Security Basics mailing list archives

Re: Self Service Password Resets


From: A K <platsakos () gmail com>
Date: Thu, 02 Apr 2009 23:24:54 +0300

An Identity Manager is what you are looking for. Give Sun's IDM a go,
you will not be disappointed. It integrates with MS-AD nicely.

<DISCLAIMER> There are a lot of other IDM products that provide
equivalent service, however I only have experience with Sun's IDM

<References>

http://www.sun.com/software/products/identity_mgr/index.xml

Campbell, Josh wrote:
Hello list,

I work for a public university and my manager has asked me to look into a self service password reset solution.  We 
have many employees that do not work on campus or even in the same state (adjunct professors).  Currently when they 
forget their password we have them go through several hoops to get their password reset, including faxing over some 
ID and having their department head contact us.  This was originally designed to be a hassle in hopes that we 
wouldn't get very many "repeat customers" for forgetting their passwords.

Anywho, I was wondering what solutions other people out there are using for this type of thing?  Ideally we would 
like something that a user could go to from their web browser at home or any computer not on our network and they 
would be forced to answer a series of challenge questions (I know this brings up the point of them forgetting the 
challenge questions too but let's not even go there).  We use MS Active Directory so that would also be a requirement 
for the solution.

Thanks in advance!

-Josh C

------------------------------------------------------------------------
This list is sponsored by: InfoSec Institute

No time or budget for traveling to a training course in this fiscal year? Check out the online information security 
courses available at InfoSec Institute. More than a boring "talking head", train in our virtual labs for a total 
hands-on training experience. Get the certs you need: CEH, CPT, CEPT, CISA, CISSP, CISM

http://www.infosecinstitute.com/request_online_training.html
------------------------------------------------------------------------


  

------------------------------------------------------------------------
This list is sponsored by: InfoSec Institute

No time or budget for traveling to a training course in this fiscal year? Check out the online information security 
courses available at InfoSec Institute. More than a boring "talking head", train in our virtual labs for a total 
hands-on training experience. Get the certs you need: CEH, CPT, CEPT, CISA, CISSP, CISM

http://www.infosecinstitute.com/request_online_training.html
------------------------------------------------------------------------


Current thread: