password escrow tools

From: Brian Birkinbine (bbirkinbine@earthlink.net)
Date: 08/31/01


Message-ID: <3B8EE503.8000808@earthlink.net>
Date: Thu, 30 Aug 2001 20:14:43 -0500
From: Brian Birkinbine <bbirkinbine@earthlink.net>
To: security-basics@securityfocus.com
Subject: password escrow tools

Has anyone implemented UNIX password escrow functionality?
I am needing resource/product information to determine which products
can handle this (commercial or open source).

I would like to be able to have a security group to generate random
passwords for generic accounts and once a month change the passwords for
a group of servers automatically.

Users of the generic accounts would use su, or sudo or equivalent
product to become the generic account.

In the event that the current password is required, we could look at the
current password for a particular generic id and release it to the
verified requestor for a period of time.

I understand this could be done manually, but I need a scalable solution
for 300+ systems.

Thanks,
Brian