<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>ReneVester.com &#187; Security</title>
	<atom:link href="http://www.renevester.com/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.renevester.com</link>
	<description>Server based computing and virtualization made available with enthusiasm.</description>
	<lastBuildDate>Mon, 05 Dec 2011 09:48:16 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Citrix Reciever 2.0 for iPhone has been released!</title>
		<link>http://www.renevester.com/2009/12/citrix-reciever-2-0-for-iphone-has-been-released/</link>
		<comments>http://www.renevester.com/2009/12/citrix-reciever-2-0-for-iphone-has-been-released/#comments</comments>
		<pubDate>Mon, 21 Dec 2009 17:28:57 +0000</pubDate>
		<dc:creator>René Vester</dc:creator>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Server Based Computing]]></category>
		<category><![CDATA[SMS PASSCODE]]></category>
		<category><![CDATA[XenApp]]></category>
		<category><![CDATA[XenDesktop]]></category>
		<category><![CDATA[Citrix]]></category>
		<category><![CDATA[iPhone]]></category>
		<category><![CDATA[Receiver]]></category>
		<category><![CDATA[RSA]]></category>
		<category><![CDATA[sms passcode]]></category>

		<guid isPermaLink="false">http://www.renevester.com/2009/12/citrix-reciever-2-0-for-iphone-has-been-released/</guid>
		<description><![CDATA[This is a joyous time.. Citrix sent us one of the fun-filled Christmas gifts.. the new version of the Citrix Receiver for iPhone. I have had the pleasure of testing this new version and i must say that it is an incredible client. This Receiver really brings some much needed functionality to the mobile device [...]]]></description>
			<content:encoded><![CDATA[<p>This is a joyous time.. Citrix sent us one of the fun-filled Christmas gifts.. the new version of the Citrix Receiver for iPhone.</p>
<p>I have had the pleasure of testing this new version and i must say that it is an incredible client. This Receiver really brings some much needed functionality to the mobile device platform. And though i am a big fan of the iPhone i really hope Citrix will manage to bring this level of functionality and features to the other emerging mobile device platforms like Android. Citrix has a tech preview out of their Android receiver it can be found here: <a title="http://community.citrix.com/display/xa/Citrix+Receiver+for+Android" href="http://community.citrix.com/display/xa/Citrix+Receiver+for+Android">http://community.citrix.com/display/xa/Citrix+Receiver+for+Android</a></p>
<p>Bringing it back on topic, the Receiver for iPhone has been out for quite some time now and have been downloaded more than 300.000 times. The receiver was a 1.0 up until now! With the release of version 2.0 i actually see a lot of cool features which will help make it a more usable platform for companies and organizations.</p>
<p>I have chosen to highlight a few of the new features:</p>
<p><strong>Support for Multiple Accounts</strong></p>
<p>This is a great feature and embraces the opportunity to also allow users access from more than organization or allow applications to be delivered from the Cloud.. or SaaS providers or what you will call it <img src='http://www.renevester.com/wp-includes/images/smilies/icon_wink.gif' alt=';-)' class='wp-smiley' />  To support this there has also been implemented a search function to allow users to find the apps they need.</p>
<p><strong>New interface</strong></p>
<p>The new client has a completely different interface for applications, favorites, online help and much more. These are really great changes with an even more iPhonish look and feel, and more useful to users and better administrated by administrators.</p>
<p><strong>Better Support for Citrix complementing technologies</strong></p>
<p>With the new release and some from 1.0.3 there is now an integrated support for Access Gateway Standard, Advanced and Enterprise and of course Support for XenDesktop 4.</p>
<p><strong>Usability improvements</strong></p>
<p>There is a lot of improvements on the usability side of things, just to mention a few it is great to work with the options to Change the initial zoom value, hide status bar, change session resolution and one of the really cool features when working on the iPhone.. a “Caffeine option” a built in feature to help keep the screen active.</p>
<p>Another cool thing which i am a big fan as most who have read this blog will know.. SMS stuff.</p>
<p><strong>2-factor support has been improved and revolutionized</strong></p>
<p>Of course Citrix quickly added support for traditional tokens primarily the RSA tokens. But one of the cool new features, is support for SMS Based 2-factor solutions like <a href="http://www.smspasscode.com">SMS PASSCODE</a>. I have written about <a href="http://www.smspasscode.com">SMS PASSCODE</a> several times <a href="http://www.renevester.com/2009/11/sms-passcode-declared-a-top-five-innovator-in-the-security-industry/">here</a>, <a href="http://www.renevester.com/2009/04/some-times-the-new-guys-do-well/">here</a>, <a href="http://www.renevester.com/2009/02/sms-passcode-launched-a-demo-site/">here</a> and <a href="http://www.renevester.com/2008/09/a-new-approach-to-2-factor-authentication-on-vpn-and-citrix-solutions/">here</a>. The integration allows for the users to log in securely into the company applications using 2-factors on their mobile devices without having to memorize the SMS based 2-factor code from an SMS and then type it into an application. It is based on a technology in which the SMS recieved on the mobile device contains a link which is allows sending the code into the Citrix Reciever application. I do not have a demo-site for this feature ready at the moment but i hope i will have one soon. Until then you can test the SMS PASSCODE solution <a href="https://demo.smspasscode.com/default.aspx?Ref=ReneVesterBlog">here on their demo site.</a></p>
