Re: Password History



Joe Chasan typed (on Fri, Aug 15, 2008 at 06:56:03PM -0400):
| On Fri, Aug 15, 2008 at 05:58:51PM -0400, Jean-Pierre Radley wrote:
| > Nico Kadel-Garcia typed (on Fri, Aug 15, 2008 at 10:05:19PM +0100):
| > > Joe Chasan wrote:
| > >> Any easy way to implement password history - e.g. user can't re-use last X
| > >> passwords, where X is a configurable parameter?
| > >>
| > >> After an IT audit, auditors were surprised this was not implemented in
| > >> SCO OpenServer (6.0/mp2)
| > >
| > > If you want thorough such control, upgrade to an OS smart enough to use
| > > Kerberos (which I'm not sure SCO has ever published), or use a Kerberized
| > > master password server with an NIS back end for SCO clients. Oddly,
| > > Solaris, Linux, and Active Directory from Windows can all do this. And
| > > oddly, Solaris's NIS requires real hand-massaging to prevent from causing
| > > system problems, even thogh Sun apparently invented it.
| >
| > OSR 6.0.0 includes Kerberos.
|
| then how would one implement this part of it?

Well, I never done it so I can't help you. Looks like you have (more
than enough) reading for weekends from now to Columbus Day at:

http://web.mit.edu/Kerberos/krb5-1.6/#documentation

--
JP
.



Relevant Pages

  • Re: Password History
    ... passwords, where X is a configurable parameter? ... auditors were surprised this was not implemented in ... SCO OpenServer ... All this came up via an IT audit by outside auditor Ernst & Young. ...
    (comp.unix.sco.misc)
  • Re: Password History
    ... where X is a configurable parameter? ... After an IT audit, auditors were surprised this was not implemented in ... SCO OpenServer ...
    (comp.unix.sco.misc)
  • Re: Password History
    ... where X is a configurable parameter? ... After an IT audit, auditors were surprised this was not implemented in ... SCO OpenServer ... Maybe you could appease your auditors by replacing Telnet etc with SSH using public key authentication? ...
    (comp.unix.sco.misc)
  • Password History
    ... Any easy way to implement password history - e.g. user can't re-use last X ... where X is a configurable parameter? ... After an IT audit, auditors were surprised this was not implemented in ...
    (comp.unix.sco.misc)
  • Re: Forgotten password - no OS X CD
    ... You either don't have to deal with many passwords, ... Any of those counts as lucky. ... I was once "caught" at work by some NSA security auditors who ...
    (comp.sys.mac.system)