From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Kevin Gillis
Sent: Thursday, December 08, 2005 5:48 PM
To: [email protected]; [EMAIL PROTECTED]
Cc: Tripp Allen
Subject: RE: [WS_FTP Forum] User password security
-----Original Message-----
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]On Behalf Of Schuessler, Doug
Sent: Thursday, December 08, 2005 5:19 PM
To: [EMAIL PROTECTED]
Cc: WS_FTP Pro forum LISTSERV
Subject: [WS_FTP Forum] User password securityWe have been using FTP server with NT user database and only allowing users to change password by calling me to change them. The NT database was used to enforce our password content/complexity requirements (minimum 6 characters, containing at least one each of uppercase, lowercase and a number or special character), since this is not available when using Ws-FTP server to maintain the accounts. With our latest security audit, we are now required to expire the passwords every ninety days. This new requirement would mean manual password changes by me are no longer a workable process. With the loss of control of passwords, we also would then need a way to replicate the passwords to another system for disaster recovery purposes. I am looking for suggestions on how to support this new requirement.
<<[EMAIL PROTECTED]>>