<p>More than i love the technology i love the convenient way in which users can access their applications.. POWER TO THE USERS! Power to convenience! <img src='http://www.renevester.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>If you want more information have a look here at Chris Flecks blog post: <a title="http://community.citrix.com/display/ocb/2009/12/21/Feature+Rich+Citrix+Receiver+2.0+for+iPhone+is+in+the+App+Store" href="http://community.citrix.com/display/ocb/2009/12/21/Feature+Rich+Citrix+Receiver+2.0+for+iPhone+is+in+the+App+Store">http://community.citrix.com/display/ocb/2009/12/21/Feature+Rich+Citrix+Receiver+2.0+for+iPhone+is+in+the+App+Store</a></p>
<p>and on the matter of mobility Vinny Sosa did a blog post here: <a title="http://community.citrix.com/display/ocb/2009/12/11/Mobilizing+your+apps+-+Part+I+-+Session+Resolution" href="http://community.citrix.com/display/ocb/2009/12/11/Mobilizing+your+apps+-+Part+I+-+Session+Resolution">http://community.citrix.com/display/ocb/2009/12/11/Mobilizing+your+apps+-+Part+I+-+Session+Resolution</a></p>
<p>And of course keep up to date on the iphone receiver site here: <a title="http://community.citrix.com/display/xa/Citrix+Receiver+for+iPhone" href="http://community.citrix.com/display/xa/Citrix+Receiver+for+iPhone">http://community.citrix.com/display/xa/Citrix+Receiver+for+iPhone</a></p>
<p>Rene Vester</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.renevester.com%2F2009%2F12%2Fcitrix-reciever-2-0-for-iphone-has-been-released%2F&amp;title=Citrix%20Reciever%202.0%20for%20iPhone%20has%20been%20released%21"><img src="http://www.renevester.com/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.renevester.com/2009/12/citrix-reciever-2-0-for-iphone-has-been-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>SMS PASSCODE declared a top five innovator in the security industry..</title>
		<link>http://www.renevester.com/2009/11/sms-passcode-declared-a-top-five-innovator-in-the-security-industry/</link>
		<comments>http://www.renevester.com/2009/11/sms-passcode-declared-a-top-five-innovator-in-the-security-industry/#comments</comments>
		<pubDate>Mon, 02 Nov 2009 05:32:53 +0000</pubDate>
		<dc:creator>René Vester</dc:creator>
				<category><![CDATA[Featured]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[SMS PASSCODE]]></category>
		<category><![CDATA[innovator]]></category>
		<category><![CDATA[SC Magazine]]></category>
		<category><![CDATA[sms passcode]]></category>

		<guid isPermaLink="false">http://www.renevester.com/2009/11/sms-passcode-declared-a-top-five-innovator-in-the-security-industry/</guid>
		<description><![CDATA[Once in a while, the little innovative, creative and fun companies actually takes off! i am thrilled that the SMS based 2-factor authentication solution from SMS PASSCODE is one of the technologies which has taken off like this. I have written about this product quite a few times and not because i am paid to [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.scmagazineus.com"><img style="border-right-width: 0px; display: inline; border-top-width: 0px; border-bottom-width: 0px; margin-left: 0px; border-left-width: 0px; margin-right: 0px" title="sclogoupdated_1448" border="0" alt="sclogoupdated_1448" align="right" src="http://www.renevester.com/wp-content/SMSPASSCODEdeclaredatopfiveinnovatorint_5C09/sclogoupdated_1448.gif" width="176" height="156" /></a> Once in a while, the little innovative, creative and fun companies actually takes off! i am thrilled that the SMS based 2-factor authentication solution from SMS PASSCODE is one of the technologies which has taken off like this. I have written about this product quite a few times and not because i am paid to do so, but because convenience to me is a very important factor in the search to deliver the ultimate infrastructure to our users. SMS PASSCODE delivers convenience in the authentication area, by taking advantage of something we all BRING with us, rather than something we have to TAKE with us like our physical tokens..</p>
<p>I was super happy to hear that <a href="http://www.smspasscode.com">SMS PASSCODE</a> was nominated by the <a href="http://blog.smspasscode.com/2009/09/28/sc-magazine-names-sms-passcode-a-security-innovators-finalist/">SC Magazine as a Security Innovator finalist</a> and even more happy when i heard they had <a href="http://www.scmagazineus.com/SC-World-Congress-concludes-with-announcement-of-winners-of-Security-Innovators-Throwdown/article/155816/">taken a fourth place in the Security Innovators Throwdown!</a> Congratulations to SMSPASSCODE, it has been an incredible journey from when i first saw the product and to the mature state it has reached now. I still need to finish a review of their latest version 3.0, it will be here soon.</p>
<p>Some of the key features i want to point out to everyone even if you do not read the entire articles, why i like the SMS PASSCODE:</p>
<ul>
<li>Typically offers a higher level of security than traditional tokens </li>
<li>A lot more convenient for the end-users </li>
<li>Easier to administrate than the physical tokens </li>
<li>No logistics, tokens back and forth </li>
<li>Very low Total Cost of Ownership </li>
</ul>
<p>Until i finish my review of version 3.0, if you guys want to learn more about SMS PASSCODE:</p>
<p>Website: <a href="http://www.smspasscode.com">www.smspasscode.com</a>     <br />Earlier review by me: <a title="Permanent Link to 2-factor authentication for Citrix, VPN and remote access in general using any" href="http://www.renevester.com/2008/09/a-new-approach-to-2-factor-authentication-on-vpn-and-citrix-solutions/">Permanent Link to 2-factor authentication for Citrix, VPN and remote access in general using any</a>&#160;</p>
