Cisco LEAP is a mutual authentication algorithm that supports dynamic derivation of session keys. With Cisco LEAP, mutual authentication relies on a shared secret, the user's logon password, which is known by the client and the network, and is used to respond to challenges between the user and the Remote Authentication Dial-In User Service (RADIUS) server. As with most password-based authentication algorithms, Cisco LEAP is vulnerable to dictionary attacks. Cisco has now announced the availability of EAP Flexible Authentication via Secure Tunneling (EAP-FAST) for users who wish to deploy an 802.1X Extensible Authentication Protocol (EAP) type that does not require digital certificates and is not vulnerable to dictionary attacks.
Related white papers
Introduction to Oracle Identity Management
Oracle Identity Management is an open, extensible, and standards-based infrastructure that can accommodate a wide variety of deployments, partner solutions and customer environments. For example, partner products may leverage Oracle...
Balancing Security Against Productivity
What makes for great security? Is it about keeping the bad guys out or letting the good guys in? About defending attacks or preventing them? When IDG Research Services queried...
Secure Desktop On-Demand Webcast
The desktop or endpoint is one of the most vulnerable parts of your environment. Threats are everywhere. You have users who love to experiment with device settings (only to wonder...
Novell Zenworks Endpoint Security Management: Total Control from a Single Console
Still super gluing your USB ports shut? Unauthorized access to networks, lost or stolen laptops and other mobile hardware, and theft of proprietary information or intellectual property accounted for more...
Ensuring Data Protection for Growing Business
Small and midsize businesses have become increasingly reliant on IT. In this paper, we look at how SMBs often progress through the IT adoption cycle, and some of the operational...
Managing the Windows Vista Migration
As organizations move to Windows Vista, they'll need a migration strategy that keeps conflicts and system disruptions in check, minimizes user downtime and inconvenience, and doesn't expose systems to security...
Solid Windows Vista Protection
The new security features included in Vista are a step forward in helping businesses defend against attacks, but they cannot be considered a complete, multi-layered defense. It goes without saying...

