 |
The TrustBroker
Security Server is a scalable and robust implementation
of a Kerberos Key Distribution Centre (KDC). It can be hosted
on popular UNIX platforms and also on Microsoft Windows NT/2000
Servers. It has been written to support Kerberos based authentication
as well as Public Key (utilising X.509 v3 certificates on
smart cards) and also supports the complementary use of token
cards to give stronger two-factor authentication for specific
users.
 |
Summary
of Features & Benefits |
 |
|
The following list summarises the features
and benefits of this Security Server product :
- Based on the Kerberos standards for security
interoperability with Microsoft Windows 2000, XP or 2003
Server based deployments.
- Interoperable with Open Source implementations
of the Kerberos protocol.
- Supports two-factor user authentication
using RSA SecurID®, VASCO Data Security Digipass™
or Secure Computing SafeWord™
- Supports Smart Card based authentication
from Clients using the IETF PKINIT
standard. This capability requires the Public Key Option
Pack.
- Provides a Virtual Smart Card certificate
store so that smart card contents can be delivered securely
to Clients upon request.
- Local or Remote administration of principal
database via gui, command line or programmable API.
- Supports DES and 3DES encryption, and
also SHA-1, MD5 and CRC checksum algorithms.
- Centrally managed password policy management
and enforcement rules, user principal account lockout rules
etc.
- Incremental propogation between KDC's
for a specific REALM.
- Supports REALM referral when used in
conjunction with Microsoft Active Directory.
 |
Future
plans ... |
 |
|
At CyberSafe we continuously monitor the
market requirements and Kerberos standards so that we can
keep our products up to date. The information below shows
a selection of the features or capabilities we are considering,
or planning for future versions of the Security Server product.
- Allow brokering of credentials with a RADIUS
& LDAP authentication. This will make
the product more suited to remote access authentication
needs.
- Allow other databases to be used for principal storage,
e.g. Oracle, Sybase or LDAP
- Support AES encryption as well as RC4
- Have updated PKINIT
support for improved interoperability with other implementations
of this standard.
Cable Network Security
We are updating the Security Server product
so that it conforms to PacketCable and IPCableCom
security standards for cable network security infrastructure.
If
your company is interested to discuss our Cable Network
Security plans please click here
and provide us with your contact details. |
|
 |
The following operating systems
are supported by the Security Server product.
- Microsoft® Windows® NT,
2000, XP & 2003
- SUN Solaris™ on Sparc - Versions 2.6, 7,
8 & 9 (32-bit)
- IBM AIX™ on PowerPC - Version 4.3.3, 5.1,
5.2 & 5.3 (32-bit)
- Hewlett Packard HP/UX™ on PA-RISC - Versions
10.10, 10.20, 10.30, 11 & 11i (32-bit)
|
|