<p>And even better, if you want to try it out, have a look at this post: <a title="Permanent Link to SMS PASSCODE launched a demo site" href="http://www.renevester.com/2009/02/sms-passcode-launched-a-demo-site/">SMS PASSCODE launched a demo site</a></p>
<p>Or click here to go directly to their Demo-site: <a title="Home.aspx" href="https://demo.smspasscode.com/default.aspx?Ref=ReneVesterBlog">Demo site</a>     </p>
<p>Congratulations again to SMS PASSCODE for moving up in a really tough world <img src='http://www.renevester.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>Rene Vester</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.renevester.com%2F2009%2F11%2Fsms-passcode-declared-a-top-five-innovator-in-the-security-industry%2F&amp;title=SMS%20PASSCODE%20declared%20a%20top%20five%20innovator%20in%20the%20security%20industry.."><img src="http://www.renevester.com/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.renevester.com/2009/11/sms-passcode-declared-a-top-five-innovator-in-the-security-industry/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>Citrix Secure Gateway memory leak</title>
		<link>http://www.renevester.com/2009/07/citrix-secure-gateway-memory-leak/</link>
		<comments>http://www.renevester.com/2009/07/citrix-secure-gateway-memory-leak/#comments</comments>
		<pubDate>Sun, 19 Jul 2009 09:19:32 +0000</pubDate>
		<dc:creator>René Vester</dc:creator>
				<category><![CDATA[Access Gateway]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Server Based Computing]]></category>
		<category><![CDATA[Webinterface]]></category>
		<category><![CDATA[XenApp]]></category>

		<guid isPermaLink="false">http://www.renevester.com/2009/07/citrix-secure-gateway-memory-leak/</guid>
		<description><![CDATA[Shawn Bass posted a blog post about his experiences with Secure Gateway 3.1.1. Shawn explains that after some period of time the private bytes in use by the secure gateway service climbs to a point where it stops working. Another major problem with this memory leak is that even when the service is no longer [...]]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.shawnbass.com/" target="_blank">Shawn Bass</a> posted a blog post about his experiences with Secure Gateway 3.1.1. <a href="http://www.shawnbass.com/" target="_blank">Shawn</a> explains that after some period of time the private bytes in use by the secure gateway service climbs to a point where it stops working.</p>
<p>Another major problem with this memory leak is that even when the service is no longer working as intended the service still listens on port 443, so a load balanced setup will not be able to detect the problem.</p>
<p>Read more on Shawn’s blog here: <a title="http://www.shawnbass.com/Blogs/tabid/58/EntryId/164/Beware-of-Secure-Gateway-v3-1-1-it-has-a-major-memory-leak-that-will-take-down-your-WI-SG-environment.aspx" href="http://www.shawnbass.com/Blogs/tabid/58/EntryId/164/Beware-of-Secure-Gateway-v3-1-1-it-has-a-major-memory-leak-that-will-take-down-your-WI-SG-environment.aspx">http://www.shawnbass.com/Blogs/tabid/58/EntryId/164/Beware-of-Secure-Gateway-v3-1-1-it-has-a-major-memory-leak-that-will-take-down-your-WI-SG-environment.aspx</a></p>
<p>Also if you need to downgrade be aware of the known security vulnerability in 3.1.</p>
<p>Rene Vester</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.renevester.com%2F2009%2F07%2Fcitrix-secure-gateway-memory-leak%2F&amp;title=Citrix%20Secure%20Gateway%20memory%20leak"><img src="http://www.renevester.com/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.renevester.com/2009/07/citrix-secure-gateway-memory-leak/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Running Citrix Access Gateway on Citrix XenServer</title>
		<link>http://www.renevester.com/2009/06/running-citrix-access-gateway-on-citrix-xenserver/</link>
		<comments>http://www.renevester.com/2009/06/running-citrix-access-gateway-on-citrix-xenserver/#comments</comments>
		<pubDate>Thu, 25 Jun 2009 21:11:22 +0000</pubDate>
		<dc:creator>René Vester</dc:creator>
				<category><![CDATA[ANG]]></category>
		<category><![CDATA[Featured]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Virtualization]]></category>
		<category><![CDATA[XenServer]]></category>

		<guid isPermaLink="false">http://www.renevester.com/2009/06/running-citrix-access-gateway-on-citrix-xenserver/</guid>
		<description><![CDATA[For a loooong time i have been looking for a way to run Access Gateway on my XenServer for test purposes. And i never found a good description on how to get it running but it seems the nut have been cracked. Citrix CTP Alexander Ervik published a guide on his site: www.ervik.as His site [...]]]></description>
			<content:encoded><![CDATA[<p>For a loooong time i have been looking for a way to run Access Gateway on my XenServer for test purposes. And i never found a good description on how to get it running but it seems the nut have been cracked. Citrix CTP Alexander Ervik published a guide on his site: <a href="http://www.ervik.as">www.ervik.as</a> His site is definitely worth a look and i keep up to date on his site.</p>
<p>Thanx for the guide Alexander..</p>
<p>You can read the entire article here: <a title="http://www.ervik.as/index.php/citrix/xenserver/1885-how-to-run-citrix-access-gateway-cag-on-citrix-xenserver" href="http://www.ervik.as/index.php/citrix/xenserver/1885-how-to-run-citrix-access-gateway-cag-on-citrix-xenserver">http://www.ervik.as/index.php/citrix/xenserver/1885-how-to-run-citrix-access-gateway-cag-on-citrix-xenserver</a></p>
<p>Rene Vester</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.renevester.com%2F2009%2F06%2Frunning-citrix-access-gateway-on-citrix-xenserver%2F&amp;title=Running%20Citrix%20Access%20Gateway%20on%20Citrix%20XenServer"><img src="http://www.renevester.com/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.renevester.com/2009/06/running-citrix-access-gateway-on-citrix-xenserver/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Some times the new guys do well..</title>
