<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Password reuse subdomains in Browse</title>
    <link>https://community.checkpoint.com/t5/Browse/Password-reuse-subdomains/m-p/167062#M22</link>
    <description>&lt;P&gt;Hey,&lt;/P&gt;&lt;P&gt;We got a installation of &lt;LI-PRODUCT title="Harmony Endpoint" id="sandblast-agent"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;running on all org PCs. We are having some not so very user friendly issues. Our situation: We got a protected domain&lt;EM&gt;domain.se&lt;/EM&gt;. Basically all our internal services are then based on subdomains to this domain, for example&amp;nbsp;&lt;EM&gt;git.domain.se&lt;/EM&gt;. The domain and all the subdomain services are connected to our AD and use one and the same&amp;nbsp;corporate password.&lt;/P&gt;&lt;P&gt;The problem we are having is when a user gets a notification about password reuse on for example&amp;nbsp;&lt;EM&gt;externaldomain.com&lt;/EM&gt; because the password is guarded by&amp;nbsp;&lt;EM&gt;git.domain.se&lt;/EM&gt;. So the user logs out, logs in again with the new password and opens a browser again. They navigate to&amp;nbsp;&lt;EM&gt;git.domain.se&amp;nbsp;&lt;/EM&gt;login there to make sure the new password i cached instead of the old one. But now when they login into&amp;nbsp;&lt;EM&gt;externaldomain.com&amp;nbsp;&lt;/EM&gt;they instead get a notification from&amp;nbsp;&lt;EM&gt;example.domain.se,&amp;nbsp;&lt;/EM&gt;they repeat the processes there to make sure the new password is cached there aswell. I think you can see where this is going. With 10+ different subdomains this becomes unsustainable for our users.&lt;/P&gt;&lt;P&gt;Is there a solution where all of the subdomains gets the new password cached when for example&amp;nbsp;&lt;EM&gt;git.domain.se&amp;nbsp;&lt;/EM&gt;gets the new password cached? I tried guading &lt;EM&gt;homepage.domain.se&amp;nbsp;&lt;/EM&gt;but it uses SSO so that had no success either. In a perfect world, one cached subdomain should be enough because when the password is changed in the main domain it also changes in all the subdomains. Alternativly, is there a way to easily clear out the cached password that the webprotection is holding?&lt;/P&gt;&lt;P&gt;Thank you in advance.&lt;/P&gt;&lt;P&gt;//Ben&lt;/P&gt;</description>
    <pubDate>Mon, 09 Jan 2023 11:58:26 GMT</pubDate>
    <dc:creator>Ben_Swe</dc:creator>
    <dc:date>2023-01-09T11:58:26Z</dc:date>
    <item>
      <title>Password reuse subdomains</title>
      <link>https://community.checkpoint.com/t5/Browse/Password-reuse-subdomains/m-p/167062#M22</link>
      <description>&lt;P&gt;Hey,&lt;/P&gt;&lt;P&gt;We got a installation of &lt;LI-PRODUCT title="Harmony Endpoint" id="sandblast-agent"&gt;&lt;/LI-PRODUCT&gt;&amp;nbsp;running on all org PCs. We are having some not so very user friendly issues. Our situation: We got a protected domain&lt;EM&gt;domain.se&lt;/EM&gt;. Basically all our internal services are then based on subdomains to this domain, for example&amp;nbsp;&lt;EM&gt;git.domain.se&lt;/EM&gt;. The domain and all the subdomain services are connected to our AD and use one and the same&amp;nbsp;corporate password.&lt;/P&gt;&lt;P&gt;The problem we are having is when a user gets a notification about password reuse on for example&amp;nbsp;&lt;EM&gt;externaldomain.com&lt;/EM&gt; because the password is guarded by&amp;nbsp;&lt;EM&gt;git.domain.se&lt;/EM&gt;. So the user logs out, logs in again with the new password and opens a browser again. They navigate to&amp;nbsp;&lt;EM&gt;git.domain.se&amp;nbsp;&lt;/EM&gt;login there to make sure the new password i cached instead of the old one. But now when they login into&amp;nbsp;&lt;EM&gt;externaldomain.com&amp;nbsp;&lt;/EM&gt;they instead get a notification from&amp;nbsp;&lt;EM&gt;example.domain.se,&amp;nbsp;&lt;/EM&gt;they repeat the processes there to make sure the new password is cached there aswell. I think you can see where this is going. With 10+ different subdomains this becomes unsustainable for our users.&lt;/P&gt;&lt;P&gt;Is there a solution where all of the subdomains gets the new password cached when for example&amp;nbsp;&lt;EM&gt;git.domain.se&amp;nbsp;&lt;/EM&gt;gets the new password cached? I tried guading &lt;EM&gt;homepage.domain.se&amp;nbsp;&lt;/EM&gt;but it uses SSO so that had no success either. In a perfect world, one cached subdomain should be enough because when the password is changed in the main domain it also changes in all the subdomains. Alternativly, is there a way to easily clear out the cached password that the webprotection is holding?&lt;/P&gt;&lt;P&gt;Thank you in advance.&lt;/P&gt;&lt;P&gt;//Ben&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jan 2023 11:58:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Browse/Password-reuse-subdomains/m-p/167062#M22</guid>
      <dc:creator>Ben_Swe</dc:creator>
      <dc:date>2023-01-09T11:58:26Z</dc:date>
    </item>
    <item>
      <title>Re: Password reuse subdomains</title>
      <link>https://community.checkpoint.com/t5/Browse/Password-reuse-subdomains/m-p/167129#M23</link>
      <description>&lt;P&gt;Hi Ben,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I would like to better understand the problem. Please reach out to us via the feedback button in your portal and we'll take it from there.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Adi&lt;/P&gt;</description>
      <pubDate>Mon, 09 Jan 2023 14:14:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Browse/Password-reuse-subdomains/m-p/167129#M23</guid>
      <dc:creator>AdiGH</dc:creator>
      <dc:date>2023-01-09T14:14:09Z</dc:date>
    </item>
  </channel>
</rss>

