LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 01-17-2011, 05:04 PM   #1
Cracker-Barrel
LQ Newbie
 
Registered: Nov 2009
Posts: 13

Rep: Reputation: 0
Authentication Protocol Decision


Hello, I need to make a choice on what authentication protocol I want to use for Authentication and Authorization. I was looking at Radius and then literature suggested that Diameter was a better protocol.

Keep in mind I need this on a hetrogeneous setup ( linux & windows together). Diameter seemed like a good fit until I discovered that the open source code no longer seems to be maintained ( C/C++).

I was also looking at Kerberos as an option though there is alot overhead with the server.

SSL/TLS or EAP?

Does anyone have any suggestions?

I am looking for simple but secure and am new at the security protocols.

-regards
 
Old 01-18-2011, 02:50 AM   #2
acid_kewpie
Moderator
 
Registered: Jun 2001
Location: UK
Distribution: Gentoo, RHEL, Fedora, Centos
Posts: 43,417

Rep: Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985Reputation: 1985
What kind of authentication do you actually want to do? Windows servers authenticating with RADIUS requests?? How? RADIUS is, as designed, great for network authentication, but not something for a windows client. Generally anything on the windows side you'd be looking at AD domain membership, wither to a proper DC or a Samba implementation on Linux.

Also be clear on the difference between Authentication and Authorization, Kerberos has *nothing* to do with Authz or User Information (which you haven't mentioned at all, and is only partially going to overlap with Authz), only user auth, and would be partnered with a separate directory (LDAP / NIS+ etc.) for authz and info mechanisms.

Last edited by acid_kewpie; 01-18-2011 at 02:52 AM.
 
Old 01-19-2011, 09:27 AM   #3
Cracker-Barrel
LQ Newbie
 
Registered: Nov 2009
Posts: 13

Original Poster
Rep: Reputation: 0
Thanks for the feedback.

Actually, my requirements that have been given to me are very vague.
Basically I have a windows client that needs to connect to a linux server.

I need to enforce both authentication and authorization.
First I need to authenticate that the windows client has the priviledge to connect and that the user ( with which the client is connect as) needs to be authorized to access different resources.


Like i said originally, as I am new at this I am looking for different suggestions, what has seen success and maybe what to stay away from.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Warning: mysql_connect(): Client does not support authentication protocol I_AM Linux - General 4 06-19-2009 11:30 AM
LXer: Tutorial: Border Gateway Protocol, The Routing Protocol of the Internet LXer Syndicated Linux News 0 11-13-2008 05:11 AM
Where to turn SSHv1 protocol and SSHv2 protocol on and off Minnie Nguyen Linux - Enterprise 3 07-05-2006 02:12 PM
ERROR 1251: Client does not support authentication protocol javier_ccs Programming 1 06-15-2005 10:12 AM
Unsupported protocol 'Compression Control Protocol' (0x80fd) received RKris Linux - Software 0 08-21-2002 08:24 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 10:45 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration