Understanding Authentication and Authorization Los Angeles CA

After you have physically secured your environment, you then want to focus on the people who access your systems and network. The next step after implementing physical security is to ensure that persons who have entered your server room or have a connection to a network port are authorized to log on to the network. Logging onto the network is known as authentication.

Local Companies

Earthlinc
818-240-0968
412 W Broadway
Glendale, CA
A T & T
818-291-0801
207 N Brand Blvd
Glendale, CA
C & C Business Center
818-548-3400
101 N Brand Blvd
Glendale, CA
Dedication Channel Inc
818-548-5047
130 N Brand Blvd
Glendale, CA
Recomm Wireless
818-242-5500
101 N Brand Blvd
Glendale, CA
Glendale Wireless
818-239-3861
217 N Verdugo RD
Glendale, CA
Inverselogic LLC
818-542-3103
3439 Ocean View Blvd
Glendale, CA
JDR Computer Inc.
562-407-9308
14111 Freeway Drive
Santa Fe Springs, CA
MM Internet
562-427-3632
3780 Kilroy Airport Way
Long Beach, CA
Akamai Technologies Inc
562-981-6044
3760 Kilroy Airport Way
Long Beach, CA


provided by:


For Dummies is a registered trademark of Wiley Publishing, Inc. in the United States and other countries. Used here by license.




Authentication

Authentication is the process of proving one’s identity to the network environment. Typically, authentication involves typing a username and password on a system before you are granted access, but you could also use biometrics to be authenticated. Biometrics are the use of one’s unique physical characteristics, such as a fingerprint or the blood vessels in one’s retina, to prove one’s identity.

Here’s a quick look at what happens when you log on to your system with a username and password. When you type a username and password to log on to a system, that username and password are verified against a database, known as the user account database, which has a list of the usernames and passwords that are allowed to access the system. If the username and password you type are in the user account database, you are allowed to access the system — otherwise, you get an error message and aren’t allowed to access the system.

The name of the account database that stores the usernames and passwords is different depending on the environment. In a Microsoft network, the account database is known as the Active Directory Database and resides on a server known as a domain controller.

Generating the access token

When you log on to a Microsoft network environment, the username and password you type are placed in a logon request message that is sent to the domain controller to be verified against the Active Directory Database. If the username and password that you have typed are correct, then an access token is generated for you. An access token is a piece of information that identifies you and is associated with everything you do on the computer and network. The access token contains your user account information and any groups you are a member of. When you try to access a resource on the network, the user account and group membership in the access token are compared against the permission list of a resource. If the user account in the access token or one of the groups contained in the access token are also contained in the permission list, then you are granted access to the resource — if not, you get an access denied message.

If you don’t have a server-based network environment and you are simply running Windows 2000 Professional or Windows XP, when you log on, the logon request is sent to the local computer — to an account database known as the Security Accounts Manager (SAM) database. When you log on to the SAM database, an access token is generated as well, and that helps the system determine what files you can access.

Smart card

Another type of logon supported by network environments today is the use of a smart card. A smart card is a small, ATM card–like device that contains your account information. You insert the smart card into a smart card reader that is connected to a computer, and then you enter the PIN (Personal Identification Number) associated with the smart card. This is an example of securing an environment by forcing someone to not only have the card but also know the PIN.

Strong passwords

It’s really hard to talk about authentication without talking about ensuring that users create strong passwords. A strong password is a password that is very difficult for hackers to guess or crack because it contains a mix of upper and lowercase characters, contains a mix of numbers and letters, and is a minimum of six characters long.

Authorization

After a user has logged on and an access token is created, the user may start trying to access resources such as files and printers. In order to access a file, folder, or printer on the network, the user must be authorized to access the resource. Authorization is the process of giving a user permission to access a resource. Do not confuse authentication and authorization — you must be first authenticated to the network, and once authenticated, you can then access the resources you have been authorized for.

In order to authorize access to a resource, you set permissions on the resource. For example, if you want to allow Jill to access the accounting folder, you need to give Jill permission to the accounting folder.

No one else is authorized to access the resource. You find out how to set permissions in the next chapter, but for now, make sure you understand the difference between authentication and authorization.


provided by:


For Dummies is a registered trademark of Wiley Publishing, Inc. in the United States and other countries. Used here by license.


Featured Local Company

Earthlinc

818-240-0968
412 W Broadway
Glendale, CA

Related Local Events
2009 IEEE Petroleum and Chemical Industry Technical Conference (PCIC 2009)
Dates: 9/14/2009 - 9/16/2009
Location:
Anaheim, CA
View Details

DIGITAL ID WORLD 2009
Dates: 9/1/2009 - 9/1/2009
Location: Hilton Anaheim
Anaheim, CA
View Details

Medical Design & Manufacturing - Trade
Dates: 6/9/2009 - 6/11/2009
Location: CANON COMMUNICATIONS LLC
Los Angeles, CA
View Details

Atlantic Design & Manufacturing - Trade
Dates: 6/9/2009 - 6/11/2009
Location: CANON COMMUNICATIONS LLC
Los Angeles, CA
View Details

Green Manufacturing Expo
Dates: 6/9/2009 - 6/11/2009
Location: CANON COMMUNICATIONS LLC
Los Angeles, CA
View Details