Comments
Patrick Collands wrote: collands (AT) gmail com I'd be very grateful for an invitation. Thank you.
Cloud Expo on Google News

SYS-CON.TV

2009 East
PLATINUM SPONSORS:
IBM
Smarter Business Solutions Through Dynamic Infrastructure
IBM
Smarter Insights: How the CIO Becomes a Hero Again
Microsoft
Windows Azure
GOLD SPONSORS:
Appsense
Why VDI?
CA
Maximizing the Business Value of Virtualization in Enterprise and Cloud Computing Environments
ExactTarget
Messaging in the Cloud - Email, SMS and Voice
Freedom OSS
Stairway to the Cloud
Sun
Sun's Incubation Platform: Helping Startups Serve the Enterprise
POWER PANELS:
Click For 2008 West
Event Webcasts
CRYPTOCard's CRYPTOServer
Lost passwords, easily guessed passwords, accounts with no passwords - they are all huge security risks

Lost passwords, easily guessed passwords, accounts with no passwords - they are all huge security risks; however, there often isn't a better, more economical way for companies on a limited budget. Biometric authentication can be expensive to implement, and many organizations have to trust employees anyway, so static passwords are a no-brainer. Still, the majority of successful security attacks are achieved through password access. What are the options? CRYPTOCard's CRYPTOServer for Linux is a good one at $499.

The CRYPTOServer Starter Kit comes with the software for CRYPTOServer, CRYPTOConsole, a USB key-style token, a smartcard token and reader, a calculator-style token, and a SecureID-style keyfob. The box set also provides a software token that's used with the administrative user once the product has been registered.

CRYPTOServer was easy to install. With a distribution of MySQL, JBoss, and JRE provided in the package, the graphical installer came to life immediately. The install was a little bumpy, however. It didn't take me long to figure out that you need to have your firewall set up (or disengaged) for MySQL and JBoss access. I also disengaged SELinux just in case. There was another hiccup when the installer attempted to access a MySQL database seemingly before the MySQL server processes were completely up and available. Since the configuration files were in place, I re-ran the installer, which picked up as an upgrade, and everything went smoothly. It should be noted, however, that the system on which you are installing CRYPTOServer needs to have the compat-libstdc++ package installed. If you are using a Red Hat distribution, you can install this package by selecting the Legacy Software Development series of packages during installation.

CRYPTOServer can be configured to use MySQL (either your own installation or the distribution provided with CRYPTOServer), MS SQL, or Oracle as a back end. CRYPTOServer uses JBoss Application Server (www.jboss.com) with JBoss's Enterprise JavaBeans (EJB). Authentication for CRYPTOServer can be configured to use your LDAP or Active Directory server for easy integration into your current environment.

Immediately following the CRYPTOServer install, you will need to install CRYPTOConsole. The CRYPTOConsole module provides the management interface to CRYPTO-Server. Token management, initialization, server licensing, and reporting functions are available through the console. The install of CRYPTOConsole ran without any problems, sporting a JRE interface via InstallAnywhere (www.macrovision.com/products/flexnet_installshield/ installanywhere/index.shtml). The requisite shortcut for CRYPTOConsole immediately appeared under applications in my desktop menu in Gnome.

When logging into CRYPTOConsole for the first time, I was presented with dialogs to set up CRYPTOServer's configuration and to initialize a token for the "super-operator," CRYPTOServer's administrative user. After I entered some basic information and set up my token PIN for user "admin," I reentered the authentication information (with the PIN this time), and registered the product. Initial application setup complete.

The majority of your interaction with CRYPTOServer takes place within the CRYPTOConsole. The interface is simple and easy to use, providing three panes for viewing containers, objects, and attributes, respectively, in its Browse tab, and search dialogs in its Search tab. All of the created users and tokens can be browsed by user, etc. The search functions in the Search tab accept regular expressions for easy searching. Several options for token management are available by highlighting an active token, then right-clicking it to display the dropdown menu items.

If you are currently supporting an RSA/SecureID authentication scheme, you will be pleased to note that you can import these tokens into CRYPTOServer to support existing non-admin users. CRYPTOServer supports RSA New PIN mode, management of time drift, and token expiration.

CRYPTOServer can be used to protect any PAM-aware application and can be used to secure OpenVPN, SSH, and Radius access. During testing, I set up CRYPTOServer to authenticate my OpenVPN and SSH access to my home network. Configuring the tokens through CRYPTOConsole was easy and intuitive. Within an hour, I was able to authenticate to CRYTPOServer with a passcode from my key fob token, thus eliminating my use of a static password.

