<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Aaron Parker &#187; Authentication</title>
	<atom:link href="http://blog.stealthpuppy.com/category/authentication/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.stealthpuppy.com</link>
	<description>on application delivery with application virtualization, server-based computing, desktop virtualization and more</description>
	<lastBuildDate>Fri, 18 May 2012 14:08:58 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
<xhtml:meta xmlns:xhtml="http://www.w3.org/1999/xhtml" name="robots" content="noindex" />
		<item>
		<title>SafeWord RemoteAccess Keeps You Waiting</title>
		<link>http://blog.stealthpuppy.com/authentication/safeword-remoteaccess-keeps-you-waiting/</link>
		<comments>http://blog.stealthpuppy.com/authentication/safeword-remoteaccess-keeps-you-waiting/#comments</comments>
		<pubDate>Fri, 02 Mar 2007 06:49:00 +0000</pubDate>
		<dc:creator>Aaron Parker</dc:creator>
				<category><![CDATA[Authentication]]></category>
		<category><![CDATA[SafeWord]]></category>

		<guid isPermaLink="false">http://blog.stealthpuppy.com/uncategorized/safeword-remoteaccess-keeps-you-waiting</guid>
		<description><![CDATA[If you are ever installing SafeWord RemoteAccess, don&#8217;t be in a hurry. Be prepared to wait while the Setup application downloads the application updates from the SafeWord site, you could be there a while. It&#8217;s clocked just over an hour &#8230; <a href="http://blog.stealthpuppy.com/authentication/safeword-remoteaccess-keeps-you-waiting/">Continue reading <span class="meta-nav">&#8594;</span></a><p><div style="padding: 5px 5px 5px 5px; border: 1px solid #cccccc; color: #303030; background-color: #f4f4f4;"><a rel="license" href="http://creativecommons.org/licenses/by-nc-sa/3.0/"><img alt="Creative Commons License" src="http://i.creativecommons.org/l/by-nc-sa/3.0/88x31.png" style="float:left;margin-right:5px;border:0px;" /></a><a href="http://blog.stealthpuppy.com/authentication/safeword-remoteaccess-keeps-you-waiting/">SafeWord RemoteAccess Keeps You Waiting</a>  is post from <a href="http://blog.stealthpuppy.com/">stealthpuppy.com</a>.  Except as noted otherwise, this work is &copy; 2005-2012 Aaron Parker and is licensed under a <a href="http://creativecommons.org/licenses/by-nc-sa/3.0/">Creative Commons Attribution-Noncommercial-Share Alike 3.0 Unported License</a>.</div></p>
]]></description>
			<content:encoded><![CDATA[<p>If you are ever installing SafeWord RemoteAccess, don&#8217;t be in a hurry. Be prepared to wait while the Setup application downloads the application updates from the SafeWord site, you could be there a while. It&#8217;s clocked just over an hour now and it&#8217;s not my end:</p>
<p><img border="0" src="/images/cs/1000.14.1060.SafeWord.png" /></p>
<p>So you don&#8217;t have to go through the pain again, once the download is complete you can find the SafeWord download files here:</p>
<p><font face="courier new,courier">C:\Program Files\Secure Computing\Installs</font></p>
<p><div style="padding: 5px 5px 5px 5px; border: 1px solid #cccccc; color: #303030; background-color: #f4f4f4;"><a rel="license" href="http://creativecommons.org/licenses/by-nc-sa/3.0/"><img alt="Creative Commons License" src="http://i.creativecommons.org/l/by-nc-sa/3.0/88x31.png" style="float:left;margin-right:5px;border:0px;" /></a><a href="http://blog.stealthpuppy.com/authentication/safeword-remoteaccess-keeps-you-waiting/">SafeWord RemoteAccess Keeps You Waiting</a>  is post from <a href="http://blog.stealthpuppy.com/">stealthpuppy.com</a>.  Except as noted otherwise, this work is &copy; 2005-2012 Aaron Parker and is licensed under a <a href="http://creativecommons.org/licenses/by-nc-sa/3.0/">Creative Commons Attribution-Noncommercial-Share Alike 3.0 Unported License</a>.</div></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.stealthpuppy.com/authentication/safeword-remoteaccess-keeps-you-waiting/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SafeWord RemoteAccess vs. Security Configuration Wizard</title>
		<link>http://blog.stealthpuppy.com/authentication/safeword-remoteaccess-vs-security-configuration-wizard/</link>
