LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 07-26-2011, 07:12 AM   #1
doqc1
LQ Newbie
 
Registered: Jul 2011
Posts: 6

Rep: Reputation: Disabled
PCI DSS Compliant Centralized authentication


I was wondering if someone could help thin down our lines of enquiry regarding our authentication regime. I'm in the very early stages of working out what is needed here so please forgive any vagueness.

This is an estate of Debian based servers running in a remote data centre.
So the admins need to ssh in over the WAN into the internal network.
There are only 3 user accounts on each just now, and about 15 servers (and growing). I am only looking authenticating at ssh access here.

Requirements:
  • PCI DSS password controls (complexity, account aging etc.)
  • Centralized administration of user accounts (if at all possible)
  • Two-factor authentication
  • Passwords transmitted only in encrypted form

Currently we have OPIE as our two-factor auth running on a box we use as a ssh stepping stone to enter the internal network. Inside the internal network we use ssh with each box authenticating locally with PAM and standard unix passwords (using cracklib & pam_unix).
This works from a PCI perspective, but obviously isn't centralized so requires Keepass or similar to keep track of all passwords as they expire and are changed.

Have so far looked at Freeradius to provide a centralized authentication server which is queried from the client via pam_radius_auth. Freeradius can be configured to use the auth-type System so we would only have to administer accounts on that 1 server. Trouble with this is that user account aging warnings don't seem to be sent back to the clients using pam_radius_auth.

So I am wondering if I should be looking at LDAP. I believe it can enforce password aging controls itself from the backend, pam_cracklib can continue to enforce complexity locally. I believe there are OTP solutions for ldap also.

Can anyone provide an insight as to whether LDAP-only, or radius/LDAP would make sense with the above set up and requirements?

Would the added complexity be worth it for such a small estate?

I am also hazy as to how radius and LDAP interact. If using LDAP, do I even need radius?.. since LDAP appears have suitable pam modules to authenticate ssh sessions.

Any insights would be welcome.
 
Old 07-26-2011, 08:40 PM   #2
chrism01
LQ Guru
 
Registered: Aug 2004
Location: Sydney
Distribution: Rocky 9.2
Posts: 18,359

Rep: Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751Reputation: 2751
You might want to read this re LDAP/Radius http://www.linuxhomenetworking.com/w...DAP_and_RADIUS. It's a detailed HOWTO with explanations, so even though the author uses Fedora, it should still be a good guide for Debian.
If you've got 15 servers & growing, some sort of Centralized Auth is probably a good idea, especially if its reqd ie PCI/DSS
 
1 members found this post helpful.
Old 08-11-2011, 04:12 AM   #3
doqc1
LQ Newbie
 
Registered: Jul 2011
Posts: 6

Original Poster
Rep: Reputation: Disabled
Thanks for the reply.. after a bit more investigate we ended up going with kerberos with a ldap backend. Seems to tick most of the boxes with the bonus of single sign on.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Debian Linux firewall pci dss anaconda Linux - Security 4 06-04-2011 10:40 AM
LXer: PCI DSS Standards 2.0 Means Good News For Linux Xen VPS LXer Syndicated Linux News 0 09-07-2010 02:40 AM
[SOLVED] mod_security and PCI-DSS compliance with Breach Security's Enhanced Rule Set rsciw Linux - Security 2 07-21-2010 04:18 AM
Logging file access - PCI DSS koobi Linux - Security 6 09-21-2007 04:08 AM
Centralized Authentication banzai_slr Linux - Security 0 05-05-2005 03:45 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 12:08 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration