Hi Jake, While it is true that RSA, for some 15 years, used a NSA-certified proprietary hash to generate the SecurID's one-time password, five years ago RSA replaced the classic SecurID with an AES-based token, so your concern about the proprietary hash is a little out of date. To the best of my knowledge (and I track this stuff), no one has ever claimed to have inverted the old Brainard hash in the classic SecurID, but the AES SecurID token, with a 128-bit secret, is state of the art, even DPA-resistant, and available in a half-dozen form-factors. The RSA Authentication Manager includes a RADIUS server, and OpenBSD, of course, has login_radius, BSD Auth, and OpenSSH. RSA, unfortunately, doesn't officially support OpenBSD, and I don't know what might be available that would be the equivalent of PAM modules under BSD Auth. There is probably some experience available here with regard to critical applications, but if not query other BSD forums or Kevin Kadow's unofficial SecurID Users' Forum at: http://tech.groups.yahoo.com/group/securid-users/ Check out Kadow's comment on another OpenBSD forum a few months ago at: http://tinyurl.com/2murme Also Tim Kornau's FreeRadius 1.1.0 port to OpenBSD http://marc.info/?l=openbsd-ports&m=113827097610572&w=2 For SecurID basics, you might want to also check out: RSA SecurID Options: http://www.rsa.com/node.aspx?id=1156 RSA Authentication Servers and Appliances: http://www.rsa.com/node.aspx?id=3049 SecurID-Ready VPNs: http://www.rsa.com/rsasecured/results.asp?search=VPN&x=0&y=0 RSA's Platform Support Matrix (which describes RSA's PAM modules): http://www.rsa.com/node.aspx?id=2573 If you are considering RSA SecurID and SSH, see: OpenSSH: http://www.openssh.com/ OpenSSH support for SecurID: http://sweb.cz/v_t_m/ and The RSA SecurID-Ready Implementation Guide for SSH: http://www.rsa.com/rsasecured/guides/imp_pdfs/ssh_secure_shell_ace5.pdf I'm a consultant to RSA, but this isn't my turf. Hope this is helpful. Suerte, _Vin ------------ in reference to --------- Jacob Yocom-Piatt-2 wrote:-- View this message in context: http://www.nabble.com/seeking-hardware-token-recommendations-tf4960311.html#a14218241 Sent from the openbsd user - misc mailing list archive at Nabble.com.
| Matthew Wilcox | [PATCH] Fix boot-time hang on G31/G33 PC |
| Vu Pham | Re: [Scst-devel] Integration of SCST in the mainstream Linux kernel |
| Greg Kroah-Hartman | [PATCH 004/196] Chinese: add translation of SubmittingPatches |
| Rafael J. Wysocki | [Bug #11799] xorg can not start up with stolen memory |
git: | |
| Li Frank-B20596 | why not TortoiseGit |
| Jon Smirl | ! [rejected] master -> master (non-fast forward) |
| Junio C Hamano | Re: If you would write git from scratch now, what would you change? |
| Wincent Colaiuta | Possible to make a totally empty repository for remote access? |
| Richard Stallman | Real men don't attack straw men |
| Chris | Prolific USB-Serial Controller |
| Douglas A. Tutty | OBSD's perspective on SELinux |
| Nick Guenther | Re: how to clear dmesg outpout |
| Volker Armin Hemmann | build error with 2.6.27.6+reiser4+ehci-hub patch. ERROR: "mii_ethtool_gset" [drive... |
| Wenji Wu | A Linux TCP SACK Question |
| Evgeniy Polyakov | [resend take 2 0/4] Distributed storage. |
| YOSHIFUJI Hideaki / | [GIT PULL] [IPV6] COMPAT: Fix SSM applications on 64bit kernels. |
