[Date Prev][Date Next] [Chronological] [Thread] [Top]

Re: [ldapext] password policy: multiple subentries, multiple password attributes, ....

simo wrote:
> Ack, having multiple password policies apply for different attributes
> looks simply as an admin nightmare. Password policies tend to be few and
> well defined as they are considered critical for the security of the
> password. That means that usually it is quite easy to correctly define
> all policies for all attributes for a specific subset of users.
> Defining them as an intersection of multiple policies seem like a
> feature I wouldn't want if I were an administrator. Looks powerful on
> paper but also potentially complicated and complex is usually an enemy
> of secure.

Full ack!

Ciao, Michael.
Ldapext mailing list