I understand... your requirement now. Would it be nicer if you actually had the ability to control the fact that certain people can only login from certain IP addresses? That way, it will be mandatory for the person to be in your office to be able to login. Using a Dongle or RSA token can also be a good feature to have.
Of course, in some cases the Proxy server's IP address is what may be received by Mifos. Regards Gurpreet On 6 November 2013 12:45, AMIT JAIN <[email protected]> wrote: > Hello Gurpreet, > Happy Diwali, > We are using a cloud for Mifos. Most of the staff is under graduate you > can not stop them by telling the policy of every thing. > There is a possibility of data sharing with any other MFI. > If any utility is there who blocks or enable the staff login on daily > basis after the confirmation of his attendance. > Any staff who is absent for the day also his login will be disable. > > It is very easy to use feature like one checks and process further. > Many more security features we may add like a dongle login for future. > > Also we are missing the word "Login Authentication". > > Regards > AMIT > > > > On Wed, Nov 6, 2013 at 12:29 PM, Gurpreet Luthra <[email protected] > > wrote: > >> Most of the requirements mentioned seem good. Should be doable for >> MifosX. Please note that asking people to change password every month or >> too frequently can lead to people creating very simple password or using a >> predictable pattern based on current month/year/etc -- which might pass >> complexity check, but can still be predicted. For instance: >> "M0han#2013Nov", next one being "M0han#2014Feb" and so on... . Read this >> discussion to understand the pros and cons of too frequent password >> changes: >> >> http://security.stackexchange.com/questions/4704/how-does-changing-your-password-every-90-days-increase-security >> >> Amit: What do you mean by "Also a feature that enables the branch's all >> login after an attendance done." ? >> >> Regards >> Gurpreet >> >> >> >> On 6 November 2013 12:19, George Lteif <[email protected]>wrote: >> >>> Hello All >>> >>> >>> >>> We had over the years lots of problems concerning mifos security >>> policies, varying from password sharing to using really simple passwords by >>> our staff. >>> >>> >>> >>> To share some of the policies we applied using Mifos 2.6 >>> >>> 1-Password expiry date (2 months) >>> >>> 2-Password complexity (special characters, caps, digits) >>> >>> 3-Password history (cannot use the same last 3 passwords) >>> >>> 4-Password Length (minimum 8 characters) >>> >>> 5-Session timeout currently is 30 minutes >>> >>> >>> >>> Some additional improvements that can also address this section in Mifos >>> X would be >>> >>> -Password reset option (could be linked to an email/email server that a >>> user can use to reset the password) >>> >>> -Password reset secret question maybe? >>> >>> -Account lockout alert sent to the admin .. >>> >>> >>> >>> >>> >>> >>> >>> >>> >>> >>> >>> *George Lteif* >>> >>> *IT Manager* >>> >>> >>> >>> >>> *The Lebanese Association For Development * >>> >>> *"Al Majmoua"* >>> >>> Beirut , Lebanon >>> >>> Phone : 961-1-369269 >>> >>> FAX : 961-1-369269 >>> >>> Pobox : 11-3483 Beirut-Lebanon >>> >>> www.almajmoua.org >>> >>> [image: anglais logo1] >>> >>> >>> >>> *From:* Ed Cable [mailto:[email protected]] >>> *Sent:* Tuesday, November 05, 2013 7:55 PM >>> *To:* A good place to start for users or folks new to Mifos.; >>> Developer; Praveen Kumar H.I.; George Lteif; Arun >>> *Subject:* Fwd: [Mifos-developer] Password Policy Rules in MifosX? >>> >>> >>> >>> Cross-posting this to mifos-users list as there should be good input >>> from users on that list. >>> >>> On Monday, November 4, 2013 11:52:12 PM UTC-8, Gurpreet Luthra wrote: >>> >>> Hello All, >>> >>> >>> >>> Seems like users of MifosX would like some basic password checking and >>> policy to be applied -- like strength of password, min length, expiration. >>> The following JIRA issue mentions the details: >>> >>> >>> >>> https://mifosforge.jira.com/browse/MIFOSX-751 >>> >>> >>> >>> Can you please give your inputs, if there are some policies being used >>> in your organization that must be met by MifosX? >>> >>> >>> >>> Also -- if a user does not perform any activity after login for say 15 >>> minutes -- then should MifosX automatically logout the user due to >>> inactivity? Is 15 minutes too less or works fine? What would you prefer? >>> >>> >>> Regards >>> >>> Gurpreet >>> >>> >>> >>> >>> >>> <https://www.facebook.com/almajmoua><http://www.linkedin.com/company/al-majmoua---the-lebanese-association-for-development><http://www.youtube.com/user/Almajmoua> >>> *Save the environment, Do not print this message unless necessary* >>> >>> >>> ------------------------------------------------------------------------------ >>> November Webinars for C, C++, Fortran Developers >>> Accelerate application performance with scalable programming models. >>> Explore >>> techniques for threading, error checking, porting, and tuning. Get the >>> most >>> from the latest Intel processors and coprocessors. See abstracts and >>> register >>> >>> http://pubads.g.doubleclick.net/gampad/clk?id=60136231&iu=/4140/ostg.clktrk >>> Mifos-developer mailing list >>> [email protected] >>> Unsubscribe or change settings at: >>> https://lists.sourceforge.net/lists/listinfo/mifos-developer >>> >> >> >> >> ------------------------------------------------------------------------------ >> November Webinars for C, C++, Fortran Developers >> Accelerate application performance with scalable programming models. >> Explore >> techniques for threading, error checking, porting, and tuning. Get the >> most >> from the latest Intel processors and coprocessors. See abstracts and >> register >> >> http://pubads.g.doubleclick.net/gampad/clk?id=60136231&iu=/4140/ostg.clktrk >> _______________________________________________ >> Mifos-users mailing list >> [email protected] >> https://lists.sourceforge.net/lists/listinfo/mifos-users >> >> > > > -- > AMIT JAIN | E.D | Digamber Finance (Chota Loan Bade Sapne) | +919414041821| > > > ------------------------------------------------------------------------------ > November Webinars for C, C++, Fortran Developers > Accelerate application performance with scalable programming models. > Explore > techniques for threading, error checking, porting, and tuning. Get the most > from the latest Intel processors and coprocessors. See abstracts and > register > http://pubads.g.doubleclick.net/gampad/clk?id=60136231&iu=/4140/ostg.clktrk > _______________________________________________ > Mifos-users mailing list > [email protected] > https://lists.sourceforge.net/lists/listinfo/mifos-users > >
<<image003.jpg>>
<<image001.png>>
<<image004.png>>
<<image/jpeg>>
<<image/png>>
<<image/png>>
------------------------------------------------------------------------------ November Webinars for C, C++, Fortran Developers Accelerate application performance with scalable programming models. Explore techniques for threading, error checking, porting, and tuning. Get the most from the latest Intel processors and coprocessors. See abstracts and register http://pubads.g.doubleclick.net/gampad/clk?id=60136231&iu=/4140/ostg.clktrk
_______________________________________________ Mifos-users mailing list [email protected] https://lists.sourceforge.net/lists/listinfo/mifos-users
