To: steve who wrote (19372 ) 12/7/2000 3:15:27 PM From: steve Read Replies (2) | Respond to of 26039 A couple three resellers and Gov IT Yellow pages and JPD - Jackson Police Department Mississippi AIXpresso softwareaixpresso.de Norway Toms Computertoms-computer.no toms-computer.no Costa Rica Suplidora de Equipos S.A.suplesa.com Florida FCM, Incfcm-inc.com US Gov Governments IT Yellow Pages... GovTechNet Product Source Companiesproductsource.govtech.net Networkcomputing.com article Authentication at Its Finest October 16, 2000networkcomputing.com A discussion about Novell NetWare security would be incomplete without mentioning NMAS (Novell Modular Authentication Services). There are two reasons why a company would want to implement this technology: Passwords aren't strong enough and alternatives are required, or management wants to restrict access to certain data based on "sequence" and "clearance" levels. The sequence defines what method or methods of authentication must be satisfied before authentication is granted. Many sequences are available: Biometric, token, X.509, password and smart cards are but a few. Novell coins the collective of these sequences as "something we are," "something we have" and "something we know." Within the parameters of a sequence, users can then decide upon a given clearance. A user's clearance determines what authentication will be granted him or her to individual NSS volumes, based on predefined policies. While currently only NSS (Novell Storage Services) volumes can be restricted with NMAS, more granularity is expected in the future, giving the same type of graded security to all NDS objects. We tested one biometric device, one token-based device, an X.509 key and a simple NDS password. Identix sent us a demo of its MT Digit fingerprint reader, and Vasco Data Security sent us a demo of the Digipass 300 challenge-response token device. Both of these devices proved formidable for securing authentication. Novell provides other methods of authentication with the NMAS product, of which we tested an X.509 certificate with our private key being accessed from disk and a simple NDS password. Individually and in combinations, authentication was quick and painless. For a list of Novell partners coding for the NMAS product, see www.novell.com/products/nmas/partners/ JPD - Jackson Police Department Mississippi The Identification Unit is responsible for the operation of the Automated Fingerprint Identification System (AFIS). This computer based ten-print fingerprint storage system is the most advanced fingerprint analysis system that is available today. The new technologies that are presently being acquired in the Identification Unit include the Identix/Mugshot computer fingerprint and photograph system and the connection with the national computer based system for AFIS through the State of Mississippi and The Federal Bureau of Investigation. city.jackson.ms.us steve