Denying users to login based on pattern in multiple auth flows

Cantor, Scott cantor.2 at osu.edu
Mon Feb 1 09:17:22 EST 2016


> In Kerberos you can, and AFAIK are encouraged, to use different accounts
> (in reality passwords) for different roles/tasks to seperate them.

I wouldn't agree that anything should be encouraging that. It's pointless when the same person knows all the passwords anyway, and inevitably sets them to the same thing, or something very close. This is one of those bad ideas managers push.

-- Scott



More information about the users mailing list