password policy: account vs. password idling

Kurt Zeilenga <[email protected]>
Newsgroups gmane.ietf.ldapext
Message-ID <[email protected]>
pwdMaxIdle and pwdLastSuccess are described in terms of "account idling" not "password idling".  That is, "This attribute specifies the number of seconds an account may remain unused before it becomes locked" and "This attribute holds the timestamp of the last successful
   authentication."

As defined now, if a user has both a password and a certificate but only uses the certificate for authentication (TLS+EXTERNAL), the password remains vulnerable to attack.

Given this is the "password policy" not a more general "account policy", this specification should focus on disabling passwords when not actively used... leaving disabling of inactive accounts to a future "account policy" specification.

-- Kurt
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.