		<link>http://www.renevester.com/2009/04/some-times-the-new-guys-do-well/</link>
		<comments>http://www.renevester.com/2009/04/some-times-the-new-guys-do-well/#comments</comments>
		<pubDate>Tue, 07 Apr 2009 13:54:47 +0000</pubDate>
		<dc:creator>René Vester</dc:creator>
				<category><![CDATA[General]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.renevester.com/2009/04/some-times-the-new-guys-do-well/</guid>
		<description><![CDATA[For a couple of years now i have been a great fan of the company and product SMS PASSCODE. A company based in Denmark delivering a strong session-based 2-factor authentication solution based on SMS. SMS PASSCODE has gone through a cool development through the last couple of years, and the penetration in the Danish market [...]]]></description>
			<content:encoded><![CDATA[<p>For a couple of years now i have been a great fan of the company and product SMS PASSCODE. A company based in Denmark delivering a strong session-based 2-factor authentication solution based on SMS. SMS PASSCODE has gone through a cool development through the last couple of years, and the penetration in the Danish market has been extreme. SMS PASSCODE has been widely adopted and a lot of customers are now using this as a means to save money on the administration of 2-factor authentication. Denmark has been widely using tokens as the means of 2-factor authentication, both RSA and Safeword products but the last couple of years the growth has been focused on the SMS based solution that SMS PASSCODE provides. </p>
<p>The reasons for this trend is tightly connected with the fact that the solution is session-based so it eliminates both pharming and phishing attacks which are becoming more and more common. And maybe as the most important change it provides a lot of customers with a solutions which is way easier to administrate, both when it comes to internal users as there is no distributions of a physical device, but also in cases of external consultants where many have experienced that tokens disappear and if you look away from the security aspect it is usually quite a bit of money that goes into these tokens, which are often lost. With SMS PASSCODE, customers are able to just remove the external consultant from and AD-group and the “2-factor access” is revoked. In case of general consultant users changing personality it is just a case of changing the phone number in your active directory.</p>
<p>Anyway…. What i wanted to do with this post was to congratulate SMS PASSCODE on making it to the Red Herring list of “Top 100 most promising Tech Companies” in Europe. I think it is awesome that the guys have been able to spread the technology and that it is now being even more widely adopted. Way to go guys. You can check out the list here: <a title="http://www.herringevents.com/europe09/redherring100.html" href="http://www.herringevents.com/europe09/redherring100.html">http://www.herringevents.com/europe09/redherring100.html</a></p>
<p>If you want to try out SMS PASSCODE you can easily do it at their demo site here: <a title="https://demo.smspasscode.com/Public/Home.aspx" href="https://demo.smspasscode.com/default.aspx?Ref=ReneVesterBlog" target="_blank">https://demo.smspasscode.com/Public/Home.aspx</a></p>
<p>If you want to know more about SMS PASSCODE have a look <a href="http://www.renevester.com/2009/02/sms-passcode-launched-a-demo-site/" target="_blank">here</a> or <a href="http://www.renevester.com/2008/09/a-new-approach-to-2-factor-authentication-on-vpn-and-citrix-solutions/" target="_blank">here</a>.</p>
<p>As i visited SMS PASSCODE yesterday i also had the chance to dig into the upcoming version, and trust me its going to be great, i will post a review when the material is released <img src='http://www.renevester.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /> </p>
<p>Rene Vester</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.renevester.com%2F2009%2F04%2Fsome-times-the-new-guys-do-well%2F&amp;title=Some%20times%20the%20new%20guys%20do%20well.."><img src="http://www.renevester.com/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.renevester.com/2009/04/some-times-the-new-guys-do-well/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>SMS PASSCODE launched a demo site</title>
		<link>http://www.renevester.com/2009/02/sms-passcode-launched-a-demo-site/</link>
		<comments>http://www.renevester.com/2009/02/sms-passcode-launched-a-demo-site/#comments</comments>
		<pubDate>Wed, 18 Feb 2009 21:20:29 +0000</pubDate>
		<dc:creator>René Vester</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.renevester.com/2009/02/sms-passcode-launched-a-demo-site/</guid>
		<description><![CDATA[SMS PASSCODE the sms based 2-factor authentication solution i have written about on several occations here and here has gone into a new phase as they have expanded their channel throughout Europe. The product has matured and so has the organisation. The latest step in their expansion has been to launch a demo-site where you [...]]]></description>
			<content:encoded><![CDATA[<p>SMS PASSCODE the sms based 2-factor authentication solution i have written about on several occations <a href="http://www.renevester.com/2008/09/a-new-approach-to-2-factor-authentication-on-vpn-and-citrix-solutions/" target="_blank">here</a> and <a href="http://www.renevester.com/2007/03/the-%e2%80%9dnew%e2%80%9d-2-factor-authentication-product-smspasscode-3/" target="_blank">here</a> has gone into a new phase as they have expanded their channel throughout Europe. The product has matured and so has the organisation. The latest step in their expansion has been to launch a demo-site where you can easily try the user-approach to the solution which is the most important factor. </p>