		<comments>http://blog.stealthpuppy.com/authentication/safeword-remoteaccess-vs-security-configuration-wizard/#comments</comments>
		<pubDate>Fri, 08 Dec 2006 01:28:00 +0000</pubDate>
		<dc:creator>Aaron Parker</dc:creator>
				<category><![CDATA[Authentication]]></category>
		<category><![CDATA[SafeWord]]></category>

		<guid isPermaLink="false">http://blog.stealthpuppy.com/uncategorized/safeword-remoteaccess-vs-security-configuration-wizard</guid>
		<description><![CDATA[If you implement SafeWord RemoteAccess with the agent software on a machine running Citrix Web Interface and use the Security Configuration Wizard (SCW) to lockdown the operating system, you may run into authentication issues. In my instance, I found that &#8230; <a href="http://blog.stealthpuppy.com/authentication/safeword-remoteaccess-vs-security-configuration-wizard/">Continue reading <span class="meta-nav">&#8594;</span></a><p><div style="padding: 5px 5px 5px 5px; border: 1px solid #cccccc; color: #303030; background-color: #f4f4f4;"><a rel="license" href="http://creativecommons.org/licenses/by-nc-sa/3.0/"><img alt="Creative Commons License" src="http://i.creativecommons.org/l/by-nc-sa/3.0/88x31.png" style="float:left;margin-right:5px;border:0px;" /></a><a href="http://blog.stealthpuppy.com/authentication/safeword-remoteaccess-vs-security-configuration-wizard/">SafeWord RemoteAccess vs. Security Configuration Wizard</a>  is post from <a href="http://blog.stealthpuppy.com/">stealthpuppy.com</a>.  Except as noted otherwise, this work is &copy; 2005-2012 Aaron Parker and is licensed under a <a href="http://creativecommons.org/licenses/by-nc-sa/3.0/">Creative Commons Attribution-Noncommercial-Share Alike 3.0 Unported License</a>.</div></p>
]]></description>
			<content:encoded><![CDATA[<p>If you implement <a href="http://www.securecomputing.com/index.cfm?skey=1277" class="broken_link">SafeWord RemoteAccess</a> with the agent software on a machine running Citrix Web Interface and use the <a href="http://www.microsoft.com/windowsserver2003/technologies/security/configwiz/default.mspx">Security Configuration Wizard</a> (SCW) to lockdown the operating system, you may run into authentication issues.</p>
<p>In my instance, I found that a user would be able to authenticate once, but then the second authentication instance would fail. Checking the agent logs was not much help as no logs were being recorded. After checking that the latest version of the SafeWord Agent was installed, I remembered that I has run the SCW on the system to help secure it. By default, the agent logs are located in:</p>
<p><span style="font-family: Courier New">C:\Program Files\Secure Computing\SafeWord\AgentLogs</span>.</p>
<p>By giving the NETWORK SERVICE account write rights to this folder the agent was able to create a log file. The second part of the issue, I was able to identify in the agent log. The file:</p>
<p><span style="font-family: Courier New">C:\Program Files\Secure Computing\SafeWord\ServerVerification\SWEC.MD5</span></p>
<p><span style="font-family: Courier New"></span>was unable to be written to the file system. By allowing the NETWORK SERVICE account write rights to the:</p>
<p><span style="font-family: Courier New">C:\Program Files\Secure Computing\SafeWord\ServerVerification</span></p>
<p><span style="font-family: Courier New"></span>folder, the agent could write this file and authentication worked successfully.</p>
<p><div style="padding: 5px 5px 5px 5px; border: 1px solid #cccccc; color: #303030; background-color: #f4f4f4;"><a rel="license" href="http://creativecommons.org/licenses/by-nc-sa/3.0/"><img alt="Creative Commons License" src="http://i.creativecommons.org/l/by-nc-sa/3.0/88x31.png" style="float:left;margin-right:5px;border:0px;" /></a><a href="http://blog.stealthpuppy.com/authentication/safeword-remoteaccess-vs-security-configuration-wizard/">SafeWord RemoteAccess vs. Security Configuration Wizard</a>  is post from <a href="http://blog.stealthpuppy.com/">stealthpuppy.com</a>.  Except as noted otherwise, this work is &copy; 2005-2012 Aaron Parker and is licensed under a <a href="http://creativecommons.org/licenses/by-nc-sa/3.0/">Creative Commons Attribution-Noncommercial-Share Alike 3.0 Unported License</a>.</div></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.stealthpuppy.com/authentication/safeword-remoteaccess-vs-security-configuration-wizard/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Swivel PINsafe and Citrix Access Gateway Installation Notes</title>
