To enhance the security of PAP, CHAP, and
•Callback system (supported PPP callback protocols: IETF type 0 [RFC 1570] and the Microsoft callback protocol)
•Centralized security (authentication server configured based on RADIUS [RFC 2138] and TACACS [RFC 1492])
•Multiple Passwords and
•
10.5 SSL and TLS
The Nokia 9290 Communicator supports the SSLv3 (Secure Socket Layer) and TLSv1 (Transport Layer Security) protocols. These protocols are integrated in the socket interface, so
10.5.1 Web browser
Web URLs (addresses) that start with “https” are
The encryption strength depends on the SSL server. The Nokia 9290 Communicator supports strong 128 bit encryption in SSL and TLS, but can downgrade its security to a lower level if the server is not capable of handling such strong encryption.
The authenticity of the Web server is determined by the help of certificates in the Certificate management tool. As discussed above in the software security chapter, the user can select which certificates are trusted and which are not. When connecting to a server, whose identity is certified by a trusted party, there will be no warning note. Other- wise, the user will be able to review the identification offered by the remote server. Some certification authority root certificates are
The HTTP (Hypertext Transfer Protocol) also provides a simple authentication protocol, which uses a username/ password pair. It can be used to authenticate the user to a remote server. This method can be used over the SSL for additional security.
10.5.2 Reading and sending mail
Access to remote mailboxes (IMAP and POP) and sending mail (SMTP) can also be secured using the SSL/TLS. You can request a secure connection by ticking the appropriate box in the settings.
In order to use secure connections with electronic mail, the mail server has to support the “starttls” command (IMAP, SMTP) or the “stls” command (POP).
Note: Sending electronic mail over a secure connection does not encrypt the mail itself, only the connection to the mail server. After the mail continues to its destination from the first mail server, it is not encrypted. This feature is most useful when accessing mail servers in a secure intranet through a public Internet service provider.
10.5.3 Supported encryption algorithms
The selection of algorithms depends on the protocol being used. It is advisable to avoid the use of
•For server authentication and/or key exchange: RSA, DSA, and
•For data encryption: RC4™ (plus the “export” version with 40 secret bits), DES, and
10.6 WAP security
When using WAP for a data call, the
WAP uses an optional security layer called WTLS. This can be turned on in the settings, or the server can mandate it. WTLS security ends at the WAP gateway. Connections to the target server from the WAP gateway might not be encrypted.
WAP Forum specifies WTLS. The Nokia 9290 Communicator supports strong 128 bit encryption in WTLS, but is able to lower the security level if required by the server. The Nokia 9290 Communicator supports server authentication and key exchange using the RSA algorithm and data encryption using the RC5™ algorithm. The gateway is authenticated using certificates. Some certification authority root certifi- cates are
35