<p>For the IT-Department, the cost savings and the easy implementation and almost no deployment needs, usually make them fixed on the solution. But how will the solution appear to the end-users? will they accept it?</p>
<p>Now you can test the solution here: <a title="https://demo.smspasscode.com/Public/Home.aspx" href="https://demo.smspasscode.com/default.aspx?Ref=ReneVesterBlog" target="_blank">https://demo.smspasscode.com/Public/Home.aspx</a></p>
<p>Rene Vester</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.renevester.com%2F2009%2F02%2Fsms-passcode-launched-a-demo-site%2F&amp;title=SMS%20PASSCODE%20launched%20a%20demo%20site"><img src="http://www.renevester.com/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.renevester.com/2009/02/sms-passcode-launched-a-demo-site/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>2-factor authentication for Citrix, VPN and remote access in general using any cellphone?</title>
		<link>http://www.renevester.com/2008/09/a-new-approach-to-2-factor-authentication-on-vpn-and-citrix-solutions/</link>
		<comments>http://www.renevester.com/2008/09/a-new-approach-to-2-factor-authentication-on-vpn-and-citrix-solutions/#comments</comments>
		<pubDate>Tue, 30 Sep 2008 19:01:51 +0000</pubDate>
		<dc:creator>René Vester</dc:creator>
				<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://www.renevester.com/2008/09/a-new-approach-to-2-factor-authentication-on-vpn-and-citrix-solutions/</guid>
		<description><![CDATA[&#160; SMS PASSCODE, next step in lowering administrative costs in relations to 2-factor authentication? First of all, let me just point out that I don&#8217;t do ordered product reviews, what I choose to write about is what I think makes sense and what could make life easier for IT Departments and in this case actually [...]]]></description>
			<content:encoded><![CDATA[<h3>&#160;</h3>
<h2>SMS PASSCODE, next step in lowering administrative costs in relations to 2-factor authentication?</h2>
<p>First of all, let me just point out that I don&#8217;t do ordered product reviews, what I choose to write about is what I think makes sense and what could make life easier for IT Departments and in this case actually easier for the users as well.</p>
<p>So, SMS PASSCODE released their version 2.5 and it is looking great. A while back I did a blog post on the first version I got my hands on titled: <a href="http://www.renevester.com/2007/03/the-%e2%80%9dnew%e2%80%9d-2-factor-authentication-product-smspasscode-3/">The &#8221;new&#8221; 2-factor authentication product SMSPasscode</a></p>
<p>So what is new since then? Well let me start out with what the concept is, I am guessing there is still quite a few out there who haven&#8217;t had the chance to use the product so far. </p>
<p>I think everyone working in IT knows that remote access to our companies should be secured by 2-factor authentication. Typically this means something you know like username and password, and a token, a sheet of sequenced numbers to answer a challenge, biometric(anyone uses that?) or even something like <u>BioPassword</u>.</p>
<p>In all its simplicity, this means there are two factors:</p>
<ol>
<li>Something you Know
<ol>
<li>Typically Username/Password </li>
</ol>
</li>
<li>Something you Have
<ol>
<li>Mobile-, cell phone </li>
<li>Token(RSA, Safeword) </li>
<li>Paper Keycard(numbers on paper to answer challenges) </li>
<li>Eye </li>
<li>Finger </li>
<li>Rythm of typing </li>
</ol>
</li>
</ol>
<p>This is what I think we can all agree on right?</p>
<p>So what have we done traditionally? We have used tokens for the most part. And why? Well the integration was good with products like Citrix Web Interface, there were agents for Radius so we could use it with VPN and most had a solution to also support things like Outlook Web Access etc&#8230; </p>
<p>So all in all we had one solution for the most part that could cover our remote access needs, great! <img src='http://www.renevester.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>So, when we all set this up, managers were happy, users got used to carrying the token around and we went on to more interesting projects.</p>
<p>But what about these tokens? They were in fact the magic key which was making sure we would not allow someone to just steal username and password off a post-it.</p>
<p>Well I found that people had to make a lot of administrative tasks to make sure that tokens were managed securely whenever:</p>
<p> <span id="more-124"></span>
</p>
<ul>
<li>A user left the company </li>
<li>A token were lost or stolen </li>
<li>A token ran out of power </li>
<li>A token had to be distributed to external consultants before they could work remotely </li>
<li>Tokens had to be called back when the work of external consultants was done </li>
</ul>
<p>That&#8217;s just some of the pains that I have seen on the management side of the token solution. Don&#8217;t get me wrong tokens do the job great; they just require a lot of administrative effort.</p>
<p>So enough with the common knowledge stuff <img src='http://www.renevester.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>A new way to do this hit me a couple of years back. A few Danish guys had worked with a customer who could not make his employees work from home. The tokens were always in the other pair of pants, left at work, forgotten in the car, or out of power because the kid used it for a chew toy&#8230;</p>
<p>So the customer asked why he couldn&#8217;t just get his token-code on his Cell phone&#8230; it was their most important tool to do their job, therefore they always had it on. And I could totally agree. I always check my pocket for my phone when I get up, leave a room or the likes.</p>
