home
NEWS       BLOGS       FORUMS       NEWSLETTERS       RESEARCH       EVENTS       DIGITAL LIBRARY       CAREERS  
Network Computing Network Computing Powered by InformationWeek Business Technology Network

IMMERSE YOURSELF:

SOA

  |

Data Center

  |

802.11n

  |

Data Privacy

  |
APO  |

Virtualization

  |

NAC

  |

Security

  |

Network Mgmt

  |

Enterprise Apps

  |

Storage & Servers


Network & Systems Management
F E A T U R E  
Authentication Gets Tough

  May 28, 2001
  By Michael Ross and Jeff Rubin



Securant Technologies ClearTrust SecureControl 4.5

Securant's ClearTrust SecureControl outperformed the competition in every category; it has unique features, a superb management console and lightning performance. Although the two runners-up, Baltimore SelectAccess and Entrust getAccess, offer very good solutions, the final tally for best product put ClearTrust at the top.

The ClearTrust environment includes an entitlements server, a dispatch server, an authorization server and a Web server plug-in. All the services installed without errors on our Microsoft Windows NT 4.0 servers, and subsequent installations on our other two Web servers went quickly and flawlessly. ClearTrust uses secret keys generated by the authorization server to secure communication between Web servers and authorization servers. Although this is a manual process, we like the added degree of control over the security keys, a facet not found in other products. The command-line keygen utility, contained on secure CT authorization servers, gave us the flexibility to generate new keys for secure communication between each Web and authorization server.

After setting up the environment, we easily created custom login pages for our pre-existing, forms-based logins. By default, ClearTrust uses a rather annoying pop-up box to request user credentials. However, the product ships with templates for forms-based, SecureID and NT logins. As a result, adding new authentication types is a breeze.

ClearTrust's greatest strength is its management environment, offered both as a Java client and as a Web interface driven by servlets. The Java client is well-organized and easy to use and provided the fastest response time among administrative tools of the products we tested. Because our product server was not set up to use servlets, we downloaded and installed Allaire Corp.'s JRun as our Web server for the ClearTrust servlet-management interface. The Java- and Web-based interfaces are identical in design and functionality, so we stayed with the Java client for our tests.

Although ClearTrust's administrative-delegation capabilities are similar to those of the other products, this product has some helpful enhancements. For example, it can track users and resources other administrators have added. This alleviates security concerns regarding administrative control if an administrator leaves the company.

Securant also leads the pack with its SecureDetector component. No other product we tested offers an IDS (intrusion-detection system) with the application and security logging features SecureDetector provides. SecureDetector lets you define a broad range of reports, from password guessing to time-of-day restricted access.

Most impressive, we found no significant performance degradation when using the SecureControl plug-in on our Web servers. In the SecureControl environment, the transaction chain begins with the Web server plug-in, which speaks to a dispatch server. Subsequently, an authorization and entitlements server communicates with the directory server. No user or authentication information is cached by the plug-in, dramatically reducing security risks by eliminating stale data. Repeated calls to the authentication server is the performance trade-off, but it took three Web servers handling more than 2,000 simultaneous connections (logging in and browsing) to raise CPU usage on the authorization and entitlements server above 50 percent. When we stopped our test at 2,400 simultaneous connections, response time was 4.7 seconds per Web page and 569 transactions per second across the entire system. For this test, we considered each file request -- HTML/ASP (Active Server Page), image and so on -- as a transaction.

ClearTrust SecureControl 4.5, starts at $20 per user. Securant Technologies, (415) 315-1500; fax (415) 315-1545. http://www.securant.com


   Page: 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 | Next Page





Ready to take that job and shove it?

Function:

Keyword(s):

State:
SPONSOR
RECENT JOB POSTINGS
CAREER NEWS
Go beyond Google and get vertical. These specialized search sites will help you find the business information you need -- fast.

Ari Balogh was named to the post of chief technology officer as the companys for a "realignment" of employees.










InformationWeek U.S. IT Salary Survey 2008
Salaries for business technology professionals are falling. Here's what you need to know in order to make good hiring decisions and personal career choices. Download Today
 
ROLLING RIGHT ALONG
Follow key Network Computing Reviews from conception to completion. This Week: Holistic APM.



Network Computing Reports Emerging Enterprise Podcast Series: Secrets to Success








TechSearch


Microsite of the Week


Powerful Information at Your Fingertips



InformationWeek Business Technology Network
InformationWeekInformationWeek 500InformationWeek 500 ConferenceInformationWeek AnalyticsInformationWeek CIO
InformationWeek EventsInformationWeek ReportsInformationWeek MagazinebMightyByte and SwitchDark Reading
Digital LibraryIntelligent EnterpriseInternet EvolutionNetwork ComputingNo Jitter
space
Techweb Events Network
InteropVoiceConWeb 2.0 ExpoWeb 2.0 SummitEnterprise 2.0 ConferenceMobile Business ExpoSoftware ConferenceCSI - Computer Security Institute
Black HatGTECEnergy CampMashup CampStartup Camp
space
Light Reading Communications Network
Light ReadingLight Reading EuropeUnstrungLight Reading's Cable Digital NewsConstantinopleInternet Evolution
Heavy ReadingLight Reading Live!Light Reading InsiderEthernet ExpoOptical ExpoTeleco TVTower Technology Summit
space
Financial Technology Network
Advanced TradingBank Systems & TechnologyInsurance & TechnologyWall Street & TechnologyAccelerating Wall StreetBank Systems & Technology Executive SummitBuyside Trading SummitInsurance & Technology Executive Summit
space
Microsoft Technology Network
MSDN MagazineTechNetThe Architecture Journal
space
App Infrastructure   |   Messaging & Collaboration   |   Network & Systems Mgmt   |   Network Infrastructure   |   Security  |   Storage & Servers   |   Wireless   |   Enterprise Apps
About Us  |  Contact Us  |  Site Map  |  Technology Marketing Solutions  |  Advertising Contacts  |   Briefing Centers
Copyright © 2008  United Business Media LLC  |  Privacy Statement  |  Terms of Service  |  Your California Privacy Rights