StoneGate Authentication Server
| The StoneGate Authentication Server is an optional feature of the StoneGate Management Center
offering strong and innovative authentication methods for the enterprise. Designed with usability
and ergonomics in mind, it is completely integrated in the StoneGate Management Center for rapid
deployment and implementation. It includes four Radius-based authentication methods that are based
on username/password pairs or on software tokens/one-time passwords for stronger
authentication. |
|
High Availability
It is also possible to implement optional high availability with rapid graphical
configuration, to form a mirrored Authentication Server pair with information replication.
Ergonomic authentication methods
The StoneGate Authentication Server includes four strong authentication methods:

-
StoneGate Password - based on username/password pair
-
StoneGate MobileID
Synchronized - dual-factor strong authentication method
based on a one-time password generated on
MobileID client token
software. To generate the OTP, the user types in the PIN.
-
StoneGate MobileID Challenge - three-factor strong
authentication method based on a one-time password generated on
MobileID client token
software. To generate the OTP, the user types in the PIN and a challenge received by the system.
-
StoneGate Mobile Text - strong authentication method where
a one-time password is sent via text message.
Identity Provider (IdP) in a Federated ID scenario
The StoneGate Authentication Server can participate in a Federated Authentication scenario as
the role of Identity Provider. Support is included for both SAML 2.0 and ADFS protocols for maximum
compatibility with different "Service Providers".
Transparent integration with existing user directories
The StoneGate Authentication Server integrates transparently with existing user directories
such as MS Active Directory or LDAP systems. Automatic user linking avoids the administrative
burden of reconfiguring existing users to enable strong authentication, configured automatically as
soon as the user tries to authenticate. A dynamic notification system updates the user with the
additional information needed (seeds, PIN) to use the new strong authentication methods.