Denying users to login based on pattern in multiple auth flows
Simon Lundström
simlu at su.se
Thu Feb 4 08:21:19 EST 2016
On Mon, 2016-02-01 at 14:17:22 +0000, Cantor, Scott wrote:
> > In Kerberos you can, and AFAIK are encouraged, to use different accounts
> > (in reality passwords) for different roles/tasks to seperate them.
>
> It's pointless when the same person knows all the passwords anyway, and inevitably sets them to the same thing, or something very close.
Well, just to be compliant eduroam passwords needs not to be the same as
our SAML federation, SWAMID in our case, passwords. In our case, eduroam
passwords are generated too.
Some passwords are protected better, like kadmin passwords, and some
passwords are stored insecurely, like in a phone or a plain file on
disk.
> This is one of those bad ideas managers push.
Or security people >; P
BR,
- Simon
More information about the users
mailing list