* Cisco says it is not open sourcing CTA
endif; ?>Cisco says it won’t make it’s NAC client software open source, and plans to keep making the software for the foreseeable future.
The company made this declaration to correct what the CTO of its security technology group said a few weeks ago – that Cisco planned to release the software to the open source community. Cisco says it is not open sourcing Cisco Trust Agent (CTA).
Cisco defines CTA like this: client software that must be installed on hosts whose policy requires validation prior to permitting network access.
CTA checks out the machine it’s installed on and reports back to policy engines about the security posture of the machine. Depending on the report and the policies, the machine is granted appropriate access or denied.
While it is possible to perform endpoint checks using temporary software agents or no agents at all, the full-client approach, which includes CTA, is necessary to give the most comprehensive scan of end devices.
The trouble is that it represents one more piece of software that has to be installed and maintained on corporate computers. So it would be nice if it could work in other scenarios – such as endpoint checking for VPN access – to make the installation and maintenance worthwhile.
The Microsoft approach – making such an agent part of the Vista operating system so it is installed on all machines and maintained as a matter of course – is therefore attractive.
The upside for customers of Cisco’s CTA being made open source is not so clear. It would be free and other vendors could use it with their products, but it would still require installation and maintenance.
The benefits here are clearly for Cisco, which can perhaps enhance it to support features unique to Cisco’s NAC architecture.




