Looking for a centralized password setup for UNIX and Linux



Hi everybody,

I wanted to get everybody's feedback regarding centralized password
management. Our environment has grown from a few admins to many. We
have gone from a Solaris shop to one that includes lots of Solaris and
Linux. We were using manual password changes per box, then moved to
shell scripting. However we have outgrown this as our passwords are
now often out of sync, as different admins are changing passwords at
different times, and new servers are being added frequently, and are
in different stages of development, etc. On top of this is meeting
Sarbanes-Oxley rules

We are looking at a centralized tool that is straightforward to
update, that can push out passwords across all the environments.

Some suggestions so far have been: LDAP, NIS, Kerberos, and Active
Directory plugins (not really liking the AD suggestion)

Concerns:

1) We don't want to get in a situation where if the password
management server has become unavailable, users are not able to login.

2) We want something that's straight forward to update and isn't
married to one particular admin's knowledge of language (like Perl,
etc).

Thanks for anybody's feedback

.



Relevant Pages

  • Re: WAS z/OS and 64 bit (was Re: WebSphere/HATS Odyssey)
    ... I've been very frustrated with this migration. ... stuff but this will go away soon and throw in a Domino Change Management ... control, deployment servant, application control, application servant. ... test for our Call Center/HATS environment I'm up to 34 tasks. ...
    (bit.listserv.ibm-main)
  • Re: How long does it take to become a good sysadmin?
    ... > software environment that I still don't understand very well. ... There are admins who really are just operators.) ... lotsa free beers after work. ... Lucky, lucky you. ...
    (comp.unix.admin)
  • Re: "Yet Another Florida Gun Friendly Law"
    ... # coercive nature of the work environment. ... The proper role of management is ... But even in the US -- workers are subject to a whole number of arbitrary ... about private property provoked some more thought. ...
    (rec.guns)
  • Re: How to stop Admins from sniffing ?
    ... Are the Sys and Net admins sanctioned by the management ... Also, by encrypting your traffic, and knowing your sys/net admins are ... isn't our place to circumvent whatever computer system policies ...
    (Security-Basics)
  • Re: Scored a win today
    ... > What's funny is the Windows-centric way with which IT and management ... because they're already running a "mixed" environment, ... them how many "flavors" of Windows point out that they're running. ... using mainframes and the box was from IBM. ...
    (comp.sys.mac.advocacy)