<p>So they decided to give it a try, not just make a solution to send it via SMS, that had been done before but to make it a personal scalable solution. </p>
<p>This is what they came up with:</p>
<p><a href="http://www.renevester.com/wp-content/uploads/2008/10/clip-image001.gif"><img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="323" alt="clip_image001" src="http://www.renevester.com/wp-content/uploads/2008/10/clip-image001-thumb.gif" width="337" border="0" /></a></p>
<p><b>Corporate Credentials Registry</b></p>
<p>They decided that the best way to find username and password were by using the existing domain so they decided to support LDAP integration. This means that on basis of LDAP and group membership you can have support people adding a new user to the &#8216;Need external Access Group&#8217; and adding in his cell phone number under the &#8216;mobile&#8217; area of the telephones section of your active directory and within 5 minutes the user can log on remotely using only his browser and his cell phone.</p>
<p><b>Load balancing services</b></p>
<p>This is something that was added in along the way as scalability required that customers could separate the roles and load balance between them. Ex. also to make sure a SMS (text message) would not be stuck on a Modem which for some reason stopped sending out messages.</p>
<p><b>Transmitter Services</b></p>
<p>These are in charge of dispatching the passcodes via the SMS modems to the users.</p>
<p><b>Authentication Clients</b></p>
<p>Now these are the important part. These are the agents for different access types. The currently supported agents are:</p>
<ul>
<li>Citrix Web interface </li>
<li>Radius Challenge/Response
<ul>
<li>Checkpoint </li>
<li>Cisco </li>
<li>Citrix Access Gateway </li>
<li>Juniper </li>
<li>Etc. </li>
</ul>
</li>
<li>IIS sites(by using ISAPI filters)
<ul>
<li>Outlook Web Access 2003 </li>
<li>Outlook Web Access 2007 </li>
<li>IIS web sites using integrated windows authentication </li>
</ul>
</li>
<li>Windows logon(by altering the GINA)
<ul>
<li>Terminal Services </li>
<li>Windows Servers </li>
<li>Windows Workstations </li>
</ul>
</li>
<li>Logon Points in Citrix Access Gateway Advanced edition. </li>
</ul>
<p>All these together support most of the interfaces I come across in my daily work.</p>
<p><b>So how does it work for the user?</b></p>
<p>The logon procedure is the same for all the authentication clients,</p>
<p><a href="http://www.renevester.com/wp-content/uploads/2008/10/clip-image002.gif"><img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="84" alt="clip_image002" src="http://www.renevester.com/wp-content/uploads/2008/10/clip-image002-thumb.gif" width="460" border="0" /></a></p>
<p>the user logs in using his username and password, if this is done correctly and Active Directory, Novell or whatever replies with OK, a passcode is sent to the phone number registered with the user and the user is presented for a field to &#8216;enter passcode&#8217;. When the user enters the passcode and it is done from the same session that initiated the request the user is validated and allowed inside. This method is by the way called <i>challenge- and sessions based</i> 2-factor authentication and is a more secure method than ex. regular hardware based tokens since it prevents phishing.</p>
<p>I have found the integrations that have been made so far have been done quite nicely, let me try to take you through a couple of examples.</p>
<p><b>Citrix Web interface</b></p>
<p>The log in page we all know.</p>
<p><a href="http://www.renevester.com/wp-content/uploads/2008/10/clip-image004.gif"><img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="192" alt="clip_image004" src="http://www.renevester.com/wp-content/uploads/2008/10/clip-image004-thumb.gif" width="368" border="0" /></a></p>
<p>If the username and password is validated, in this case in active directory, a passcode is sent to the cell number registered on the user in active directory. The user is then presented with a field to enter the passcode, with information on the status of the SMS </p>
<p><a href="http://www.renevester.com/wp-content/uploads/2008/10/clip-image006.gif"><img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="183" alt="clip_image006" src="http://www.renevester.com/wp-content/uploads/2008/10/clip-image006-thumb.gif" width="365" border="0" /></a></p>
<p>and how long the passcode is valid.</p>
<p><a href="http://www.renevester.com/wp-content/uploads/2008/10/clip-image008.gif"><img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="184" alt="clip_image008" src="http://www.renevester.com/wp-content/uploads/2008/10/clip-image008-thumb.gif" width="364" border="0" /></a></p>
<p>If the passcode is valid users gets approved and are allowed into the applications.</p>
<p><a href="http://www.renevester.com/wp-content/uploads/2008/10/clip-image010.gif"><img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="241" alt="clip_image010" src="http://www.renevester.com/wp-content/uploads/2008/10/clip-image010-thumb.gif" width="364" border="0" /></a></p>
<p><b>Cisco VPN client, using Radius challenge/response</b></p>
<p>As normally the user logs on with his Cisco VPN client</p>
<p><a href="http://www.renevester.com/wp-content/uploads/2008/10/clip-image012.gif"><img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="147" alt="clip_image012" src="http://www.renevester.com/wp-content/uploads/2008/10/clip-image012-thumb.gif" width="344" border="0" /></a></p>
<p>And after validation of username and password using radius a challenge is sent in shape of a text message to the cell phone and the use is presented with a passcode response field</p>
<p><a href="http://www.renevester.com/wp-content/uploads/2008/10/clip-image014.gif"><img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="144" alt="clip_image014" src="http://www.renevester.com/wp-content/uploads/2008/10/clip-image014-thumb.gif" width="372" border="0" /></a></p>
