Information Security

Activate your FREE membership today  |  Log-in

  • Visit other TechTarget ANZ sites: 
Posted
May 16, 2008
 |  By
Sandra Kay Miller

REVIEW: Secure Computing SafeWord

SafeWord 2008
Price: Starts at $854 for a five-user starter pack.

 

Passwords are no longer effective for remote access to critical applications. Increasingly, organisations are turning to two-factor authentication. SafeWord delivers identity management and access control for Windows systems using tokens that generate secure single-use passcodes that cannot be stolen or hacked, to complement existing remote access infrastructure such as VPNs.

It supports a variety of remote access products including those from Citrix, Cisco, Check Point, Nortel, Juniper, F5, Aventail and any other RADIUS-based VPN.

 

Configuration/Management A  

There are two configuration options--via Active Directory or using the SafeWord 2008 Management Console, which is one of the components of the optional Enterprise Solution Pack (ESP). ESP offers a variety of useful features including SecureWire Access Gateway (an SSL VPN with unlimited users), protection for Windows login, and MobilePass, which generates the same passcodes as the physical token through mobile devices.

The basic installation of SafeWord Server, the management console and the Auto Updater Agent were straightforward, simple port settings for the authentication engine, administrative service and database, host addresses and key signing.

AD offered the easiest and quickest setup. We needed only to open AD to launch SafeWord. The Management Console operates independently through the Windows program groups. Users can be imported directly from AD or a third-party database.

We tested the Alpine model token, which comes with a lifetime guarantee. You can get a premium token with numeric keypads for added PIN-based protection.

Lost or damaged tokens can rapidly be decommissioned, replaced and reassigned. Emergency passcodes can be generated as well.

 

Reporting and Logging B  

With regulatory compliance driving many security purchases, SafeWord covers the bases with extensive logs for administrative actions and authentication.

To make log files more manageable, we were able to configure how frequently log files would be transferred from the database into an archive file for more efficient storage. However, to view an archived log, the file must be loaded back onto the database. Reports can be created through the tools option on the admin server. Log data can be exported into third-party report generators or Microsoft Excel spreadsheets for custom graphs, tables and charts. While the data sets for the templates were easy to assign, the actual report generation into spreadsheet format didn't work very well, splitting data into multiple sheets instead of into a single master table.

 

Effectiveness A  

SafeWord's flexibility in securing user access provides a variety of ways for organisations to effectively control remote access through various multifactor authentication scenarios. Users have a choice between several methods including a combination of synchronous (event- or time-based), asynchronous (challenge-response), memorised, appended, CHAP-encoded and dynamic passwords. Multiple users can also share a single token, but each will have a different password.

Any organisation with a significant mobile workforce armed with smartphones and PDAs should seriously consider purchasing the optional ESP for the MobilePass feature, which generates authentication codes on mobile devices in lieu of hardware tokens.

Verdict

SafeWord 2008's package is an attractive option for organisations wanting to add cost-effective, yet strong, two-factor authentication.

 


Testing methodology: We tested SafeWord on Microsoft Windows 2003 Server, managing with both Active Directory and with the SafeWord 2008 console. We also evaluated the optional add-on module, Enterprise Solution Pack.

 


TechTarget ANZ sites: SearchCIO.com.au | SearchNetworking.com.au | SearchSecurity.com.au | SearchStorage.com.au | SearchVoIP.com.au

WF Online community sites: ElectricalSolutions | ElectronicsOnline | FoodProcessing | InMotionOnline | LabOnline | ProcessOnline | RadioComms | SafetySolutions | SustainabilityMatters | Voice&Data

Copyright © 2008 Westwick-Farrow Pty Ltd. All rights reserved.
About Us | Contact Us | TechTarget