Educause Security Discussion mailing list archives

Re: Password expiration Process ?


From: "Kenneth G. Arnold" <bkarnold () CBU EDU>
Date: Fri, 7 Apr 2006 09:24:40 -0500

Our passwords expire every 120 days.  The user receives the following email
warnings
1-Between 29 and 30 days before expiration
2-Between 13 and 14 days before expiration
3-Every day starting at 7 days before expiration until the password expires.

The account expiration of the approximately 3000 accounts was initially
spread over a period of a month so that the password expirations would not
all take place on the same day.  We have no system in place to reset the
password based on answering questions only the user should know.  I
considered putting something into SCT Banner Web to allow a user to
initiate a password reset but since Banner Web will eventually be accessed
here inside a portal with Single Sign On it didn't make sense to do this
since once SSO was initiated the user would probably not remember their
Banner Web PIN.


Brother Kenneth Arnold
System Administrator
Information Technology Services
Christian Brothers University
(901) 321-4333

Current thread: