Educause Security Discussion mailing list archives

Re: Password policy


From: Gene Spafford <spaf () CERIAS PURDUE EDU>
Date: Wed, 1 Nov 2006 15:09:22 -0500

Do most enforce password expirations?  I came from a large
corporation and they enforced a 90 day password expiration policy.
It seemed to have the effect of making passwords less secure as
most would write them down in obvious places.
Do most enforce a strong password policy?
Any other recommendations/insights along this line would be helpful.

I can suggest my post here <http://www.cerias.purdue.edu/weblogs/spaf/
general/post-30/>, and the follow-ups.

--spaf

Current thread: