[332] in resnet

home help back first fref pref prev next nref lref last post

Re: How do you handle forgotten passwords?

daemon@ATHENA.MIT.EDU (Kelly Taylor)
Tue Nov 6 11:14:15 2001

Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii" ; format="flowed"
Message-ID:  <a05001901b80db99e48be@[172.20.107.57]>
Date:         Tue, 6 Nov 2001 11:12:55 -0500
Reply-To: Resnet Forum <RESNET-L@listserv.nd.edu>
From: Kelly Taylor <ktaylor@HAMPSHIRE.EDU>
To: RESNET-L@listserv.nd.edu
In-Reply-To:  <4.2.0.58.20011025110550.00c156d0@127.0.0.1>

>I've been asked to find out what procedures other universities follow when
>a client forgets their password.

At Hampshire, which is very small (and many of the students I can
verify by sight) we have 2 official ways of requesting a password
reset. (This is for the student email/webpages Solaris box only - we
have no other network passwords and will be implementing LDAP soon,
so there will only ever have to be ONE password.  Bwahahahahahaha.)

They either have to:
a) bring a photo ID to one of several people who have root on the
student email server (me, the sysadmin, webmanager or one of the
student "stouters" who admin the box)

b) fill out a "Got Password?" password reset request form, which must
contain their name, box & phone #, and I then reset their password to
something random yet semi-secure and put it in their on-campus
mailbox along with instructions on how to change their password to
something THEY can remember.  The theory being  that only they will
have the combination to their box.

Granted, if someone really wanted to, it would be easy to steal
someone's login/pwd but we've generally had more problems with h@%0rz
creating fake accounts than stealing real ones, and those have all
been from off-campus.   Most "mad haxors" on-campus have enough of
their own boxen to beat on and don't need to mess with the school's
servers.

-Kelly
--
- - - - - - - - - - - - - - - - - - - - - - - -
Kelly B. Taylor
Computing Services Coordinator
http://computing.hampshire.edu
- - - - - - - - - - - - - - - - - - - - - - - -

___________________________________________________
You are subscribed to the ResNet-L mailing list.

To subscribe, unsubscribe or search the archives,
go to http://LISTSERV.ND.EDU/archives/resnet-l.html
___________________________________________________

home help back first fref pref prev next nref lref last post