Forum Discussion
marian_57792
Nimbostratus
May 10, 2011local password reset automation
hey guys,
let me describe our issue. we got many local accounts set to 3 month password duration. If user doesn't change pwd in advance, password will expire and doesn't allow user to change it or logon to F5. It's very time consuming to reset each expired pwd's, sent notification mail and sync active-standby LTM's every time. we cannot have remote authentication due to security reason(security officer).
How are you dealing with this kind of issue ? cron jobs, notification emails, or ?
really appreciate you answers.
Thank you
Marian
3 Replies
- Hamish
Cirrocumulus
Sorry. Only ever done individual user accounts with either TACACS or Radius...
Why does your security officer think local accounts are more secure than using a centralised auth system? Centralised means more control. Not more insecurity (Although I'm sure someone could build an insecure central system :)...
H - hoolio
Cirrostratus
But at least you'd only have one potentially insecure AAA server instead of many :)
Marian, if can you think of a way to improve this scenario (like sending email notifications from LTM when a user's password is about to expire) you could open a request for enhancement case with F5 Support to request the new functionality. But I agree with Hamish--most enterprise level customers use remote admin auth and handle the account management there.
Aaron - marian_57792
Nimbostratus
Thank you Hamish and Hoolio
Marian
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects