BeyondTrust

Security In Context

Bringing you news and commentary on solutions and strategies for protecting your critical IT infrastructure.

Extending Password Policy To UNIX and Linux

Post by Peter McCalister September 21, 2011

Our friends and colleagues at the Linux Foundation have been hit by a “brute force attack” and many of their sites have been taken down until the security breach is fully controlled.

The good news here? The Linux kernel and the projects’ source codes haven’t been affected. The bad news? As noted by desktoplinux.com, “Username, password, email address, and “other information” provided by users registered with the sites may have been stolen.” As a Linux user and big fan of the Linux Foundation, my personal information is likely included in the compromised set. And on a personal basis, the fix is easy–a new, strong password that’s unique to that site.

What about on a corporate level? When a breach like this occurs, say at a BeyondTrust customer with a large deployment of Linux & UNIX systems, what’s the best practice for IT admins?
I wrote a couple months back about password management and how it is the weakest link in enterprise security. There have been many studies done that show password complexity and a regular cycle of password changes improves the daunting prospect of maintaining security. This is a best practice employed in most enterprise IT organizations and a key component of compliance with regulations and standards like Sarbanes-Oxley.

Password policy is easily managed in Active Directory for Windows systems. But what about Linux and UNIX systems–as highlighted by the breach at Linux.com?

We’ve noted before that centralizing on a single directory is a security best practice, and we have a free and open source solution that enables extending password policy to Linux and UNIX systems–fulfilling best practice requirements. PowerBroker Identity Service – Open Edition is a free download for over 200 Linux and UNIX platforms and enables administrators to join machines to Active Directory and require users to login with their directory credentials. The entire process takes less than five minutes–download, install, join. The password policies that you set in your Windows environment are then extended to users on these machines.

And when a security breach occurs like the one noted above? Administrators can push out a password change requirement or trust their strong password policy to keep systems secure across the enterprise, no matter what operating system they are using.

Leave a Reply

Additional articles

BI-Qualys-Connector-IMG1

Getting More Value from QualysGuard Vulnerability Data with BeyondInsight v5.1

If your vulnerability assessment scans can’t produce meaningful and actionable reports, performing a scan does no good for anyone. If you’ve read my other blog posts, you know I have no qualms about stating that BeyondTrust provides the best vulnerability reporting in the industry. Ask your favorite analyst and they’ll tend to agree. Of course,…

Post by Morey Haber April 18, 2014
Tags:
, , , , , , , ,
insider-threat-fed

Mitigating Inside Threats to U.S. Federal IT Environments

Recent high-profile cases have increased the perceived risks that go along with disclosure and usage of confidential information. One of the most difficult security threats to mitigate is an attack from the inside. When an over-privileged user, such as an unhappy current or former employee, contractor, or consultant, begins navigating your network, how will you…

Post by BeyondTrust Software April 17, 2014
Tags:
, , , , ,

Are you a Target? Investigating Security Breaches with Kevin Johnson

Last week, over 1,000 IT security professionals watched as Kevin Johnson, CEO of Secure Ideas, presented his expert opinion on lessons learned from recent, high-profile retail breaches. Here’s a summary of key takeaways from the webcast plus an on-demand recording of the full, 60-minute presentation. Understanding the “why” behind attacks According to Kevin, the primary…

Post by Chris Burd April 17, 2014
Tags:
, , , , ,