		<link>http://blog.stealthpuppy.com/authentication/swivel-pinsafe-and-citrix-access-gateway-installation-notes/</link>
		<comments>http://blog.stealthpuppy.com/authentication/swivel-pinsafe-and-citrix-access-gateway-installation-notes/#comments</comments>
		<pubDate>Tue, 28 Nov 2006 23:50:25 +0000</pubDate>
		<dc:creator>Aaron Parker</dc:creator>
				<category><![CDATA[Authentication]]></category>
		<category><![CDATA[Access-Gateway]]></category>

		<guid isPermaLink="false">http://blog.stealthpuppy.com/uncategorized/swivel-pinsafe-and-citrix-access-gateway-installation-notes</guid>
		<description><![CDATA[The good guys over at Swivel have let me post a document that Graham Field (from Swivel) has created for integrating Swivel PINsafe into Access Gateway Advanced Edition 4.5. The document covers everything you&#8217;ll need to get PINsafe authentication working &#8230; <a href="http://blog.stealthpuppy.com/authentication/swivel-pinsafe-and-citrix-access-gateway-installation-notes/">Continue reading <span class="meta-nav">&#8594;</span></a><p><div style="padding: 5px 5px 5px 5px; border: 1px solid #cccccc; color: #303030; background-color: #f4f4f4;"><a rel="license" href="http://creativecommons.org/licenses/by-nc-sa/3.0/"><img alt="Creative Commons License" src="http://i.creativecommons.org/l/by-nc-sa/3.0/88x31.png" style="float:left;margin-right:5px;border:0px;" /></a><a href="http://blog.stealthpuppy.com/authentication/swivel-pinsafe-and-citrix-access-gateway-installation-notes/">Swivel PINsafe and Citrix Access Gateway Installation Notes</a>  is post from <a href="http://blog.stealthpuppy.com/">stealthpuppy.com</a>.  Except as noted otherwise, this work is &copy; 2005-2012 Aaron Parker and is licensed under a <a href="http://creativecommons.org/licenses/by-nc-sa/3.0/">Creative Commons Attribution-Noncommercial-Share Alike 3.0 Unported License</a>.</div></p>
]]></description>
			<content:encoded><![CDATA[<p>The good guys over at <a href="http://www.swivelsecure.com/">Swivel</a> have let me post a document that Graham Field (from Swivel) has created for integrating Swivel PINsafe into Access Gateway Advanced Edition 4.5. The document covers everything you&#8217;ll need to get PINsafe authentication working with Advanced Access Control, including setting up Turing or Single Channel authentication (use to stop bots not humans). You get a copy of the document in <a href="/files/citrix/PINsafeCAGIntegration.doc">Word format here</a> and the LOGIN.ASCX with the code for setting up the <a href="/files/citrix/PINsafeLoginASX.zip">Turing authentication here</a>.</p>
<p><div style="padding: 5px 5px 5px 5px; border: 1px solid #cccccc; color: #303030; background-color: #f4f4f4;"><a rel="license" href="http://creativecommons.org/licenses/by-nc-sa/3.0/"><img alt="Creative Commons License" src="http://i.creativecommons.org/l/by-nc-sa/3.0/88x31.png" style="float:left;margin-right:5px;border:0px;" /></a><a href="http://blog.stealthpuppy.com/authentication/swivel-pinsafe-and-citrix-access-gateway-installation-notes/">Swivel PINsafe and Citrix Access Gateway Installation Notes</a>  is post from <a href="http://blog.stealthpuppy.com/">stealthpuppy.com</a>.  Except as noted otherwise, this work is &copy; 2005-2012 Aaron Parker and is licensed under a <a href="http://creativecommons.org/licenses/by-nc-sa/3.0/">Creative Commons Attribution-Noncommercial-Share Alike 3.0 Unported License</a>.</div></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.stealthpuppy.com/authentication/swivel-pinsafe-and-citrix-access-gateway-installation-notes/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Windows XP, Internet Explorer 7 and SharePoint</title>
		<link>http://blog.stealthpuppy.com/authentication/windows-xp-internet-explorer-7-and-sharepoint/</link>
