Where We’ve Been ...
Authentication
- Basic: Account and Password
- Enhanced: Basic + Smart Card
- License: IP Address
Problems
- Vulnerable to Eavesdropping and Cracking
- Difficult to Validate IP Address
- DHCP, Mobile Users, ISP’s
Notes:
Like most sites our authentication history centers around user account name and password. In most cases there are multiple instances per user. They also represent different policies based on the operating system and application. Passwords flow in clear text over network wires from non-secure workstations in departments, dorms and from off campus.
More and more users are working from a number of different workstations. This includes sites both on and off campus. The ability to validate an IP address to meet license restrictions is limited at best.