How to secure access to the Authentication Web Service
3 years ago
Originally Published: 2004-05-27
Article Number
000060360
Applies To
RSA Mobile 1.5 Authentication Server
Microsoft Windows 2000 Advanced Server SP4
Issue
How to secure access to the Authentication Web Service
Static username/password combination is the only option
Cause
The Authentication Web Service that runs on RSA Mobile for application integration is protected by a basic username/password scheme. The initial credentials are "authapicaller" and "changeit". Currently, other authentication schemes (such as LDAP user or NTLM/Active Directory user) are not supported.
Resolution
An enhancement request is being considered for future versions of RSA Mobile, where a number of alternative authenticators present in the underlying BEA WebLogic application server may be used.