Another common use of CRYTPOServer is to secure Apache. Using the CRYTPOServer documentation for securing Apache, a component called CRYPTOWeb, I was able to secure a Web site and then authenticate to it with my already configured token in a little less than an hour. Once I had Apache up and secure, I configured CRYPTODeploy, a component that allows you to automate hardware token assignment and activation. Once CRYPTODeploy was configured, I could issue a hardware token with only instructions to go to the CRYPTODeploy site on our network. The rest was done by the user, and he was securely connected within 15 minutes.

CRYPTOServer represents a positive swing in the Linux applications market. This product is easy to configure for system administrator and user alike. At $499, CRYPTOServer is a great value, and, by eliminating static passwords, it's an even greater investment in security for your network.

This review was performed on a Pogo Linux server featuring dual-core Opteron processors. For more info, please visit www.pogolinux.com.

About Matt Frye
Matt Frye is the Review Editor at Linux.SYS-CON.com, and Engineer in New Product Introduction and Emerging Network Solutions at Tekelec.

In order to post a comment you need to be registered and logged in.

Register | Sign-in

Reader Feedback: Page 1 of 1

LinuxWorld Product Review: CRYPTOCard's CRYPTOServer. Lost passwords, easily guessed passwords, accounts with no passwords - they are all huge security risks; however, there often isn't a better, more economical way for companies on a limited budget. Biometric authentication can be expensive to implement, and many organizations have to trust employees anyway, so static passwords are a no-brainer. Still, the majority of successful security attacks are achieved through password access. What are the options? CRYPTOCard's CRYPTOServer for Linux is a good one at $499.

Lost passwords, easily guessed passwords, accounts with no passwords - they are all huge security risks; however, there often isn't a better, more economical way for companies on a limited budget. Biometric authentication can be expensive to implement, and many organizations have to trust employees anyway, so static passwords are a no-brainer. Still, the majority of successful security attacks are achieved through password access. What are the options? CRYPTOCard's CRYPTOServer for Linux is a good one at $499.


Your Feedback
Enterprise Open Source Magazine News Desk wrote: LinuxWorld Product Review: CRYPTOCard's CRYPTOServer. Lost passwords, easily guessed passwords, accounts with no passwords - they are all huge security risks; however, there often isn't a better, more economical way for companies on a limited budget. Biometric authentication can be expensive to implement, and many organizations have to trust employees anyway, so static passwords are a no-brainer. Still, the majority of successful security attacks are achieved through password access. What are the options? CRYPTOCard's CRYPTOServer for Linux is a good one at $499.
LinuxWorld News Desk wrote: Lost passwords, easily guessed passwords, accounts with no passwords - they are all huge security risks; however, there often isn't a better, more economical way for companies on a limited budget. Biometric authentication can be expensive to implement, and many organizations have to trust employees anyway, so static passwords are a no-brainer. Still, the majority of successful security attacks are achieved through password access. What are the options? CRYPTOCard's CRYPTOServer for Linux is a good one at $499.
Latest Cloud Developer Stories
CloudBench Applications, Inc. announced its financial results for the three months and nine months ending September 30, 2009. All amounts are stated in Canadian dollars unless otherwise noted. Revenues from BasicGov, the Company's cloud computing solution for local government, gr...
The new contract is an industry first, with CSC being the first Microsoft partner to lead and win a cloud computing services agreement of this scale. Under terms of the contract, CSC will provide Royal Mail Group's 30,000 employees with access to new IT services using Microsoft's...
Operates in over 170 countries and is one of the world’s leading providers of communications solutions and services. Richard Tarboton talks for MeettheBoss.TV on his role as Head of Energy & Carbon for BT and what they are doing towards reducing carbon emissions.
CA is going to put its Agile Planner software on salesforce.com’s Force.com platform in the first half to accelerate development time and give users visibility over their development initiatives to reduce time-to-market. Customers are supposed to be able to accelerate the deploym...
Despite its uncertain fate Sun soldiers on. Monday it trotted out a cloud-based multiplatform desktop as a service for K-12 and community colleges that can run Windows, the Mac OS, Linux and Solaris applications to nearly any client device, including its own Sun Ray thin clients....
Subscribe to the World's Most Powerful Newsletters
Subscribe to Our Rss Feeds & Get Your SYS-CON News Live!
Click to Add our RSS Feeds to the Service of Your Choice:
Google Reader or Homepage Add to My Yahoo! Subscribe with Bloglines Subscribe in NewsGator Online
myFeedster Add to My AOL Subscribe in Rojo Add 'Hugg' to Newsburst from CNET News.com Kinja Digest View Additional SYS-CON Feeds
Publish Your Article! Please send it to editorial(at)sys-con.com!

Advertise on this site! Contact advertising(at)sys-con.com! 201 802-3021

SYS-CON Featured Whitepapers
ADS BY GOOGLE

Breaking Cloud Computing News
CloudBench Applications, Inc. announced its financial results for the three months and nine months e...