Re: How secure is "Password Safe Application" ?



The primary use is to put "service" accounts (for SQL, Sharepoint,
thirdy-part apps) that are unfortunately need to be shared.
The admins must not put their own accounts there and each admin should have
his own password.

"Robert Moir" <robspamtrap+msnews@xxxxxxxxx> wrote in message
news:uXnCVFPLGHA.2124@xxxxxxxxxxxxxxxxxxxxxxx
Marlon Brown wrote:
Do you think it is an acceptable security practice use an application
such as "Password Safe Application" from SourceForget.net to store
server passwords in my organization ? Some admins want to store such
Password Safe Application on a network share, protected by NTFS
folder permissions to the admin group.

Please advise.

Well its probably safer than having them write the passwords on post it
notes and hide them under their keyboards.

What exactly are you hoping to achieve? What will this password repository
be used for exactly? To store centrally held but seldom used "master"
passwords "in the event of a disaster"?

Or for forgetful admins who are worried they can't remember their
passwords from one day to the next?

I assume your admins each use their own admin account rather than a shared
one so that you stand some chance of auditing who made which changes?



.



Relevant Pages

  • Re: one account - login to terminal services on several domains...
    ... which child-domain it may be in and allow them to manage accounts in any ... you should create a global group in the forest root e.g. "Forest ... and domain admins group and other sensitive security principals in the ... To differentiate these permissions from the "Forest Server-Admins" it would ...
    (microsoft.public.windows.server.active_directory)
  • RE: restricted admins...
    ... >Subject: restricted admins... ... Computers at the Domain Controllers container) ... Put the user accounts into an "ERP Dev" group, ...
    (microsoft.public.win2000.general)
  • RE: Changing the domain password policy
    ... The Domain Admin accounts should be the first to implement a strong ... Admins, Schema Admins, System Restore Accounts, SQL SA accounts, etc.) ... EARN A MASTER OF SCIENCE IN INFORMATION ASSURANCE - ONLINE ... The NSA has designated Norwich University a center of Academic Excellence ...
    (Security-Basics)
  • Re: Account Operators accessing other account operators
    ... Yes our helpdesk users were account operators from our NT days ... hoping to avoid having to delegate permissions on each OU and the ... want to use delegated accounts for AD data admins." ... They do not appear to have access to their own accounts or anything above. ...
    (microsoft.public.windows.server.active_directory)
  • Question about disabling local account creation and NoMachineGroups -- Anyone have an answer
    ... I don't want web admins to be able to create local ... disallow admins from creating local accounts. ... That checkbox is cleared but users still can create local accounts. ... I found the NoMachineGroups feature and have applied that. ...
    (microsoft.public.frontpage.extensions.windowsnt)