Password"#1219 Click #1

Vision…one Net Mission A world where networks of all types—corporate and public, intranets, extranets, and the Internet—work together as one Net and securely connect employees, customers, suppliers, and partners across organizational boundaries Mission To solve complex business and technical challenges with Net business solutions that enable people, processes, and systems to work together and our customers to profit from the opportunities of a networked world

wiN big Access and Security table one Net solutions lab visit the in the to obtain an entry form