Re: unique hardware identification



In response to "Devon H. O'Dell" <devon.odell@xxxxxxxxx>:

2006/12/19, Koen Martens <fbsd@xxxxxxxx>:
Hi All,

I was wondering, if something like a unique hardware identification
would be possible on FreeBSD.

I'd like a machine to authenticate to a server, for which it will
need a unique identification. Problem is, it should be generated
automatically and not easy to fake / detect without already having
root access to the box.

I'm thinking of something like combining serial numbers from
CPU/disks for example, but there does not seem to be a clear way to
obtain these (not all cpu's even have a serial number in there).

I am just inquiring if someone on this list has an idea that might
help with this problem.

Missed the original post on this.

Kerberos does this reliably and securely. Part of the point of Kerberos
is that machines must authenticate themselves to each other.

Another option is SSL certificates.

Although, since you don't describe the goal you're trying to accomplish,
it's difficult to know if either of those will work for you.

--
Bill Moran
Collaborative Fusion Inc.
_______________________________________________
freebsd-hackers@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-hackers
To unsubscribe, send any mail to "freebsd-hackers-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • Re: IPSec on webserver
    ... As long as server is not part of domain it won't be able to use Kerberos as ... Kerberos only works in domain. ... At the local office the intranet runs behind a public IP. ... everything is set to authenticate using kerbos. ...
    (microsoft.public.win2000.security)
  • Re: NTLM authentication
    ... I can't use kerberos because I am on a Winnt system based on NTML not ... this is a local intranet and you are only running SQL on a server which is not a Domain member and you want to authenticate windows accounts using NTLM? ...
    (microsoft.public.dotnet.languages.csharp)
  • Re: unique hardware identification
    ... if something like a unique hardware identification ... I'd like a machine to authenticate to a server, ... A lot of software we use now, accesses a license server via the network, and authenticates clients based on their MAC address,. ...
    (freebsd-questions)
  • Re: Kerberos Auth using O2k3 and E2k3 in a cluster
    ... >authenticate to our LCS and our DC using kerberos; it's just the Exchange ... They may ask the Exchange server for a GC name, ...
    (microsoft.public.exchange.connectivity)
  • Re: Kerberos Auth using O2k3 and E2k3 in a cluster
    ... >authenticate to our LCS and our DC using kerberos; it's just the Exchange ... They may ask the Exchange server for a GC name, ...
    (microsoft.public.exchange.admin)