RSA SecurID Authentication

Jeremy M. Guthrie jeremy.guthrie at berbee.com
Wed Dec 12 18:08:03 CET 2007


The PAM module for RSA(ACE) does work except in one case:
-  an account in 'next token mode' or 'new pin mode' causes FreeRADIUS to spin 
out and swallow all of the memory on the host running it till it crashes.

I have not nailed down yet if it is PAM or FreeRADIUS but as example, OpenSSH 
has no issue dealing with either instance.  Not laying blame, I just do not 
know the root cause of the issue yet.

On Wednesday 12 December 2007, Arran Cudbard-Bell wrote:
> Hi,
>
> Just wondering if anyone on here had some experience with authenticating
> against a SecurID management server.
> I think the easiest way would be just to proxy to the RSA RADIUS Server
> (Funk),  but I see there are some PAM modules available from RSA.
>
> So if anyone been successful using either of these methods, FR Version
> and Method (PAM,Proxy) info would be greatly appreciated.
>
> Seems like something useful that could go into the wiki.
>
> Thanks,
> Arran



-- 

--------------------------------------------------
Jeremy M. Guthrie        jeremy.guthrie at berbee.com
Managed Cisco Security Solutions
Senior Network Engineer        Phone: 608-298-1061
CDW Berbee                       Fax: 608-288-3007
5520 Research Park Drive         NOC: 608-298-1102
Madison, WI 53711
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 189 bytes
Desc: This is a digitally signed message part.
URL: <http://lists.freeradius.org/pipermail/freeradius-users/attachments/20071212/48b7fc75/attachment.pgp>


More information about the Freeradius-Users mailing list