Re: password policy: multiple subentries, multiple password attributes, ....
Michael Ströder <[email protected]>
| Newsgroups | gmane.ietf.ldapext |
|---|---|
| Message-ID | <[email protected]> |
simo wrote: > Ack, having multiple password policies apply for different attributes > looks simply as an admin nightmare. Password policies tend to be few and > well defined as they are considered critical for the security of the > password. That means that usually it is quite easy to correctly define > all policies for all attributes for a specific subset of users. > Defining them as an intersection of multiple policies seem like a > feature I wouldn't want if I were an administrator. Looks powerful on > paper but also potentially complicated and complex is usually an enemy > of secure. Full ack! Ciao, Michael.