Have configured my Windows domain to use Ubikey for Windows log on authentication. Sophos UTM supports SSO and smartcards (Yubikey) in some cases (but not all cases):
- HTTP-proxy works since the user is authenticated by Windows domain
- User portal? (Not certain if access to user portal supports SSO?)
- UTM supports OTP for some services, ie SSL VPN, where OTP can be delivered by Ubikey. But the user must also use a password, which is in my case is the users domain password
- L2TP/IPSec cannot be used with Ubikey since L2TP/IPSec VPN using smartcards is not supported by UTM (which is very sad)
This is my findings. The conclusion is that I cannot switch from passwords to smartcards for user authentication (user must use smartcard for logging in) since Sophos UTM does not support smartscards for all services. The purpose of using smartcards is that the users shall not use any password, but that is currently not possible.
Comments? Am I right?
This thread was automatically locked due to age.