Eicon Networks S93 Installationsanleitung Seite 80

  • Herunterladen
  • Zu meinen Handbüchern hinzufügen
  • Drucken
  • Seite
    / 130
  • Inhaltsverzeichnis
  • FEHLERBEHEBUNG
  • LESEZEICHEN
  • Bewertet. / 5. Basierend auf Kundenbewertungen
Seitenansicht 79
Using Security Dynamics Authentication 80
Edit the password in sdtacplus.cfg, which is used for the TACACS+ encryption
between _sdtacplusd and Diva Server for Windows NT (valid for ACE/Server, version
2.2, on a HP-X computer, version 10.01, with Security Dynamics D200 SecurID tokens).
In Diva Server for Windows NT this password can be edited in NCPA/ Eicon
authentication Service/Config. The password must of course be identical on both sides.
PINs must be assigned using the Set PIN to next Tokencode setting, because a dialog
between server and client is not possible. When adding or changing clients in the
ACE/Server database, the New PIN mode has to be suppressed and set to PIN
generation Set PIN to next Tokencode.
The client side
In general, a client wanting to dial into the Windows NT server Remote Access Service
must enter a user name and a password. If the Windows NT server is secured with the
Security Dynamics authentication in addition to the RAS authentication, the client must
also enter a Security Dynamics user name and a SecurID PASSCODE.
User: RASusername;SDusername;SDPASSCODE
Password: RASPassword
Domain:
The client takes the PASSCODE from his or her individual SecurID token, to which a
four-digit PIN (Personal Identification Number) is normally assigned. For authentication,
the ACE/Server requires the Security Dynamics user name and the PASSCODE.
In the standard version, the (usually) 10 digits (i.e. 4-digit PIN and 6-digit number code)
are entered consecutively. When the Windows NT server logs on to the WAN-Miniport
driver again, the last entered SecurID PASSCODE appears in the RAS logon dialog box,
enabling the PIN of the last user to be determined without problem.
If there are different users on the client computers, for security reasons we recommend
the use of SecurID PINPAD cards. When using this token, the user PIN is entered into the
token and automatically added on to the current number code by the token. The SecurID
PASSCODE therefore consists of only six digits, but the PIN cannot be determined from
the PASSCODE when a connection is established again.
Note: The Next Tokencode is transparent for the user, i.e. the message Please enter
the next code is not shown. (In the case of the Windows NT Dial-Up Networking, the error
code 648 PASSWORD has expired is returned.) As a result, an initial dial attempt with
the current code will fail. However, a second logon with the following code will be
successful.
Seitenansicht 79
1 2 ... 75 76 77 78 79 80 81 82 83 84 85 ... 129 130

Kommentare zu diesen Handbüchern

Keine Kommentare