<p>After the passcode has been validated the user is allowed access.</p>
<p><b>Windows logon</b></p>
<p>And my last example in this post will be the Gina. I have spoken to quite a few customers who would like to publish a terminal server directly on the internet using just RDP. One way of making this kind of solution a bit safer is to integrate 2-factor authentification into the GINA of the terminal server. </p>
<p>Before I show how this works, let me just point out that it is possible to make local groups with people who are not prompted for passcode when they log on. </p>
<p>So&#8230; you log on to your terminal server using whatever URL in your remote desktop client.</p>
<p><a href="http://www.renevester.com/wp-content/uploads/2008/10/clip-image016.gif"><img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="280" alt="clip_image016" src="http://www.renevester.com/wp-content/uploads/2008/10/clip-image016-thumb.gif" width="337" border="0" /></a></p>
<p>And in the same manner as I showed earlier in the article it then ships a passcode to the users cell phone and prompts the user for the passcode.</p>
<p><a href="http://www.renevester.com/wp-content/uploads/2008/10/clip-image018.gif"><img style="border-right: 0px; border-top: 0px; border-left: 0px; border-bottom: 0px" height="173" alt="clip_image018" src="http://www.renevester.com/wp-content/uploads/2008/10/clip-image018-thumb.gif" width="354" border="0" /></a></p>
<p>The supported platforms at the moment for the GINA agent is</p>
<ul>
<li>Windows XP pro </li>
<li>Windows Server 2003 </li>
<li>Windows Server 2003 x64 </li>
<li>Terminal Server running 2003 or 2003 x64 </li>
</ul>
<p><b>Is SMS PASSCODE the only way to go?</b></p>
<p>For sure no <img src='http://www.renevester.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' />  SMS PASSCODE provides a great way to deliver passcodes to the mobile work force. And luckily there is support for side-by-side functionality with SMS PASSCODE and RSA, Safeword so that you can use the best solution for the individual user.</p>
<p><b>So why is it that I am using SMS PASSCODE more and more?</b></p>
<p>Well for me SMS PASSCODE provides a stable, secure and scalable 2-factor authentication platform. It integrates in to most of the products I come across and on top of this it solves one of the main issues that my customers experience today. </p>
<p>On the administrative side of the token issue SMS PASSCODE solves quite a few of the pains for me.</p>
<ul>
<li>A user left the company
<ul>
<li>User is disabled in Active directory my helpdesk and thereby loses all remote access </li>
</ul>
</li>
<li>A token ran out of power
<ul>
<li>The cell phone is simply recharged on a regular basis </li>
</ul>
</li>
<li>A token had to be distributed to external consultants before they could work remotely
<ul>
<li>Users and cell numbers are simply added and the users gain remote access. </li>
</ul>
</li>
<li>Tokens had to be called back when the work of external consultants was done
<ul>
<li>Whenever the user is deleted or the cell number is removed, the license is freed up and can be used for another user. </li>
</ul>
</li>
</ul>
<p><b>We considered SMS before, but there is no QoS on SMS&#8230;</b></p>
<p>This is true but I will have to say that I have heard about problems when sending a SMS from a &#8220;western&#8221; SIM-card to a Chinese SIM-card. Sending a SMS from a Danish SIM-card to another Danish SIM-card in China is not a problem. The same seems to be the case in Slovakia. In these two cases I have had customers which have not been able to have the passcodes delivered in time, and for those users we have just raised the time limit of the OTP.</p>
<p>Besides that I have a lot of customers sending all their SMS&#8217;s from Denmark to users all over and the general opinion seems to be that this solves some of the token-pains for a large group of their users.</p>
<p><b>Conclusion</b></p>
<p>Everybody is using SMS today, everybody has a cell phone(how else would we vote in next episode of Idols?), why not use a device which is already found almost everywhere?</p>
<p>On the security and administrative side of things, I have heard of users where their token has been misplaced for weeks, months without them taking action. But whether it is a private cell phone or company cell phone, I have heard of only a few who has been able to live without it for more than a few days. And the users can even call their own Service provider and have their phone(token) locked out, saving the it-department the hassle of having a 24-7 phone support to help people who lose their tokens.</p>
<p>I want to become even more mobile and I think this product could help a lot of people to ease the troubles of having a secure remote access strategy.</p>
<p>/Rene Vester</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.renevester.com%2F2008%2F09%2Fa-new-approach-to-2-factor-authentication-on-vpn-and-citrix-solutions%2F&amp;title=2-factor%20authentication%20for%20Citrix%2C%20VPN%20and%20remote%20access%20in%20general%20using%20any%20cellphone%3F"><img src="http://www.renevester.com/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.renevester.com/2008/09/a-new-approach-to-2-factor-authentication-on-vpn-and-citrix-solutions/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>The &#8221;new&#8221; 2-factor authentication product SMSPasscode</title>
		<link>http://www.renevester.com/2007/03/the-%e2%80%9dnew%e2%80%9d-2-factor-authentication-product-smspasscode-3/</link>
		<comments>http://www.renevester.com/2007/03/the-%e2%80%9dnew%e2%80%9d-2-factor-authentication-product-smspasscode-3/#comments</comments>
		<pubDate>Sat, 17 Mar 2007 17:28:17 +0000</pubDate>