		<comments>http://blog.stealthpuppy.com/authentication/windows-xp-internet-explorer-7-and-sharepoint/#comments</comments>
		<pubDate>Thu, 23 Nov 2006 04:50:04 +0000</pubDate>
		<dc:creator>Aaron Parker</dc:creator>
				<category><![CDATA[Authentication]]></category>
		<category><![CDATA[Internet-Explorer]]></category>

		<guid isPermaLink="false">http://blog.stealthpuppy.com/uncategorized/windows-xp-internet-explorer-7-and-sharepoint</guid>
		<description><![CDATA[Internally we have deployed SharePoint Portal Server 2003 as our intranet. To ensure that the Citrix Web Interface for SharePoint (WISP) web part works correctly, we need to ensure that there is only authenticated access to SharePoint (WISP fails if &#8230; <a href="http://blog.stealthpuppy.com/authentication/windows-xp-internet-explorer-7-and-sharepoint/">Continue reading <span class="meta-nav">&#8594;</span></a><p><div style="padding: 5px 5px 5px 5px; border: 1px solid #cccccc; color: #303030; background-color: #f4f4f4;"><a rel="license" href="http://creativecommons.org/licenses/by-nc-sa/3.0/"><img alt="Creative Commons License" src="http://i.creativecommons.org/l/by-nc-sa/3.0/88x31.png" style="float:left;margin-right:5px;border:0px;" /></a><a href="http://blog.stealthpuppy.com/authentication/windows-xp-internet-explorer-7-and-sharepoint/">Windows XP, Internet Explorer 7 and SharePoint</a>  is post from <a href="http://blog.stealthpuppy.com/">stealthpuppy.com</a>.  Except as noted otherwise, this work is &copy; 2005-2012 Aaron Parker and is licensed under a <a href="http://creativecommons.org/licenses/by-nc-sa/3.0/">Creative Commons Attribution-Noncommercial-Share Alike 3.0 Unported License</a>.</div></p>
]]></description>
			<content:encoded><![CDATA[<p>Internally we have deployed SharePoint Portal Server 2003 as our intranet. To ensure that the Citrix Web Interface for SharePoint (WISP) web part works correctly, we need to ensure that there is only authenticated access to SharePoint (WISP fails if anonymous access is enabled). What I have found on Windows XP machines that have been upgraded to IE7, is that users are prompted for authentication when accessing SharePoint (IE presents the standard Windows authentication dialog) instead of the browser passing authentication through to IIS as it should.</p>
<p>To fix this, I&#8217;ve had to add the URL to our SharePoint installation to the Local Intranet zone and pass-through authentication works fine. I can&#8217;t seem to find any technical information on this issue, but I&#8217;m assuming that Internet Explorer does not default pass authentication through to just any web site. This issue does not appear to affect Internet Explorer 7 on Windows Vista.</p>
<p><div style="padding: 5px 5px 5px 5px; border: 1px solid #cccccc; color: #303030; background-color: #f4f4f4;"><a rel="license" href="http://creativecommons.org/licenses/by-nc-sa/3.0/"><img alt="Creative Commons License" src="http://i.creativecommons.org/l/by-nc-sa/3.0/88x31.png" style="float:left;margin-right:5px;border:0px;" /></a><a href="http://blog.stealthpuppy.com/authentication/windows-xp-internet-explorer-7-and-sharepoint/">Windows XP, Internet Explorer 7 and SharePoint</a>  is post from <a href="http://blog.stealthpuppy.com/">stealthpuppy.com</a>.  Except as noted otherwise, this work is &copy; 2005-2012 Aaron Parker and is licensed under a <a href="http://creativecommons.org/licenses/by-nc-sa/3.0/">Creative Commons Attribution-Noncommercial-Share Alike 3.0 Unported License</a>.</div></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.stealthpuppy.com/authentication/windows-xp-internet-explorer-7-and-sharepoint/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>AAC 4.2 and Swivel PINsafe</title>
		<link>http://blog.stealthpuppy.com/authentication/aac-42-and-swivel-pinsafe/</link>
		<comments>http://blog.stealthpuppy.com/authentication/aac-42-and-swivel-pinsafe/#comments</comments>
		<pubDate>Tue, 10 Oct 2006 12:47:00 +0000</pubDate>
		<dc:creator>Aaron Parker</dc:creator>
				<category><![CDATA[Authentication]]></category>
		<category><![CDATA[Access-Gateway]]></category>

		<guid isPermaLink="false">http://blog.stealthpuppy.com/uncategorized/aac-42-and-swivel-pinsafe</guid>
