Tuesday, June 24, 2008

What's so important? I'm curious.


What's your guess as to why this ad has appeared two days in a row in the Seattle-Times? I know you can't tell how big the ad is but it is basically 2/3rds the width of a page and about 1/6th the size of the page high. So this is not a small ad. Additionally, it's in the main section of the newspaper - not stuck back in the classifieds - so you can't miss it.

What data does the owner need so badly? Is the phone itself so valuable?

I'm curious...are you?

Tuesday, June 17, 2008

Privileged Account Management

One of my colleagues just finished up a white paper that is worth reading: Privileged Account Management. Learn How to Secure Your Assets and Control Your Costs



Here's the abstract from the white paper:

Privilege Manager safely delegates administrative privileges, including root. It protects heterogeneous Unix systems from the threat of external attackers, as well as abuse and misuse from trusted internal users. This document addresses the security return on investment (ROI) of using Quest Software’s Privilege Manager for Unix security software to protect company assets stored on Unix systems. It also demonstrates how Privilege Manager can control costs and greatly improve system security, so an organization can increase productivity.



Privileged Account Management is something that I see more and more customers starting to talk about and consider solutions for this problem. It's worth a read just to better understand the problem space on Linux/Unix and specifically around "root" access control.

We have a broader white paper coming out regarding this topic that I'll let you know about.


Blogged with the Flock Browser

Friday, June 13, 2008

Quest ActiveRoles Server Integration with IBM Tivoli Identity Manager


After a lot of work at both Quest and IBM we have managed to get a "Ready for Tivoli e-Business Software" certification. We've seen more and more customers building a "tiered" identity infrastructure where they might have an identity framework - like Tivoli Identity Manager - and want to couple that with a best-of-breed solution for Windows and Active Directory like Quest's ActiveRoles Server. TIM allows you can effectively manage identities across your whole enterprise while benefiting from Quest's specialized Active Directory expertise while also enabling the consolidation of your Unix and Linux identities via Vintela Authentication Services.

Details below...

Quest Software has partnered with IBM to create a validated solution that helps facilitate and improve IBM Tivoli Identity Manager (ITIM) deployments to maximize efficiency, security, and compliance. This solution leverages an already-deployed Active Directory infrastructure in conjunction with ITIM. The solution enables ITIM to manage user accounts within Active Directory through Quest ActiveRoles Server via SPML 2.0 (Service Provisioning Markup Language - an Oasis International Standard).

Through this tiered approach, ITIM deployments can proceed quicker and more simply by delivering deeper ITIM-based identity administration for the Windows/AD environment. It enables a single connection to Active Directory to achieve codeless provisioning and management of Exchange, SharePoint, Active Directory Lightweight Directory Services accounts (AD LDS, formerly ADAM), and any Active Directory-enabled application. This approach can also benefit any Unix, Linux, or Mac system as well as a number of enabled applications that have been brought into the Active Directory "trusted realm" through Quest's identity integration technologies (Vintela Authentication Services and Vintela Single Sign-on for Java), further eliminating the need to build and maintain unique ITIM connectors and manage identity individually across the wide spectrum of platforms and applications.

Benefits of the combined Quest/Tivoli solution include:


  • Decreased time and cost for ITIM implementation

  • Wizard-driven configuration (out-of-the-box)

  • Pre-built SPML integration

  • No need to build and maintain connectors to Unix, Linux, Java, and Mac operating systems

  • Streamlining of on-going management because identities are managed through Active Directory and subject to rules and roles defined through Quest ActiveRoles Server

  • Quest's Active Directory management and identity integration solutions are:
    Easy to deploy - Codeless provisioning of Active Directory-based identity lifecycle management

  • Automated account creation in Active Directory with no custom code to maintain

  • Advanced/automated group management that supports segregation of duties

  • Approval workflow and attestation over group memberships

Technorati Tags:
, , , , , , , ,

Wednesday, June 11, 2008

Common Criteria (or other) Certification ≠ A Secure Product

Customers are demanding more and more security certifications. While I don't disagree with certifications I do have a problem with customers and the market equating a certification as meaning the product is secure. This is not true.

Here's an example of a just reported vulnerability (Computerworld, May 26/08):

Cisco Security Advisory: Cisco IOS Secure Shell Denial of Service Vulnerabilities

The Secure Shell server (SSH) implementation in Cisco IOS contains multiple vulnerabilities that allow unauthenticated users the ability to generate a spurious memory access error or, in certain cases, reload the device.

Vulnerable Products: Cisco devices running certain 12.4-based IOS releases and configured to be managed via SSH may be affected by this issue.

And, from the Common Criteria Certification's list of certified products:

Cisco IOS Firewall Version 12.3(14)T and 12.4(4)T - EAL4+ certification on 27-NOV-06
Certification report: ST_VID10038-VR.pdf
Security target: ST_VID10038-ST.pdf

...and SSH was a "security target" of the evaluation:

...the security target specifies that administration of the TOE may be conducted locally via the console port or remotely via an SSH connection to the TOE-enabled router provided an external AAA service capable of single-use mechanisms is used

QED: Security Review or Certification ≠ A Secure Product

Technorati Tags:
, ,