RE: Passwords

From: Mark Medici (mark@dbma.com)
Date: 10/31/01


Subject: RE: Passwords
Date: Tue, 30 Oct 2001 19:19:47 -0500
Message-ID: <0393D629EEDEC246956A0F2CEBF8F83B01A3FD@njmail1.dbma.com>
From: "Mark Medici" <mark@dbma.com>
To: "Taylor, Gord" <GORD.TAYLOR@royalbank.com>, "Keith Maxon" <KMaxon@Pulte.com>, "focus-ms" <focus-ms@securityfocus.com>

The problem with this is that you can only set security at the NT share
level. There's no opportunity to set different permissions (rights) to
specific files or subdirectories of the drive or directory on the
NetWare server that you select as a "mount point" for your NT share.

So this isn't a good solution for environments that have granular
security settings, and particularly not for user home directories.

Also, the users loose any NDS and other NetWare-specific features, since
they don't actually participate on the NetWare network (i.e., the
NetWare server never sees the individual users, just the NTGATEWAY user
account).

> -----Original Message-----
> From: Taylor, Gord [mailto:GORD.TAYLOR@royalbank.com]
> Sent: Tuesday, October 30, 2001 8:03 AM
> To: Keith Maxon; focus-ms
> Subject: RE: Passwords
>
>
> One of the options is to use gateway services for netware.
> Users log into
> NT, drives are mapped through NT, but all the normal Netware
> resources are
> still available.
>
> -----Original Message-----
> From: Keith Maxon [mailto:KMaxon@Pulte.com]
> Sent: Monday, October 29, 2001 11:39 AM
> To: 'focus-ms@securityfocus.com'
> Subject: Passwords
>
>
> I'm sure this problem has been posted before, but I am in an
> interesting
> position. We run Windows 95 clients (we are migrating to
> 2000), Windows NT
> 4.0 DC's and Novell 4.11. I just had security awareness
> training instructing
> all employees not to give passwords out to the IS department,
> however, as
> all of you know, NT and Novell don't sync very well. Is there a way to
> securely sync the two without compromising my policy? Any help is
> appreciated. Thanks.
>
>
>
> --------------------------------------------------------------
> --------------------------------------------------------------
> -------------------
> This e-mail may be privileged and/or confidential, and the
> sender does not waive any related rights and obligations. Any
> distribution, use or copying of this e-mail or the
> information it contains by other than an intended recipient
> is unauthorized. If you received this e-mail in error, please
> advise me (by return e-mail or otherwise) immediately.
>
> Ce courriel est confidentiel et protégé. L'expéditeur ne
> renonce pas aux droits et obligations qui s'y rapportent.
> Toute diffusion, utilisation ou copie de ce message ou des
> renseignements qu'il contient par une personne autre que le
> (les) destinataire(s) désigné(s) est interdite. Si vous
> recevez ce courriel par erreur, veuillez m'en aviser
> immédiatement, par retour de courriel ou par un autre moyen.
>
>
> ==============================================================
> ================
>
>



Relevant Pages

  • RE: passwords in asp pages
    ... and using integrated security for connecting to the database- this will ... remove cleartext passwords from the files. ... grab the raw asp source from the server. ... to facilitate one-on-one interaction with one of our expert instructors. ...
    (Security-Basics)
  • Re: Oh Dear, Where to start?!
    ... > sort of security solution? ... > use, passwords, physical security, backup/disaster ... > admin, network admin, tech support, programming, and ... Theres lots of software out there for backups. ...
    (Security-Basics)
  • [NT] Webserver 4D Weak Password Preservation Vulnerability
    ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... complete Web Server environment written entirely on top of 4th Dimension, ... WS4D web server saves the passwords somewhere insecure. ...
    (Securiteam)
  • Re: Final Year Project Brainstorming
    ... An interesting and always relevant topic is passwords. ... with a real-life scenario where Ubuntu's security is better than Vista ... The computers were very old so they were told they would have to ... Figure the cost of IT person for Vista vs ...
    (Ubuntu)
  • Re: Electronic Storage of Class 1/ 2 Medical forms... "Best Practice"?
    ... This has proven to be more of a security ... it will be as secure as most of the stuff at the NSA (National ... the user is taken to the server directory where the form is stored. ... Are the passwords sufficiently ...
    (rec.scouting.usa)