Skip to Content
Building Internet Firewalls, 2nd Edition
book

Building Internet Firewalls, 2nd Edition

by Elizabeth D. Zwicky, Simon Cooper, D. Brent Chapman
June 2000
Intermediate to advanced
894 pages
30h 54m
English
O'Reilly Media, Inc.
Content preview from Building Internet Firewalls, 2nd Edition

Chapter 21. Authentication and Auditing Services

Services can get information about how to identify users, and what users are allowed to do, from various sources. For instance, they can keep local files (this is what Unix web servers do when they use “basic” authentication), or they can use the operating system’s normal methods (this is what Windows NT web servers do when they use “Windows NT Challenge/Response” authentication). However, there is now a third popular option, a centralized authentication service that is independent of the specific service and the specific computer the service is running on. That service makes up part of something often referred to as an AAA server.

An AAA server (sometimes spoken as “Triple A server”) provides authentication, authorization, and auditing services:

Authentication

The process of obtaining verified, proven identification. Authentication determines who somebody or something is.

Authorization

The process of determining what somebody can do. Don’t confuse authentication and authorization. Authentication is a prerequisite for authorization (unless everybody is authorized to do something, such as anonymous FTP).

Auditing

Provides information on when authentication and authorization was granted or denied.

Authentication services attempt to prove identity, to ensure that you know what person you are dealing with. This task can be very easy if it doesn’t matter very much and you are in an environment you trust, or very difficult if people may be trying ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.

Read now

Unlock full access

More than 5,000 organizations count on O’Reilly

AirBnbBlueOriginElectronic ArtsHomeDepotNasdaqRakutenTata Consultancy Services

QuotationMarkO’Reilly covers everything we've got, with content to help us build a world-class technology community, upgrade the capabilities and competencies of our teams, and improve overall team performance as well as their engagement.
Julian F.
Head of Cybersecurity
QuotationMarkI wanted to learn C and C++, but it didn't click for me until I picked up an O'Reilly book. When I went on the O’Reilly platform, I was astonished to find all the books there, plus live events and sandboxes so you could play around with the technology.
Addison B.
Field Engineer
QuotationMarkI’ve been on the O’Reilly platform for more than eight years. I use a couple of learning platforms, but I'm on O'Reilly more than anybody else. When you're there, you start learning. I'm never disappointed.
Amir M.
Data Platform Tech Lead
QuotationMarkI'm always learning. So when I got on to O'Reilly, I was like a kid in a candy store. There are playlists. There are answers. There's on-demand training. It's worth its weight in gold, in terms of what it allows me to do.
Mark W.
Embedded Software Engineer

You might also like

Network Security, Firewalls, and VPNs

Network Security, Firewalls, and VPNs

J. Michael Stewart
Firewall Fundamentals

Firewall Fundamentals

Wes Noonan, Ido Dubrawsky

Publisher Resources

ISBN: 1565928717Errata Page