Skip to main content
U.S. Department of Energy
Office of Scientific and Technical Information

NT Security in an Open Academic Environment

Technical Report ·
DOI:https://doi.org/10.2172/10099· OSTI ID:10099

Stanford Linear Accelerator Center (SLAC) was faced with the need to secure its PeopleSoft-Oracle business system in an academic environment that has no firewall. To provide protected access to the database servers for NT-based users all over the site while not hindering the lab's open connectivity with the Internet, we implemented a pseudo three-tier architecture for PeopleSoft with Windows Terminal Server and Citrix MetaFrame technology. The client application and Oracle database were placed behind a firewall, and access was granted via an encrypted link to a thin client. Authentication in the future will be through two-factor token cards. NT workstations in the business system unit were further secured through switched network ports and an automated installation process that included SMB signing and disabling LM Authentication in favor of NTLMv2. The hardened workstations then accessed the business system through the Citrix Secure ICA client. How these security measures affected our mixed environment (Windows9x, Samba, Transarc AFS clients, Pathworks, developers, researchers) is discussed.

Research Organization:
Stanford Linear Accelerator Center, Menlo Park, CA (US)
Sponsoring Organization:
USDOE Office of Energy Research (ER) (US)
DOE Contract Number:
AC03-76SF00515
OSTI ID:
10099
Report Number(s):
SLAC-PUB-8172
Country of Publication:
United States
Language:
English

Similar Records

Interception and modification of network authentication packets with the purpose of allowing alternative authentication modes
Patent · Tue Sep 02 00:00:00 EDT 2008 · OSTI ID:943457

LBNL SecureMessaging
Software · Sun Mar 16 19:00:00 EST 2003 · OSTI ID:code-56980

Implementing a secure client/server application
Conference · Mon Aug 01 00:00:00 EDT 1994 · OSTI ID:102395