- CheckMates
- :
- Products
- :
- General Topics
- :
- GAIA Password Policy - Deny access to unused accou...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
GAIA Password Policy - Deny access to unused accounts
We have a client that has a enterprise identity access system that controls logon, password rotation and complexity to access systems like GAIA. They would like to turn on "Deny access to unused accounts". The admin account in GAIA is considered a "break glass" account and not normally used unless there was an emergency and the identity access system not available (identity access system does not include the admin account). As per the documentation "If there were no successful login attempts within a set time, the user is locked out and cannot log in". Can anyone confirm this would apply to the default admin account as well? I'm sure it does and would result in admin being locked out.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
It does apply, I tested this couple of times before.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
So, if that is the case is there a way around this so it would "not" apply to the admin account. A bit silly to lock out the admin account.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Personally, I dont think its silly, because think of it this way...if admin has not logged in for 365 days, chances are they wont log in day 366 either lol
Anyway, I dont see any option to change that per user, either in web UI or clish
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If you’re using an external system for authentication (e.g. RADIUS), it’s probably better to enforce this on the authentication server instead of on Gaia.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Definitely makes more sense in this case.
