Products

Salt RADIUS+


Salt RADIUS+ is a standalone and scalable out-of-thebox RADIUS compliant server enabling enterprises to leverage their existing directory to secure remote network access using strong two-factor authentication via Salt mCodeXpress mobile tokens or SMS OTP (one time password) as the remote user's credential.



Salt RADIUS+ is positioned as a cost effective user authentication solution for Virtual Private Networks; Citrix Application Delivery and other RADIUS aware applications.

Key Benefits

  • Salt RADIUS+ is designed for rapid deployment as an appliance making it ideal for SMEs and others seeking low complexity but high trust solutions to their user authentication needs. Salt RADIUS+ is configured via onboard web pages with template configurations also provided for leading VPN and gateway services.
  • Salt RADIUS+ is able to directly leverage common user stores such as Active Directory for retrieval of user's token identifiers to be used within the Salt RADIUS+ server.

User Store

In a typical deployment, Salt RADIUS+ connects to a User Store to validate userid|password credentials and retrieve user mobile numbers. Salt RADIUS+ will work with any LDAP or JDBC User Store, including: Active Directory, MS SQL Server, Oracle, Novell Directory Server, Novell eDirectory, and IBM Tivoli Directory Server.

Alternatively, Salt RADIUS+ can store and manage user information locally if the deployment environment does not have an appropriate User Store.

Simplified mCodeXpress Provisioning and Registration

Salt RADIUS+ supports two simple registration and provisioning models for mCodeXpress.

User self service whereby a user who is already authenticated to a LAN accesses LAN based web registration pages which lead the user through:

  • Download of a generic mCodeXpress application to the user's handset.
  • Initiation of the application on the handset which requests the user to select a PIN and then generates a 128-bit AES key, and displays a 16-digit alphanumeric "Registration Code".
  • The user then enters the Registration Code into the Salt RADIUS+ self-service User Registration pages.

For remote users with traditional userid|password access to a VPN seeking to upgrade to higher assurance levels, the same procedure can be followed with the final activation of the mCodeXpress token completed by an Administrator after validation (by phone or email with the user) that the deployment is in fact to the identified user's handset.

Salt SMS OTP Registration

Registration for SMS OTP service is through inclusion of the user's mobile handset within the external or local user store as appropriate, and activation of the user for SMS OTP validation.

As for mCodeXpress, this can be completed via Salt RADIUS+ web based registration pages by the user or the Administrator.

RADIUS Profile Support

  • Password Authentication Protocol (PAP)
  • Challenge-Handshaking Authentication Protocol (CHAP)*

* Not supported with LDAP User Stores

Compliance & Interoperability Testing

  • AT&T Global Network Service
  • CheckPoint Firewall-1
  • Citrix XenApp 5.0

Platform Support

  • Any J2EE container supporting JRE 1.5 and JSP 2.1; such as Apache Tomcat, Glassfish, Oracle WebLogic, IBM WebSphere, JBoss
  • VMware Virtualization
  • Sun VirtualBox
  • Ubuntu Linux Distribution