tgreene
Executive Editor

Vendors work toward single sign-on for remote access

Opinion
Sep 2, 20032 mins

* Aventail, others extending single sign-on to remote-access users

Single sign-on for remote-access users is consider a good thing because it simplifies things for the remote user, who has less to remember, and for the network administrator, who has fewer passwords to worry about.

Secure Sockets Layer remote-access vendors are starting to address this, making it possible to sign on to an SSL proxy server and have the server sign on to individual applications the remote user seeks. The caveat in many cases is that the sign-on for the proxy must be the same as the sign-on for the host application.

The mechanism is for the proxy server to remember the name and password and apply it when the application server seeks it.

Aventail this week is announcing an alliance with three other vendors – Imprivita, Netegrity and RSA Security – to push this a little further. Each has products to manage user identities, and by assuring interoperability with Aventail gear, this technology, including single sign-on, can be extended to Aventail customers.

In addition to making things more convenient for end users, such technology allows for fewer errors. If users aren’t called on to remember multiple names and passwords, the more likely it is that they will accurately remember the ones they do have. This should result in fewer calls for help that tie up help desks and lead to loss of productivity while remote users wait to log in properly.

According to a Gartner study cited by Aventail, a quarter of help-desk calls are about passwords, and single sign-on could get rid of as much as 85% of those calls. Even if the number isn’t that striking, any steps to reduce the load should be welcome.

Potential customers interested in SSL VPNs should ask about this feature when they are evaluating vendors. While it is not a make-or-break decision, it is a convenience that, all other things being equal, it is better to have than not to have.