
Authus is een modulaire AAA-oplossing ontwikkeld door HENZ ICT, gebouwd op de beproefde Radiator AAA Server. Het systeem is ontworpen voor maximale flexibiliteit, uitgebreide protocolondersteuning en volledige compliance met moderne security-eisen.
Daarnaast vinden wij het belangrijk dat je niet afhankelijk bent van een vendor. Al je netwerk apparatuur kan je aansluiten op Authus om de authenticatie te verzorgen.
Ondersteunde protocollen en standaarden
Authus ondersteunt een breed scala aan authenticatie-, autorisatie- en accountingprotocollen:
Authenticatie
- RADIUS (RFC 2865, RFC 2866, RFC 3576)
- TACACS+
- Multifactor authenticatie opties:
- Microsoft OTP
- Microsoft Push notifications (geen Number matching)
- Google Authenticator
- Duo Security
- RSA Token
- YubiKey
- DigiPass
- EAP-methoden:
- EAP-TLS
- EAP-TTLS (met PAP, CHAP, MSCHAPv2)
- PEAP (v0/v1)
- EAP-MSCHAPv2
- EAP-FAST
- EAP-GTC
- EAP-PWD
- MD5
- Generic Token Card
- LEAP
- FAST
- TLS
- TTLS
- PAP
- CHAP
- MSCHAPV1
- MSCHAPV2
- PEAP
- PWD
- IPv4, IPv6, UDP, TCP
Management en integratie
- RESTful API’s voor provisioning en logging
- SNMP(V2 en V3) voor monitoring
- Syslog (UDP/TCP, met support voor TLS)
Logging en auditing
Authus biedt uitgebreide loggingmogelijkheden, geschikt voor troubleshooting, auditing en compliance:
- Authenticatie-logging: volledige logging van login pogingen, response codes, authenticatiemethodes, client-identificatie en reply attributes
- Authorisatie-logging: volledige logging van de TACACS authorisatie pogingen
- Accounting logs: volledige logging van gebruikerssessies, met onder andere NAS-identificatie
De logging is extern te pushen naar een syslog server of een ander logging dienst (een ELC stack bijvoorbeeld )
De RFC's
Authus voldoet uiteraard aan een aantal RFC's. Voor de echte techneut hier een lijst van de RFC's:
- RFC 2486 - The Network Access Identifier
- RFC 2548 - Microsoft Vendor-specific RADIUS Attributes
- RFC 2578 - Structure of Management Information Version 2 (SMIv2)
- RFC 2607 - Proxy Chaining and Policy Implementation in Roaming
- RFC 2759 - Microsoft PPP CHAP Extensions, Version 2
- RFC 2809 - Implementation of L2TP Compulsory Tunneling via RADIUS
- RFC 2865 - Remote Authentication Dial In User Service (RADIUS)
- RFC 2866 - RADIUS Accounting
- RFC 2867 - RADIUS Accounting Modifications for Tunnel Protocol Support
- RFC 2868 - RADIUS Attributes for Tunnel Protocol Support
- RFC 2869 - RADIUS Extensions
- RFC 3162 - RADIUS and IPv6
- RFC 3447 - Public-Key Cryptography Standards (PKCS) #1: RSA Cryptography
- RFC 3579 - RADIUS (Remote Authentication Dial In User Service) Support For Extensible Authentication Protocol (EAP)
- RFC 3580 - IEEE 802.1X Remote Authentication Dial In User Service (RADIUS) Usage Guidelines
- RFC 3748 - Extensible Authentication Protocol (EAP)
- RFC 4137 - State Machines for Extensible Authentication Protocol (EAP) Peer and Authenticator
- RFC 4226 - HOTP: An HMAC-Based One-Time Password Algorithm
- RFC 4372 - Chargeable User Identity
- RFC 4603 - Additional Values for the NAS-Port-Type Attribute
- RFC 4648 - The Base16, Base32, and Base64 Data Encodings
- RFC 4669 - RADIUS Authentication Server MIB for IPv6
- RFC 4671 - RADIUS Accounting Server MIB for IPv6
- RFC 4675 - RADIUS Attributes for Virtual LAN and Priority Support
- RFC 4679 - DSL Forum Vendor-Specific RADIUS Attributes
- RFC 4746 - Extensible Authentication Protocol (EAP) Password Authenticated Exchange
- RFC 4764 - The EAP-PSK Protocol: A Pre-Shared Key Extensible Authentication Protocol (EAP) Method
- RFC 4818 - RADIUS Delegated-IPv6-Prefix Attribute
- RFC 4849 - RADIUS Filter Rule Attribute
