Firewall Wizards mailing list archives

Token based OTP: SafeWord or SecurID?


From: kadokev () msg net
Date: Tue, 12 Sep 2000 18:39:52 -0500 (CDT)

I'm currently evaluating options for commercial one-time-password systems,
previously I had been using SNK-004 under FWTK, with the fixes for the problems
I found last year (see BugTraq). FYI, SNK-004 is fundamentally identical to the
challenge-response hardware/software tokens from Axent.

The client is looking for something commercially supported, with simple
hardware tokens, compatible with modern Solaris and SSH1. The choice is down
to SafeWord or SecurID.

Since cost is a factor, SafeWord has an edge there. Also, Safeword supports
the SNK-004 system (Listed as 'SecureNet' under authenticators), which is a
plus for converting existing users.

Looking at the Solaris installation scripts and the SDK/API software each
company includes, neither of them is very attractive at the moment. I may
end up going with SecurID primarily because it has been around longer and
has more support in third-party applications (Sudo, FWTK, etc).

Can anybody suggest compelling reasons to choose one over the other, or
another vendor I may have missed (CryptoCard and Axent are out of the running)?


Thanks,

Kevin Kadow
MSG.Net, Inc.

_______________________________________________
Firewall-wizards mailing list
Firewall-wizards () nfr net
http://www.nfr.net/mailman/listinfo/firewall-wizards


Current thread: