|
Directories are generally deployed in support of other applications, such as messaging and PKI (Public Key Infrastructure) based security. Information in the directory is usually openly available to any client with access to the directory servers, which may be on the Internet or on a closed network or LAN/VPN.
This open access to data means that there are generally no security concerns related to data confidentiality or on controlling access to data – a goal of the directory is to make information available. However, data in the directory is often of critical importance to the applications using the directory. Tampering with or removing data in the directory can cause severe problems to such applications. Isode's Secure Directory solution provides a high level of protection against such problems. This page describes the security threats, and how Isode's Secure Directory solution protects against them. Application Security ThreatsThe nature of security threat to applications relying on directory due to tampering with or removal of data from the directory is illustrated by three examples:
Directory Security ThreatsFrom a directory viewpoint, there are two basic approaches to creating the application security threats:
The net effect of both of these types of attack is the same. The important protection against both of these attacks is authentication. If a directory server is modifying data, it should correctly authenticate the client requesting the changes. If a client (or directory server) is receiving data from a directory server it should authenticate the server. Correct authentication will enable these attacks to be prevented. Strong AuthenticationIsode's Secure Directory solution is based on strong authentication, using digital signatures and PKI to provide several services:
Strong authentication provides a higher level of protection than password based authentication. It simplifies administration for server/server authentication, and enables server authentication and signed operations (which cannot be provided with password based authentication). More information on strong authentication is provided in three Isode white papers:
Secure ManagementThe strong authentication capabilities described above are supported by Isode's M-Vault directory server. This includes the ability to require signed operations for all updates, which enforces a high level of security for all changes to directory data.
Isode also provides Sodium (Secure Open Data, Identity and User Manager) as an administrative tool for securely managing data in the directory (shown above). This is a critical component of a secure directory system. Supporting CapabilitiesWhile strong authentication is the central capability that differentiates Isode’s Secure Directory, there are some related capabilities that are also important:
|
|
| Copyright © 2009 Isode | sitemap privacy feedback
|