You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Hello. ISO/IEC 27001 and PCI DSS, as well as other security standards, have a requirement to periodically change users' passwords.
Does anybody have any thoughts how to implement this in ViMbAdmin?
As far as I can see it, the problem is divided into four parts:
When (user|admin) sets a password to a mailbox, store current (or expiration?) timestamp in the database;
Take this timestamp into account when an external system requests mailbox properties;
Take (or not, depending on company needs) this timestamp into account when user logs in to change his password;
Periodically check and notify users that their passwords will expire soon.
As 1.-3. can be added as a plugin fairly easily, they require schema modification (OR using field mailbox.modified - is it possible??)
2. requires modified requests to the database (mention it in documentation)
And 4. requires some kind of cron job and a template for mailing notifications.
What do you say?
The text was updated successfully, but these errors were encountered:
(just a small note a profile control panel linked to a SSO or at least a LDAP is probably more convenient to centrally control the password lifecycle than to hunt it in every application / that would be a nightmare to audit and certify if each application used in a domain has its own procedure to force users to change passwords)
(just a small note a profile control panel linked to a SSO or at least a LDAP is probably more convenient to centrally control the password lifecycle than to hunt it in every application
Yes, but ViMmAdmin is that very application which keeps and manages passwords, and it IS by design a source of credentials for SMTP/IMAP server - so this functionality is a must for it.
Hello. ISO/IEC 27001 and PCI DSS, as well as other security standards, have a requirement to periodically change users' passwords.
Does anybody have any thoughts how to implement this in ViMbAdmin?
As far as I can see it, the problem is divided into four parts:
As 1.-3. can be added as a plugin fairly easily, they require schema modification (OR using field
mailbox
.modified
- is it possible??)2. requires modified requests to the database (mention it in documentation)
And 4. requires some kind of cron job and a template for mailing notifications.
What do you say?
The text was updated successfully, but these errors were encountered: