OK, and I agree. User name and password only scare me. We use certificate
and also use SCV to check a few registry keys to see if te computer is a
member of our domain. It's not fool-proof, but it does raise the bar a bit.
Ray
From: Yang Xiao <yxiao2004 AT GMAIL DOT COM>
Reply-To: Mailing list for discussion of Firewall-1
<FW-1-MAILINGLIST AT AMADEUS.US.CHECKPOINT DOT COM>
To: FW-1-MAILINGLIST AT AMADEUS.US.CHECKPOINT DOT COM
Subject: Re: [FW-1] secure client unable to authenticate due to expire of
passwor d
Date: Mon, 24 Jul 2006 06:37:57 -0400
On 7/21/06, Ray <sixsigma44 AT hotmail DOT com> wrote:
Why is SDL considered risky? We're not using it, but it sure would sove
problems like this.
Thanks,
Ray
I was really refering to VPN authentication using AD LDAP, I loath this
kind
of single sign-on even if you enforce strict password complicity and
expriation policy, but then still, I'd prefer using something like RSA
tokens.
- Yang
=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to LISTSERV AT amadeus.us.checkpoint DOT com
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
fw-1-owner AT ts.checkpoint DOT com
=================================================
=================================================
To set vacation, Out-Of-Office, or away messages,
send an email to LISTSERV AT amadeus.us.checkpoint DOT com
in the BODY of the email add:
set fw-1-mailinglist nomail
=================================================
To unsubscribe from this mailing list,
please see the instructions at
http://www.checkpoint.com/services/mailing.html
=================================================
If you have any questions on how to change your
subscription options, email
fw-1-owner AT ts.checkpoint DOT com
=================================================
|