Educause Security Discussion mailing list archives

Re: Self Service Password Reset


From: Cal Frye <cjf () CALFRYE COM>
Date: Wed, 4 Feb 2009 14:00:48 -0500

Andrea,
How many systems are using this same password, and is there a single directory?

For new students, for example, we set their eDirectory password, which permits them to log
into a lab workstation if needed, but not into their email. When they go to the
self-service site, the password is updated in both systems and then they're good to
continue on their way.

Are students' own computers forced to join your domain to obtain access to the
self-service web page? Can't that be made available to all?

As much as possible you want to force users to register their profile. Otherwise your Help
Desk gains little from the exercise.

Not sure of your second question. We have the same registration for all, and passwords
expire every 122 days, or approximately once a semester.

Di Fabio, Andrea wrote:
Experts,

I am seeking your feedback on how to implement Self Serice Password Reset.
We have just finished the development and testing of a in house, web based
password reset program.  We are now looking at how to deploy it and are
seeking feedback from institutions that already have experience with it.

Here some of the questions that we discussed and to which we are seeking
feedback.

1. Do we want to force users to register their profile and if so, what is
the best approach for doing so?
2. Is the forced registration different for existing and new faculty?  Is it
different for existing and new students?
3. Should we force our new accounts to go through a registration workflow
that includes creating the profile?  Should we do the same for existing
accounts?

One of the most discussed topic, was the "How is someone going to use the
self service password reset if they can't even logon to a PC to begin with?"
We do not have MS programmers capable of rewriting the GINA and personally I
would not feel comfortable pushing an in-house built GINA campus-wide.  Some
of the suggestions ranged from creating a guest account, using kiosks, using
your neighbor's PC, dedicating some PC in the labs to calling the helpdesk
as the last resort.

Any thoughts, ideas, comments, suggestions?

Thanks.




--
Celebrating the 200th anniversary of Darwin's birth,
and the 150th anniversary of the publication of the Origin of Species.
-- Cal Frye, Network Administrator, Oberlin College
   Mudd Library, x.56930 -- CIT will NEVER ask you for your password!

   www.calfrye.com,  www.pitalabs.com

"The problem with the world is that everyone is a few drinks behind." --Humphrey Bogart.

Current thread: