[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

RE: [cobalt-users] Question about preventing a user of changing his password



> So whenever a client uses http://www.hisdomain.com/personal
> I don't want him to be able to change his password. How can
> I achieve this?

1. Don't give them shell access.

2. Remove their access to whatever webpage allows them to change their
password.

3. Read up on password aging, and require that individual passwords stay
around for at least five years.

4. Let one of your other machines stay up around the clock trying to
crack your own users' passwords anyway.

--
Rodolfo J. Paiz
rpaiz@xxxxxxxxxxxxxx <mailto:rpaiz@xxxxxxxxxxxxxx>