		<dc:creator>René Vester</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[authentication]]></category>
		<category><![CDATA[sms passcode]]></category>

		<guid isPermaLink="false">http://www.nightshade.dk/?p=65</guid>
		<description><![CDATA[Yesterday I had my first-hand experience with a product I have heard a lot about but never seen. The product is called SMSPasscode and is a direct competitor to products like Safeword and RSA. SMSPasscode provides 2-factor authentication, but moves the &#8216;object you have to have&#8217; inside one of our most common items, the cell [...]]]></description>
			<content:encoded><![CDATA[<p>Yesterday I had my first-hand experience with a product I have heard a lot about but never seen. The product is called SMSPasscode and is a direct competitor to products like Safeword and RSA. SMSPasscode provides 2-factor authentication, but moves the &#8216;object you have to have&#8217; inside one of our most common items, the cell phone. I have to be honest I was very skeptical but after my experience with SMSPasscode I do believe many customers would benefit from a solution like this.</p>
<p><strong></strong></p>
<p> <span id="more-26"></span>
<p><strong>Product outline</strong>The product consists of an engine, transmitters and modems. The engine tags the usernames to the predefined cell phone number for the user, and the transmitters and modems sends out the SMS-Text message.</p>
<p><strong>The logon process with Citrix WI and AG     <br /></strong>    <br />You connect to your Citrix Access Gateway as we all know it. There is no changes made to the Access Gateway as it is done in this example I setup &quot;Forwarding of credentials&quot; from the Access Gateway to the Citrix Web interface.    <br />So I log in on my Access Gateway logon-point.</p>
<p><img alt="" src="http://www.nightshade.dk/wp-content/031707_1601_Thenew2fac14.jpg" />    <br />As I type in my username and password and hit &#8216;Login&#8217; I am transferred to the Web interface-server and my username and password is forwarded from the Access Gateway. I am now prompted for a new pass code. This pass code is not in my possession but as soon as the SMSPasscode service detected my logon an SMS with my pass code was dispatched and arrives within a few seconds as a Flash-SMS on my cell phone. Whether you want a Flash-SMS or not is optional and can be configured from the web administration console.</p>
<p><img alt="" src="http://www.nightshade.dk/wp-content/031707_1601_Thenew2fac24.jpg" /></p>
<p>As my cell phone lights up I type in the pass code and is forwarded to my accessible Citrix Applications.</p>
<p><img alt="" src="http://www.nightshade.dk/wp-content/031707_1601_Thenew2fac34.jpg" /></p>
<p>The product seems very reliable, and easy to administrate when put into production and the great thing is that this product can coexist with Safeword or RSA and you are able to provide differentiated methods for 2-factor authentication, maybe you have external partners and want them to only log on once or twice, this is easily done with SMSPasscode as you can simply add a user and join it with a phone number in the administration interface and the user is able to log on, without having to dispatch a physical token to the partner or customer.</p>
<p>SMSPasscode is running on its third year and the product has matured nicely. Within a few months a new release will be out a version 2.0, to mention a few of the new features:   <br />- Radius Server    <br />- ISAPI    <br />- LDAP</p>
<p>The new features will be welcomed and in particular I am looking forward to the radius option to see how well the integration will be directly on the Citrix Access Gateways. But all this will come hopefully within a month, and I will be sure to write a post about the version 2.0 release as soon as I get my hands on it.</p>
<p><strong>Where do I see SMSPasscode integration in the near future     <br /></strong>    <br />My personal belief is that this technology could actually mean the beginning of something great as I can imagine public institutions using this technology to provide 2-factor authentication when we are doing our taxes online, shopping for pizza or even when trusted users log in to the most confidential parts of our ERP, CRM or what have we. The technology is suddenly opening the door as we can now remove the logistics tied in with delivering a physical token to customers, partners or employees.</p>
<p><strong>My impression so far</strong></p>
<p>As it has might shown through this post I am very excited about this new product and the possibilities. The features to support a Citrix Access infrastructure is in place and works very well and the next exciting step for me will be when we get the extended integration in form of ISAPI, LDAP and Radius.</p>
<p>I will deliver an update on SMSPasscode as soon I have had a chance to work more with the version 2.0. If you want more information you are welcome to contact me or take a look around <a href="http://www.smspasscode.dk">www.smspasscode.dk</a> they have a good site with lots of good information, screenshots and testimonials from their many large Danish customers.</p>
<p>/Rene Vester</p>
<p><a class="a2a_dd addtoany_share_save" href="http://www.addtoany.com/share_save#url=http%3A%2F%2Fwww.renevester.com%2F2007%2F03%2Fthe-%25e2%2580%259dnew%25e2%2580%259d-2-factor-authentication-product-smspasscode-3%2F&amp;title=The%20%26rdquo%3Bnew%26rdquo%3B%202-factor%20authentication%20product%20SMSPasscode"><img src="http://www.renevester.com/wp-content/plugins/add-to-any/share_save_120_16.png" width="120" height="16" alt="Share"/></a> </p>]]></content:encoded>
			<wfw:commentRss>http://www.renevester.com/2007/03/the-%e2%80%9dnew%e2%80%9d-2-factor-authentication-product-smspasscode-3/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
	</channel>
</rss>

