cloudstack-dev mailing list archives

Site index · List index
Message view « Date » · « Thread »
Top « Date » · « Thread »
From Nick Owen <no...@wikidsystems.com>
Subject Re: Cloudstack two-factor authentication plugin
Date Tue, 21 Aug 2012 15:20:31 GMT
Also, if anyone wants to test without setting up a WiKID server, let
me know. I can set it up on one of our demo servers.

On Fri, Aug 17, 2012 at 12:53 PM, Will Chan <will.chan@citrix.com> wrote:
> +1 to this addition.  Fantastic work.
>
> ________________________________________
> From: owen.nick@gmail.com [owen.nick@gmail.com] On Behalf Of Nick Owen [nowen@wikidsystems.com]
> Sent: Friday, August 17, 2012 8:13 AM
> To: cloudstack-dev@incubator.apache.org
> Subject: Cloudstack two-factor authentication plugin
>
> Greetings!
>
> I recently did a presentation on cloud infrastructure and strong
> authentication.  As part of that effort, we have released a plugin for
> Cloudstack that requires users to use WiKID two-factor authentication
> when logging into the Cloudstack admin.  The source and a jar file can
> be found on our sourceforge site here
> https://sourceforge.net/projects/wikid-twofactor/files/Cloudstack%20WiKID%20Integration/
> and is licensed under the ASL v2.  An installation doc is here:
> http://www.wikidsystems.com/support/wikid-support-center/how-to/how-to-add-wikid-two-factor-authentication-to-cloudstack-manager.
>
> Some background:  WiKID use asymmetric encryption embedded in software
> tokens to securely transmit PINs one way and OTPs the other to
> authenticate users.  We have a dual source model.  This code is fully
> compatible with the open-source Community version.
>
> Why did we do this? Because static passwords suck.  Why should you be
> interested in this? Because almost all attacks involve some escalation
> of privilege from weak, guessable, stolen or default credentials.
> "Cloud" brings  tremendous benefits but puts a great deal of strain on
> authentication at all levels.
>
> We would love to have this code included in the cloudstack build, if
> there is interest.
>
> Thanks,
>
> Nick
>
> --
> Nick Owen
> WiKID Systems, Inc.
> http://www.wikidsystems.com
> #wikid on freenode
> @wikidsystems



-- 
--
Nick Owen
WiKID Systems, Inc.
http://www.wikidsystems.com
Commercial/Open Source Two-Factor Authentication

Mime
View raw message