Lab Notes
Musings on Wi-Fi security issues, our product plans, and the general state of the world. Follow up with your comments and complaints to Lab Notes's .
Elektron 1.1b2
- Remote Administration The Elektron Settings application now supports connecting to the Elektron server over the LAN, rather than being restricted to running on the same machine as the server. This means that you can stick your server in a closet and administer it from your desktop — no more need to be sitting at the server or using something like VNC to configure it. To keep things secure, the connection between the server and the Elektron Settings application is encrypted using SSL.
- Session Timeouts You can now configure the length of time that a user may be logged into the network. Enabling this feature sends a RADIUS "Session-Timeout", requiring the client to re-authenticate after a fixed period of time. This increases security by forcing the per-client encryption keys to be regenerated at regular intervals. One caveat: this feature requires that your access points support the Session-Timeout attribute, and not all do. If your access points do not, then it will simply be ignored.
- MAC Address Authentication Since first releasing Elektron eight weeks ago, we've been surprised by the number of requests we are receiving for this feature. It's a simple (but not very secure) method of limiting access to the wireless network based on the MAC address of the client's Wi-Fi card. For organizations that need some form of control over who accesses their network, but can't upgrade their users to recent WPA Enterprise capable equipment (K-12, you know who I'm talking about!), this feature will keep out casual users. It does not provide encryption, and it is easy to spoof for anybody with even a small amount of technical expertise, so we don't recommend its use unless you absolutely cannot deploy WPA Enterprise.
- Command Line Account Configuration Elektron now includes a command line tool for adding and removing Elektron user accounts, and for changing the passwords on those accounts. This allows you to script the account management process, and even create different front-ends for it. For instance, the Elektron manual includes an example CGI demonstrating a web page that allows a user to change their Elektron account password.
- LEAP Support In addition to PEAP and TTLS, Elektron now supports LEAP for authentication. There is some older equipment out there that only supports LEAP, and now you can authenticate this equipment using Elektron.
Search
Recent Entries
Mac OS X 10.5.1
Elektron and Leopard
Elektron 2.0.1755
AirPort Base Station Update 2007-002
AirPort Extreme Update 2007-004
New Elektron Release: 2.0.1744
PARC: Wi-Fi PKI Usability Stinks
A Real iPhone Exploit?
Duke: iPhones Don't Actually Attack
When iPhones Attack
Monthly Archives
November 2007 (1)
October 2007 (1)
September 2007 (1)
August 2007 (1)
July 2007 (8)
June 2007 (16)
November 2005 (8)
October 2005 (13)
September 2005 (22)
August 2005 (23)
July 2005 (21)
June 2005 (26)
May 2005 (23)
April 2005 (23)
March 2005 (25)
February 2005 (23)
January 2005 (29)
December 2004 (32)
November 2004 (32)
Subscribe to Lab Notes
Elektron® is a registered trademark of Periodik Labs LLC