Denying users to login based on pattern in multiple auth flows

Simon Lundström simlu at su.se
Thu Feb 4 08:21:19 EST 2016


On Mon, 2016-02-01 at 14:17:22 +0000, Cantor, Scott wrote:
> > In Kerberos you can, and AFAIK are encouraged, to use different accounts
> > (in reality passwords) for different roles/tasks to seperate them.
> 
> It's pointless when the same person knows all the passwords anyway, and inevitably sets them to the same thing, or something very close.

Well, just to be compliant eduroam passwords needs not to be the same as
our SAML federation, SWAMID in our case, passwords. In our case, eduroam
passwords are generated too.

Some passwords are protected better, like kadmin passwords, and some
passwords are stored insecurely, like in a phone or a plain file on
disk.

> This is one of those bad ideas managers push.

Or security people >; P

BR,
- Simon


More information about the users mailing list