RE: Password management WAS: local admin compromised
From: James D. Stallard (cds@cionlne.com)Date: 11/13/01
- Previous message: Robert Clark: "RE: Domain Question"
- In reply to: Read, Greg: "Password management WAS: local admin compromised"
- Next in thread: jaylittle: "Re: Password management WAS: local admin compromised"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
From: "James D. Stallard" <cds@cionlne.com> To: "'Read, Greg'" <ReadG@JAGUARS.NFL.com>, <focus-ms@securityfocus.com> Subject: RE: Password management WAS: local admin compromised Date: Tue, 13 Nov 2001 16:04:57 -0000 Message-ID: <002f01c16c5c$f13555c0$6400000a@leafgrove.com>
Greg
Best practice is to defend your passwords as well as possible. Depending
on how large your site is this could mean a password protected Excel
spreadsheet (not easy to crack) or an envelope in a safe.
I is always a good idea to have different passwords for each server
local admin account and these should again be different to the domain
admin passwords. It is up to you where you draw the line and don't
forget the security of the room these servers are stored in and the
security of your backups and Emergency recovery disks.
Regards
James D. Stallard
james@leafgrove.com
Mobile: 07979 49 88 80
Tel: 0118 9345 020
Fax: 0118 9340 518
www.leafgrove.com
-----Original Message-----
From: Read, Greg [mailto:ReadG@JAGUARS.NFL.com]
Sent: 13 November 2001 13:53
To: 'focus-ms@securityfocus.com'
Subject: Password management WAS: local admin compromised
Jay,
>The key here is to limit the
>possibilities for privilege escalation by ensuring that the
>local Admin accounts do not share their passwords with any
>Domain Admin accounts.
I've heard this before and tend to agree with it, but...
what do you do to manage (remember) local Admin passwds?
We have a room full of servers, should all the local admin passwds be
different from each other as well as the domain?
How about services that need domain accounts to run (like
SQL server replication); what do you do to manage the passwds for these
accounts?
I don't ask these questions flippantly, I'd like to know what best
practices are. My only thought is to store them in some sort of secure
database, but what to use?
Thanks,
Greg
- Previous message: Robert Clark: "RE: Domain Question"
- In reply to: Read, Greg: "Password management WAS: local admin compromised"
- Next in thread: jaylittle: "Re: Password management WAS: local admin compromised"
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ] [ attachment ]
Relevant Pages
|