- RFC 4851 - The Flexible Authentication via Secure Tunneling Extensible Authentication Protocol Method (EAP-FAST)
- RFC 5080 - Common Remote Authentication Dial In User Service (RADIUS) Implementation Issues and Suggested Fixes
- RFC 5090 - RADIUS Extension for Digest Authentication
- RFC 5106 - The Extensible Authentication Protocol-Internet Key Exchange Protocol version 2 (EAP-IKEv2) Method
- RFC 5176 - Dynamic Authorization Extensions to Remote Authentication Dial In User Service (RADIUS)
- RFC 5216 - The EAP-TLS Authentication Protocol
- RFC 5246 - The Transport Layer Security (TLS) Protocol Version 1.2
- RFC 5247 - Extensible Authentication Protocol (EAP) Key Management Framework
- RFC 5281 - Extensible Authentication Protocol Tunneled Transport Layer Security Authenticated Protocol Version 0 (EAP-TTLSv0)
- RFC 5422 - Dynamic Provisioning Using Flexible Authentication via Secure Tunneling Extensible Authentication Protocol (EAP-FAST)
- RFC 5516 - Diameter Command Code Registration for the Third Generation Partnership Project
- RFC 5580 - Carrying Location Objects in RADIUS and Diameter
- RFC 5580 - Carrying Location Objects in RADIUS and Diameter
- RFC 5607 - Remote Authentication Dial-In User Service (RADIUS) Authorization for Network Access Server (NAS) Management
- RFC 5608 - Remote Authentication Dial-In User Service (RADIUS) Usage for Simple Network Management Protocol (SNMP) Transport Models
- RFC 5904 - RADIUS Attributes for IEEE 802.16 Privacy Key Management Version 1 (PKMv1) Protocol Support
- RFC 5931 - Extensible Authentication Protocol (EAP) Authentication Using Only a Password
- RFC 5997 - Use of Status-Server Packets in the Remote Authentication Dial In User Service (RADIUS) Protocol
- RFC 5998 - An Extension for EAP-Only Authentication in IKEv2
- RFC 6158 - RADIUS Design Guidelines
- RFC 6238 - TOTP: Time-Based One-Time Password Algorithm
- RFC 6421 - Crypto-Agility Requirements for Remote Authentication Dial-In User Service (RADIUS)
- RFC 6519 - RADIUS Extensions for Dual-Stack Lite
- RFC 6572 - RADIUS Support for Proxy Mobile IPv6
- RFC 6613 - RADIUS over TCP
- RFC 6614 - Transport Layer Security (TLS) Encryption for RADIUS
- RFC 6677 - Channel-Binding Support for Extensible Authentication Protocol (EAP) Methods
- RFC 6678 - Requirements for a Tunnel-Based Extensible Authentication Protocol (EAP) Method
- RFC 6911 - RADIUS Attributes for IPv6 Access Networks
- RFC 6929 - Remote Authentication Dial In User Service (RADIUS) Protocol Extensions
- RFC 6930 - RADIUS Attribute for IPv6 Rapid Deployment on IPv4 Infrastructures (6rd)
- RFC 6960 - X.509 Internet Public Key Infrastructure Online Certificate Status Protocol - OCSP
- RFC 7055 - A GSS-API Mechanism for the Extensible Authentication Protocol
- RFC 7056 - Name Attributes for the GSS-API Extensible Authentication Protocol (EAP) Mechanism
- RFC 7268 - RADIUS Attributes for IEEE 802 Networks
- RFC 7585 - Dynamic Peer Discovery for RADIUS/TLS and RADIUS/DTLS Based on the Network Access Identifier (NAI)
- RFC 7593 - The eduroam Architecture for Network Roaming
- RFC 7930 - Larger Packets for RADIUS over TCP
- RFC 8044 - Data Types in RADIUS
- RFC 8146 - Adding Support for Salted Password Databases to EAP-pwd
- RFC 8559 - Dynamic Authorization Proxying in the Remote Authentication Dial-In User Service (RADIUS) Protocol
- RFC 8907 - The Terminal Access Controller Access-Control System Plus (TACACS+) Protocol
- RFC 9190 - EAP-TLS 1.3: Using the Extensible Authentication Protocol with TLS 1.3
- RFC 9427 - TLS-based EAP types and TLS 1.3
Geïnteresseerd?
Er is meer informatie over Authus:
Wij laten je graag de kracht van Authus zien.
Vraag een demo aan