Advertisement

02.08.2007 at 10:05PM PST, ID: 22156079
[x]
Attachment Details

Client side certificates vs dual factor authentication

Asked by zimboman in Miscellaneous Security

Tags: client, side, certificates, authentication

Please can someone clear this up for me. Are client side certificate connections less secure than DF authentication? I am proposing a VPN solution to a client, using OpenVPN software, but their offshore business IT dept has claimed the connections need to be a minimum dual factor authentication.

I am trying to allow my clients' business partner's specific users, remote access to a PC on a separate network (my clients'), accessing an application over remote desktop. I had recommended OPenVPN, which can be configured to only allow access to the server "host", and will not push out routes to the rest of the network. However if they access the PC via RDP, I guess they will have some access anyway, but that is not a security risk to themselves...(business partner)
They also need access to a OpenVMS server on the network, so I need to somehow allow for telnet access...

Anyone have any ideas on the best way to accomplish this? I heard of Juniper SSL VPN devices, that may be able to accomplish this - but are they difficult to configure?
I suppose I am getting off the subject, but any assistance is appreciated.

Thanks,
ZMStart Free Trial
[+][-]02.09.2007 at 06:17AM PST, ID: 18501286

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]02.09.2007 at 08:17PM PST, ID: 18506036

View this solution now by starting your 7-day free trial. Setting up your free trial is quick, easy, and secure. We will return you to this solution, unlocked, when you're done.

 

About this solution

Zone: Miscellaneous Security
Tags: client, side, certificates, authentication
Sign Up Now!
Solution Provided By: prashsax
Participating Experts: 2
Solution Grade: A
 
 
[+][-]02.10.2007 at 05:19AM PST, ID: 18506945

At Experts Exchange, members can ask their questions to thousands of technology professionals, also known as Experts. Experts compete and collaborate to answer those questions by leaving comments like this one.

Start your 7-day free trial to view this Expert Comment or ask the Experts your question.

 
[+][-]02.14.2007 at 12:15PM PST, ID: 18534942

Often, when Experts are collaborating with members who have asked questions, they will request additional information about the problem. Askers respond with an author comment like this one.

Start your 7-day free trial to view this Author Comment or ask the Experts your question.

 
 
Loading Advertisement...
20080716-EE-VQP-32