SecurID and SEPM

| | Comments (0) | TrackBacks (0)

Symantec Endpoint Protection Manager Console (SEP11) allows authentication through local accounts, Active Directory and SecurID. SecurID is a two factor authentication system which combines a user known PIN and a token generated 6 digit code for authentication. The token is generated every 60 seconds.

Because the SecurID passcode is always changing imagine my surprise when I attempted to log into SEPM and I received an error that my password has expired. After checking the KB and the Symantec forums and not finding an answer, I opened a case with support. Support tells me that this is a known issue that should be fixed in a future maintenance release.

For now I'm either going to have to configure AD authentication for people requiring access to the SEPM console (such as admins and helpdesk). If I continue with SecurID accounts I'll have to recreate their accounts every 90 days.

I think its a really good idea to use AD or SecurID for authentication so that each administrator doesn't end up with 50 accounts with bad passwords that are never changed. It would be preferable however if the authentiction actually worked correctly.

Categories

0 TrackBacks

Listed below are links to blogs that reference this entry: SecurID and SEPM.

TrackBack URL for this entry: http://www.infosecblog.org/mt-tb20071121.pl/746

Leave a comment

Powered by Ajax Comments

About this Entry

This page contains a single entry by Roger published on June 21, 2008 3:42 PM.

Tech Support Bakeoff was the previous entry in this blog.

Security Update available for Adobe Reader and Acrobat 8.1.2 is the next entry in this blog.

Find recent content on the main index or look in the archives to find all content.

Add to Google
Please contact me by leaving a comment where appropriate. Otherwise, you can click here to reveal an email address for me.
Got Backups? Get Safe Online Remember Rick Rescorla Powered by Movable Type 4.2-en