CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. Come to CPUG CON 2008 EUROPE in Switzerland on September 8th - 9th!
    Two days full of technical content for Check Point administrators in the beautiful Swiss Alps!
    We already have sign-ups from twelve different countries!
2. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 7/14, 8/25, 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
3. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
4. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Check Point Firewall-1/VPN-1 And Related Products > Authentication
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2005-08-14
BarryStiefel BarryStiefel is offline
Administrator
 
Join Date: 2005-08-11
Location: San Francisco, CA
Posts: 539
Rep Power: 10
BarryStiefel has disabled reputation
Default Running out of S/Keys?

Running out of S/Keys?

When a user has less than 10 S/Key passwords left, FireWall-1 will prompt the user to create a new S/Key chain. The user will need to specify a different "seed" value (the default seed is the username), a new chain length to FireWall-1, and the last "password" in the chain.



On a Unix machine, I would generate the new key chain as follows (assuming I want to use "seed" as my new seed value and 1000 as my chain length): ~ $ key 1000 seed Reminder - Do not use this program while logged in via telnet or rlogin. Enter secret password: [Secret Key] JOG WAKE SUN MEND ILL COWLAfter I've done this, I can input this information into my telnet/client auth session as follows:

Check Point FireWall-1 authenticated Telnet server running on kenny User: phoneboy SKEY CHALLENGE: 9 phoneboy. Enter SKEY string: MUG EMMA PI PRY HOYT MANN User phoneboy authenticated by S/Key system You have only 8 one-time passwords left. A new S/Key chain should be created. If you have a new chain, you can enter it now by typing the chain length and the last password in the chain. Enter New Chain (y/n) ? y Enter S/Key chain length: 1000 Enter the last string of the new chain: JOG WAKE SUN MEND ILL COWL New S/Key chain accepted Connected to kyleNote: I entered the password I generated above when it asked me for the "last string". It is only used to initialize the S/Key chain. Future passwords will decrement from there. Also,



FireWall-1 will always prompt you to use the "old" seed value and not the new one. You will need to remember to use the new seed value when using an S/Key generator or generating your own list.

-- PhoneBoy - 30 Dec 2003

FAQForm FAQs.Class: OperatingSystem?: FAQs.Version:
Reply With Quote
  #2 (permalink)  
Old 2005-12-05
larstr larstr is offline
Junior Member
 
Join Date: 2005-12-01
Posts: 9
Rep Power: 0
larstr has an average reputation (10+)
Default Re: Running out of S/Keys?

Keep in mind that S/Key is no longer supported. I believe support for it were abonded in NG FP4.
Reply With Quote
  #3 (permalink)  
Old 2006-05-09
bar004 bar004 is offline
Junior Member
 
Join Date: 2006-05-09
Posts: 1
Rep Power: 0
bar004 has an average reputation (10+)
Default Re: Running out of S/Keys?

Hi All,

I'm a new member in this Forum so hello to everyone.

I'm also getting this kind of massage when i'm getting to the last 10 passwords.(s/key)

Does anyone know if I can change a definitions in my FW or in the secure client so I won't get this massages and keep the authentication process smooth ?

I'm working with a third part Gina and I my system can't deal with this massages for now on.

I'll be very happy for a solution for this problem if anyone is still working with s/key or remember how it was like in "those early days".

Regards,

Asaf Rosenheck
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 20:09.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0