|
Yeah, I realised that shortly afterwards. The value of this
approach escapes me, however :)
I don't care which day of the week I change my password on
and nor should the users IMHO.
neil
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Gil Kirkpatrick Sent: 06 June 2006 15:07 To: [email protected] Subject: RE: [ActiveDir] max password age > where else to look? Think “divisble by
7”… From:
[EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]
On Behalf Of
[EMAIL PROTECTED] I'll second guess joe -
91 stops ppl from using cyclic passwords, which use dates or quarters to
generate a password. e.g. passwordq12006, passwordq22006
etc. Hopefully joe will give
an authoritative response :) neil From:
[EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]
On Behalf Of Steve Okay. I'll ask the question that everyone else is
afraid to.... why 91 and not 90? Cheers On 5/31/06, joe <[EMAIL PROTECTED]>
wrote: :o) I can
imagine.... Something I like to
recommend to folks is to monitor password changes. Depending on how big you are
you may even want to do it daily. It is a great way to keep an eye open for
various issues. For instance if passwords aren't being changed in the normal
periods at the normal rates, your policy may not be working. If more than usual
are being changed then possibly you have some DC issues. You will even be able
to graph out the password changes and possibly find interesting trends. Oh
to go along with this, I recommend a password age of 91 days for the obvious
reasons... Actually I always recommend that over 90 days.
joe From: [EMAIL PROTECTED] [mailto:
[EMAIL PROTECTED]] On
Behalf Of Douglas W Stelley Subject: RE:
[ActiveDir] max password age > where else to
look?
From: [EMAIL PROTECTED] [mailto:
[EMAIL PROTECTED]] On
Behalf Of Al Mulnick you echo the intMaxPwdAge value? I'm wondering if you're
not pulling back the max password age value correctly either through a
misspelling or some other error prevents you from getting the value.
Having used that method before, I can tell you it does work in a Windows
2000 environment and a Windows 2003 environment. Native, DFL, etc.
PLEASE READ: The information
contained in this email is confidential and intended for the named recipient(s)
only. If you are not an intended recipient of this email please
notify the sender immediately and delete your
copy from your system. You must not
copy, distribute or take any further action in reliance on it. Email is
not a secure method of communication and Nomura International plc ('NIplc')
will not, to the extent permitted by law, accept responsibility or liability
for (a) the accuracy or completeness of, or (b) the presence of any virus,
worm or similar malicious or disabling code in, this message or any
attachment(s) to it. If verification of this email is sought then please request
a hard copy. Unless otherwise stated this email: (1) is not, and should
not be treated or relied upon as, investment research; (2) contains
views or opinions that are solely those of the author and do not necessarily
represent those of NIplc; (3) is intended for informational purposes only and
is not a recommendation, solicitation or offer to buy or sell securities or
related financial instruments. NIplc does not provide investment services
to private customers. Authorised and regulated by the Financial Services
Authority. Registered in no. 1550505 VAT No. 447 2492 35.
Registered Office: 1 PLEASE READ: The information contained in this email is confidential and
intended for the named recipient(s) only. If you are not an intended
recipient of this email please notify the sender immediately and delete your
copy from your system. You must not copy, distribute or take any further
action in reliance on it. Email is not a secure method of communication and
Nomura International plc ('NIplc') will not, to the extent permitted by law,
accept responsibility or liability for (a) the accuracy or completeness of,
or (b) the presence of any virus, worm or similar malicious or disabling
code in, this message or any attachment(s) to it. If verification of this
email is sought then please request a hard copy. Unless otherwise stated
this email: (1) is not, and should not be treated or relied upon as,
investment research; (2) contains views or opinions that are solely those of
the author and do not necessarily represent those of NIplc; (3) is intended
for informational purposes only and is not a recommendation, solicitation or
offer to buy or sell securities or related financial instruments. NIplc
does not provide investment services to private customers. Authorised and
regulated by the Financial Services Authority. Registered in England
no. 1550505 VAT No. 447 2492 35. Registered Office: 1 St Martin's-le-Grand,
London, EC1A 4NP. A member of the Nomura group of companies.
|
- RE: [ActiveDir] max password age > where else to look? Gil Kirkpatrick
- RE: [ActiveDir] max password age > where else to l... neil.ruston
