Re: Password expiration and non-interactive access question
- From: David J Dachtera <djesys.no@xxxxxxxxxxxxxxxx>
- Date: Fri, 15 Dec 2006 20:19:29 -0600
Paul Sture wrote:
In article <45821576.DFB7A017@xxxxxxxxxxxxxxxx>,
David J Dachtera <djesys.no@xxxxxxxxxxxxxxxx> wrote:
Larry Kilgallen wrote:
In article
<OFF33EC97B.2E8142E7-ON85257243.0076DBA7-85257243.0076F2E4@xxxxxxxxx>,
norm.raphael@xxxxxxxxx writes:
Kilgallen@xxxxxxxxxxx (Larry Kilgallen) wrote on 12/13/2006 04:14:21 PM:
In article <OF49A64769.88FEB730-ON85257243.00723863-85257243.the
00728B0F@xxxxxxxxx>, norm.raphael@xxxxxxxxx writes:
I see an account with NETWORK access only allowed and a recent network
login,
but a finite passwordlifetime and a password change date in 1997, yet
Whatpassword
on the FTP transfers continues to work. Is this expected behavior?
am I
not getting?
There is no way for a NETWORK login to change the password, so there is
no occasion for LOGINOUT to force a change.
For most uses of a password (as distinguished from proxy login) in
such situations the password has been stored in a computer device so
forcing password changes does not increase security anyway.
Thanks, Larry. That makes sense and is consistent. Now I just need to
enlighten the SOX auditors....
Locking the password might reduce the chance that the SOX auditor's
tools would flag this. It might flag the locked password, but that
is typically something for which a "permitted exceptions" list is
maintained by the site.
Can you point me to the doc. where it talks about "locking a password"?
That's a
new one on me, VMS-wise.
SYSUAF> MOD username/FLAGS=LOCKPWD
LOCKPWD Prevents the user from changing the password
for the account. By default, users can change
their passwords (NOLOCKPWD).
"Prevents the user from changing the password" but not the SysAdmin. I guess
that's what threw me off.
Goofy thing is, it seems inconsistent with other IT Security axioms that require
long, goofy, mixed-case alphanumeric passwords that can't be remembered.
--
David J Dachtera
dba DJE Systems
http://www.djesys.com/
Unofficial OpenVMS Marketing Home Page
http://www.djesys.com/vms/market/
Unofficial Affordable OpenVMS Home Page:
http://www.djesys.com/vms/soho/
Unofficial OpenVMS-IA32 Home Page:
http://www.djesys.com/vms/ia32/
Unofficial OpenVMS Hobbyist Support Page:
http://www.djesys.com/vms/support/
.
- Follow-Ups:
- Re: Password expiration and non-interactive access question
- From: Larry Kilgallen
- Re: Password expiration and non-interactive access question
- References:
- Re: Password expiration and non-interactive access question
- From: norm . raphael
- Re: Password expiration and non-interactive access question
- From: Larry Kilgallen
- Re: Password expiration and non-interactive access question
- From: David J Dachtera
- Re: Password expiration and non-interactive access question
- From: Paul Sture
- Re: Password expiration and non-interactive access question
- Prev by Date: Re: Run image from sumitted batch procedure
- Next by Date: Re: thank you
- Previous by thread: Re: Password expiration and non-interactive access question
- Next by thread: Re: Password expiration and non-interactive access question
- Index(es):
Relevant Pages
|