Till now the market has not seen a mature product by which connecting to LINUX operating systems can safely be accomplished and supervised.
Here now the good news many have been longing for: a product of this type can now be ordered at Sefirot GmbH.
The product consists of two components:
"AdminLinuxLogon", a program that allows the system administrator to configure and administer user accounts for
Smart Card access in accordance with the security policy.
"Smart Card LinuxLogon", an access program for user authentication at logon screen via
Smart Card (authentication and autorization component).
These programs excel in user tutoring. Very particular GUIs have been developed and finely synthezised. While IT security has a bad reputation for complexity it has been achieved to conceal those processes behind friendly menues and toolbars.
Smart Card LinuxLogon access may be individually configured by the administration program: security levels can be defined,
Smart Cards can be analyzed and administered during establishment of access protection (as desired by the security policy in force). As an example: password based access may be permitted as an additional option to standard
Smart Card based access; or it may be ruled which key variable lengths must in any case be supported by the given
Smart Card.
There is an important feature of this product deserving an extra highlight:
A highly secure access protection is provided by this software even without certificate presence. That means: access protection need not compulsarily be achieved by certificates and respective keys on a
Smart Card. Assuming that the Smart Card does not contain a certificate but an asymmetrical key couple then the
Smart Card Logon can be carried out on the basis of this key couple via a sign- or a crypt challenge response procedure respectively.
Smart Cards:
all Smart Cards supported by Sefirot may be employed with the "Smart Card Logon Linux" software.
Card readers:
Smart Card Logon under Linux may be utilized together with all present card readers with MUSCLE PC/SC drivers. Not all Linux drivers for card readers presently on the market are stable and sufficiently tested, however. It is therefore suggested to employ card readers tested and recommended by Sefirot for the
Smart Card LinuxLogon operation. For most recent information go to
www.sefirot.de.