		<description><![CDATA[If you are looking to integrate the Swivel PINsafe one time password (OTP) authentication system into Advanced Access Control 4.2 you&#8217;ll find that it&#8217;s not going to work out of the box. You will see the following authentication packet sequence &#8230; <a href="http://blog.stealthpuppy.com/authentication/aac-42-and-swivel-pinsafe/">Continue reading <span class="meta-nav">&#8594;</span></a><p><div style="padding: 5px 5px 5px 5px; border: 1px solid #cccccc; color: #303030; background-color: #f4f4f4;"><a rel="license" href="http://creativecommons.org/licenses/by-nc-sa/3.0/"><img alt="Creative Commons License" src="http://i.creativecommons.org/l/by-nc-sa/3.0/88x31.png" style="float:left;margin-right:5px;border:0px;" /></a><a href="http://blog.stealthpuppy.com/authentication/aac-42-and-swivel-pinsafe/">AAC 4.2 and Swivel PINsafe</a>  is post from <a href="http://blog.stealthpuppy.com/">stealthpuppy.com</a>.  Except as noted otherwise, this work is &copy; 2005-2012 Aaron Parker and is licensed under a <a href="http://creativecommons.org/licenses/by-nc-sa/3.0/">Creative Commons Attribution-Noncommercial-Share Alike 3.0 Unported License</a>.</div></p>
]]></description>
			<content:encoded><![CDATA[<p>If you are looking to integrate the <a href="http://www.swivelsecure.com/?page=products">Swivel PINsafe</a> one time password (OTP) authentication system into Advanced Access Control 4.2 you&#8217;ll find that it&#8217;s not going to work out of the box. You will see the following authentication packet sequence once you have configured PINsafe as a RADIUS profile within AAC and attempt to authenticate:</p>
<ol>
<li>AAC sends a RADIUS Access-Request with the users credentials</li>
<li>PINsafe sends back a RADIUS Access-Accept</li>
<li>AAC sends a RADIUS Access-Request</li>
<li>PINsafe sends back a RADIUS Access-Reject (the credentials are now invalid as the password can only be used once)</li>
<li>AAC sends a RADIUS Access -Request</li>
<li>PINsafe sends back a RADIUS Access -Reject</li>
<li>AAC sends a RADIUS Access -Request</li>
<li>PINsafe sends back a RADIUS Access -Reject</li>
</ol>
<p>This is because Advanced Access Control is not handling the RADIUS Message-Authenticator attribute correctly. Well good news, Citrix have created a private hotfix which I was able to test out earlier this afternoon and authentication is now working successfully. This hotfix replaces <strong>Citrix.AuthenticationService.RADIUSClient.dll</strong> and you will have to call Citrix to get a copy of the file. Quote case number 31367637 as a reference if required.</p>
<p>Now the next thing for me to do is test this fix out with integrating <a href="http://www.vasco.com/products/range.html">Vasco DIGIPASS</a> authentication with Advanced Access Control, which I&#8217;ve seen having the same issues.</p>
<p><font color="#ff0033">UPDATE</font>: <strike>Unfortunately this fix hasn&#8217;t make it in time for the 4.5 release of Advanced Access Control. Once you upgrade to 4.5 you may have to request an updated fix.</strike>  Apparently this fix or an equivalent has made it into Advanced Access Control 4.5. Graham from Swivel has tested with PINsafe sucessfully with AAC 4.5.</p>
<p><div style="padding: 5px 5px 5px 5px; border: 1px solid #cccccc; color: #303030; background-color: #f4f4f4;"><a rel="license" href="http://creativecommons.org/licenses/by-nc-sa/3.0/"><img alt="Creative Commons License" src="http://i.creativecommons.org/l/by-nc-sa/3.0/88x31.png" style="float:left;margin-right:5px;border:0px;" /></a><a href="http://blog.stealthpuppy.com/authentication/aac-42-and-swivel-pinsafe/">AAC 4.2 and Swivel PINsafe</a>  is post from <a href="http://blog.stealthpuppy.com/">stealthpuppy.com</a>.  Except as noted otherwise, this work is &copy; 2005-2012 Aaron Parker and is licensed under a <a href="http://creativecommons.org/licenses/by-nc-sa/3.0/">Creative Commons Attribution-Noncommercial-Share Alike 3.0 Unported License</a>.</div></p>
]]></content:encoded>
			<wfw:commentRss>http://blog.stealthpuppy.com/authentication/aac-42-and-swivel-pinsafe/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

