Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
John_Richards
Contributor

GAIA Password Policy - Deny access to unused accounts

We have a client that has a enterprise identity access system that controls logon, password rotation and complexity to access systems like GAIA. They would like to turn on "Deny access to unused accounts". The admin account in GAIA is considered a "break glass" account and not normally used unless there was an emergency and the identity access system not available (identity access system does not include the admin account). As per the documentation "If there were no successful login attempts within a set time, the user is locked out and cannot log in". Can anyone confirm this would apply to the default admin account as well? I'm sure it does and would result in admin being locked out.

0 Kudos
5 Replies
the_rock
Legend
Legend

It does apply, I tested this couple of times before.

0 Kudos
John_Richards
Contributor

So, if that is the case is there a way around this so it would "not" apply to the admin account. A bit silly to lock out the admin account.

0 Kudos
the_rock
Legend
Legend

Personally, I dont think its silly, because think of it this way...if admin has not logged in for 365 days, chances are they wont log in day 366 either lol

Anyway, I dont see any option to change that per user, either in web UI or clish

Andy

0 Kudos
PhoneBoy
Admin
Admin

If you’re using an external system for authentication (e.g. RADIUS), it’s probably better to enforce this on the authentication server instead of on Gaia.

0 Kudos
the_rock
Legend
Legend

Definitely makes more sense in this case.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events