Tanapro taRadiusSrv 2.5

(Für deutsche Fassung hier klicken)

This is the product description of Tanapro taRadiusSrv. The technical documentation can be found here.

Tanapro taRadiusSrv is a copyrighted RADIUS server of Tanapro GmbH (www.tanapro.ch) that provides strong authentication for user logins (VPN, RAS, etc.). It is a secure, inexpensive, software-only solution that does not need any additional HW/SW tokens.

The software is multi-lingual and delivered in english and german. You can easily translate the texts in the language files and have them installed by the system administrator.

taRadiusSrv is written in Eve (www.ewesoft.com) and uses the freely available Eve VM (version 1.50 or higher).

Features

Strong authentication

What is strong authentication and why do we need it?

Strong authentication means identifying a user by a method that is more secure than just login-name and password. This is especially needed when logging-in via the Internet where there are no other identifying criterias like the calling-station-id (the phone number from where the user is connecting).

With only login-name/password, a user is poorly identified and hackers could guess or even know the login credentials. By using a second authentication factor (two factor security) this security threat is eliminated or at least extremely reduced.

Security details

The login procedure with sending a one-time password runs as follows:
  1. The user logs in with his password, that is stored in the server's database.
  2. If the password is correct, the server creates a one-time token and sends it to the user. The system's administrator can configure up to 3 methods for sending the token. The easiest way is by email to a web-based mail account. If there is a SMS gateway, the token could be sent to the user's mobile phone.
  3. The user logs in again, this time with password+token. If password and token are correct, the user is allowed to login.

The secure login procedure is much easier when using TOTP:

  1. The user gets his one-time token from an app (e.g. Google Authenticator or FreeOTP) or from a hardware TOTP device (e.g. Token2)
  2. The user logs in with password+token. If password and token are correct, the user is allowed to login.
Security features:

Costs

The whole solution is not costly for the following reasons:

Free License

The Software is delivered with a free license which allows you to test the Software in your own environment. Because this license does not support strong authentication, we highly recommend that you buy a PRO license for production use!
The free license has following restrictions: