cat-users AT lists.geant.org
Subject: The mailing list for users of the eduroam Configuration Assistant Tool (CAT)
List archive
- From: Philippe Taurines <Philippe.Taurines AT crous-toulouse.fr>
- To: Paul Dekkers <paul.dekkers AT surf.nl>, ALBRIZIO DANIELE <albrizio AT units.it>, "cat-users AT lists.geant.org" <cat-users AT lists.geant.org>
- Subject: RE: [[cat-users]] Eduroam : Password Update
- Date: Wed, 24 Jan 2024 16:19:39 +0000
- Accept-language: fr-FR, en-US
- Arc-authentication-results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=crous-toulouse.fr; dmarc=pass action=none header.from=crous-toulouse.fr; dkim=pass header.d=crous-toulouse.fr; arc=none
- Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=acguDPKy2ScD5xHU0oBCWWTC7Wrnu1eV/73EZM4llF0=; b=ShxlfUuyR/sieXepuj3Uepsg94EqIGsyx37lotjm+cjPeIhEo3L6ZHedv7xKHb5mmDx/srdVwLWLF/DugwH3vLVofgHRB6/J6LR4jPQNDPoSgNZNd3BmenU4aX+r64drSOJZqxEDkpXLdDxph8OIo0fi083Jw8FLuiQ3iJDoTYVokAJ0nRMw5cjrTgB3cAq4GOLR86rl9qf7qnSP7a605Zhx4aGXxDEBnmlUFG9+yLsw918136ZOYfmppcmllJGpyskjjTZ/qKBK9KFDpXlHELbRkGIBSOUAcyXkrys09dl8cF7+gL02bLZiu+eUaKDiRIfZM0lbLOB21QPu5eKKlw==
- Arc-seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=AwBCX+Cq/fT7KapvL+4TIqa/F1YZBeJ1QfnMzIe9ywXiyFhBpLlRgSv6WKC6jL4g0q4Qj3yoS/TOO22Yu87mdM2mtYzLinmk8jenlnVK3lFC3QaN3WT+2QNnX4pviAkPYhBdvFkhBgP18MUDKX7QYdzeI2naV9W8RfMfqK6x8criqv+MF7h2p6g9KVAKul9PEp+pYPWPvRWHCCcC9YlxvfLU2U0SPnKuO4xRz83Rd0V4h22TEC5meG4BUgze1a0qyfiK4ZKF4+CnWgBqRPlFDtZS2aRgHs8392o6er4/WpN79vqkU9mb1qCiOwjZ/+7ICCWPtfOn5B/l07pMkLPXaQ==
- Authentication-results: dkim=none (message not signed) header.d=none;dmarc=none action=none header.from=crous-toulouse.fr;
For my part,
The idea of integrating a lifespan for accounts with login and password could be a start. But this will not fully satisfy the need because a user can install the eduroam profile via “eduroamCat” well after updating their password. And we will still end up with locked accounts, in my opinion, the most effective solution would be for the radius server to detect the event below:
And requires password renewal on the Windows client, so that it no longer makes incorrect connection attempts leading to account locking.
PS : Regarding the NIST recommendations on password renewal policy, I share your opinion. But on condition that you have implemented MFA because otherwise the risks of brute force or dictionary attack are too great.
De : Paul Dekkers <paul.dekkers AT surf.nl>
Hi, In principle the geteduroam clients support the concept of "credential expiration". We use this in the pseudo-accounts, because the certificates have a limited lifespan. We know exactly what their lifespan is though. So after this time, we can remove the profile, and in advance we can ask the client to reconfigure. For username/passwords we don't know how long the credentials are (still) valid. Also, the feature isn't built into CAT: but we could consider it. Assuming the credentials are "at most" valid for 6 months, you could use the timer. Regards, P.S. Personally I like the new NIST advise to no longer work with password expiration I must say. I don't think it adds a lot to the security to change a password periodically, unless you're certain there was a compromise.
On 24/01/2024 14:06, Philippe Taurines (via cat-users Mailing List) wrote:
|
- [[cat-users]] Eduroam : Password Update, Philippe Taurines, 01/23/2024
- Re: [[cat-users]] Eduroam : Password Update, Tomasz Wolniewicz, 01/23/2024
- RE: [[cat-users]] Eduroam : Password Update, Philippe Taurines, 01/24/2024
- Re: [[cat-users]] Eduroam : Password Update, Tomasz Wolniewicz, 01/24/2024
- Re: [[cat-users]] Eduroam : Password Update, ALBRIZIO DANIELE, 01/24/2024
- RE: [[cat-users]] Eduroam : Password Update, Philippe Taurines, 01/24/2024
- Re: [[cat-users]] Eduroam : Password Update, Paul Dekkers, 01/24/2024
- RE: [[cat-users]] Eduroam : Password Update, Philippe Taurines, 01/24/2024
- Re: [[cat-users]] Eduroam : Password Update, Paul Dekkers, 01/24/2024
- RE: [[cat-users]] Eduroam : Password Update, Philippe Taurines, 01/24/2024
- Re: [[cat-users]] Eduroam : Password Update, Lukas Wringer, 01/24/2024
- Re: [[cat-users]] Eduroam : Password Update, Tomasz Wolniewicz, 01/24/2024
- RE: [[cat-users]] Eduroam : Password Update, Philippe Taurines, 01/24/2024
- Re: [[cat-users]] Eduroam : Password Update, Tomasz Wolniewicz, 01/23/2024
Archive powered by MHonArc 2.6.24.