USB key security for OWA

Posted on 2008-10-27
Medium Priority
Last Modified: 2013-12-04
Hi Everyone,

I'm just wondering is it possible for one to use USB key loaded up with certificate for a "token" like security measure without using smart card to access OWA ?

Question by:jjoz
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2

Accepted Solution

DBT_Support earned 750 total points
ID: 22811648
Is this the kind of solution you are looking for? http://www.authenex.com/authenex-solutions/strong-authentication-for-owa.htm
Authenex 2Factor authentication can be done with a usb dongle, and then the username and password.
Also client side security certificates generated from an internal CA will provide a second factor.
This certificate will need to be loaded into the certificate store, and is not eaily USB portable.
LVL 31

Assisted Solution

Paranormastic earned 750 total points
ID: 22812814
If you aren't looking for 'traditional' smartcard styled USB token access, you could export the certificate (presumably including the private key so they could decrypt files) to file and copy that to a USB token or email it, etc., and then import it to another box (e.g. their home system).  It would stay installed, but would not have the same level of security as a regular smartcard solution which would copy over the public key but keep the private key safe.  Doing it with the export/import method would work fine, but if their home system got compromised then their private key could become compromised, resulting in having to reissue the cert - this would also technically allow someone that had the cert access to decrypt whatever was encrypted with it.  How much this matters is up to your corporate security policy.

Author Comment

ID: 22827015
yeah, sort of like that.

i wonder if anyone ever use this http://www.rsa.com/press_release.aspx?id=1575 RSA SecurID® 6100 USB Token for securing the OWA system.
Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

LVL 31

Assisted Solution

Paranormastic earned 750 total points
ID: 22830261
That should work fine for housing client certs - this is a smart USB token - essentially a smartcard in a different form factor with a virtual reader instead of a physical one.  Pretty much every smartcard company has added smart tokens to their lineup years ago.  Maybe I misunderstood your initial question - I thought you were looking at attempting a non-smartcard solution meaning using a standard usb flash thumb drive instead of a usb smart token.  

USB smart tokens are pretty neat - try to negotiate a deal with the vendors as most of them have enormous markups on these things - a company I used to test for made them for about 11 bucks and sells them for about 80!  I know they need to make a profit, but I think a 700% markup is a bit extreme.  I would say 30-40 bucks is a decent deal, that's about the price of a standard smartcard.  Its the exact same chip inside - literally - just a different interface.

Author Comment

ID: 22836807

Paranormastic that's the way i want "would it be possible to secure our OWA using our own USB key ?" that's the question in other words.

but thanks for all who contribute to this thread, now i know that 2-Factor security is possible for securing OWA.

Author Closing Comment

ID: 31510216
Thanks for the info.

Featured Post

Put Machine Learning to Work--Protect Your Clients

Machine learning means Smarter Cybersecurity™ Solutions.
As technology continues to advance, managing and analyzing massive data sets just can’t be accomplished by humans alone. It requires huge amounts of memory and storage, as well as high-speed processing of the cloud.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The Cyber News Rundown brings you the latest happenings in cyber news weekly. Who am I? I’m Connor Madsen, a Webroot Threat Research Analyst, and a guy with a passion for all things security. Any more questions? Just ask.
What's worse than having your data encrypted by ransomware? Getting attacked by a so-called "wiper," which simply destroys the data and offers you no hope of ever seeing it again.
The video tutorial explains the basics of the Exchange server Database Availability groups. The components of this video include: 1. Automatic Failover 2. Failover Clustering 3. Active Manager
This video discusses moving either the default database or any database to a new volume.
Suggested Courses
Course of the Month14 days, 18 hours left to enroll

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question