Windows

NAVIGATION
CATEGORIES
REFERRENCE
LINKS
  • SHAREPOINT AND EXTERNAL LDAP

    4 answers - 715 bytes - related search similar search Add To My Delicious Add To My Stumble Upon Add To My Google Mark Add To My Facebook Add To My Digg Add To My Reddit

    HI,
    I have a SharePoint site for a client, it is driving me crazy because
    the sales people are telling me that the users for this site, cant have
    their password expiring. The client is a government agency, so I don't
    want to be responsible for any information being stolen.
    How big of a security risk is not having password expiring? it seems to
    me like security 101, but the sales guy is saying that banks don't ask
    you to change your password every X day, good point.
    Something I was thinking is having SharePoint authenticating with their
    LDAP server, is this possible to do? can anybody point to a url on how
    to do this?
    thanks
    Rezuma
  • No.1 | | 990 bytes | |

    I have been involved in externally facing Microsoft sponsored
    extranet/Sharepoint sites.

    The password gets changed.

    We have a GUI web portal and we are forced to change the password.

    Sales people set your security policy these days?

    Ramon Linan wrote:
    HI,

    I have a SharePoint site for a client, it is driving me crazy because
    the sales people are telling me that the users for this site, cant
    have their password expiring. The client is a government agency, so I
    don't want to be responsible for any information being stolen.

    How big of a security risk is not having password expiring? it seems
    to me like security 101, but the sales guy is saying that banks don't
    ask you to change your password every X day, good point.

    Something I was thinking is having SharePoint authenticating with
    their LDAP server, is this possible to do? can anybody point to a url
    on how to do this?

    thanks

    Rezuma
  • No.2 | | 2252 bytes | |

    You might consider creating an ADAM instance which is a copy of their
    LDAP source and authenticate against it. But I fully agree with you that
    the better way is allow passwords to expire. If you set up the IIS
    password changing extension on the server you might be able to integrate
    it in such a way that they can change their passwords against it. I'm
    assuming that certificate based authentication is out of the question?

    From: ActiveDir-owner (AT) mail (DOT) activedir.org
    [mailto:ActiveDir-owner (AT) mail (DOT) activedir.org] Behalf Ramon Linan
    Sent: 19 September 2006 17:45
    To: ActiveDir (AT) mail (DOT) activedir.org
    Subject: RE: [ActiveDir] SHAREPINT AND EXTERNAL LDAP

    HI,

    I have a SharePoint site for a client, it is driving me crazy because
    the sales people are telling me that the users for this site, cant have
    their password expiring. The client is a government agency, so I don't
    want to be responsible for any information being stolen.

    How big of a security risk is not having password expiring? it seems to
    me like security 101, but the sales guy is saying that banks don't ask
    you to change your password every X day, good point.

    Something I was thinking is having SharePoint authenticating with their
    LDAP server, is this possible to do? can anybody point to a url on how
    to do this?

    thanks

    Rezuma

    Disclaimer:
    The Development Bank of Southern Africa exercises no control over information contained in any e-mail message originating from within the organisation. The Bank makes no representation relating to the completeness or accuracy and accepts no responsibility for any loss, damage or liability that is incurred by reliance on the content hereof by the recipient or any other party. Each page attached hereto must also be read in conjunction with any disclaimer, which forms part of it.
    Confidentiality:
    The e-mail is privileged and confidential and for use of the addressee only. Should you have received this e-mail in error, please return it to webmaster (AT) dbsa (DOT) org. Dissemination, disclosure, copying or any similar actions of the content of this e-mail is strictly prohibited.
  • No.3 | | 1918 bytes | |

    I have been told (BTW) by the patch management tool folks that still
    support customers that buy NT patches -- that their main customers that
    buy NT patches from Microsoft are banks and financial institutions.

    Consider as well that when I walk into Bank of America they are running
    DS based apps.

    I wouldn't use "banks" as a shining example of security policywhen
    BofA has

    1. allowed slammer to nail their ATM networks
    2. Lost backup tapes causing identity theft

    as two such shining examples of security policy in action.

    Who's going to be on the firing line when something happens? Bank of
    America? your buns?

    If it's your buns, are your comfortable with not changing passwords?

    Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP] wrote:
    I have been involved in externally facing Microsoft sponsored
    extranet/Sharepoint sites.

    The password gets changed.

    We have a GUI web portal and we are forced to change the password.
    Sales people set your security policy these days?

    Ramon Linan wrote:
    >HI,
    >
    >I have a SharePoint site for a client, it is driving me crazy because
    >the sales people are telling me that the users for this site, cant
    >have their password expiring. The client is a government agency, so I
    >don't want to be responsible for any information being stolen.
    >
    >How big of a security risk is not having password expiring? it seems
    >to me like security 101, but the sales guy is saying that banks don't
    >ask you to change your password every X day, good point.
    >
    >
    >Something I was thinking is having SharePoint authenticating with
    >their LDAP server, is this possible to do? can anybody point to a url
    >on how to do this?
    >
    >thanks
    >
    >Rezuma
    >
  • No.4 | | 2566 bytes | |

    Too true Susan.

    Also in Banks, at least in SA, you need the Account number/PIN/Password
    combination to get access to your account and not just a password.

    Message
    From: ActiveDir-owner (AT) mail (DOT) activedir.org
    [mailto:ActiveDir-owner (AT) mail (DOT) activedir.org] Behalf Susan Bradley,
    CPA aka Ebitz - SBS Rocks [MVP]
    Sent: 19 September 2006 18:26
    To: ActiveDir (AT) mail (DOT) activedir.org
    Subject: Re: [ActiveDir] SHAREPINT AND EXTERNAL LDAP

    I have been told (BTW) by the patch management tool folks that still
    support customers that buy NT patches -- that their main customers that

    buy NT patches from Microsoft are banks and financial institutions.

    Consider as well that when I walk into Bank of America they are running
    DS based apps.

    I wouldn't use "banks" as a shining example of security policywhen
    BofA has

    1. allowed slammer to nail their ATM networks
    2. Lost backup tapes causing identity theft

    as two such shining examples of security policy in action.

    Who's going to be on the firing line when something happens? Bank of
    America? your buns?

    If it's your buns, are your comfortable with not changing passwords?

    Susan Bradley, CPA aka Ebitz - SBS Rocks [MVP] wrote:
    I have been involved in externally facing Microsoft sponsored
    extranet/Sharepoint sites.

    The password gets changed.

    We have a GUI web portal and we are forced to change the password.
    Sales people set your security policy these days?

    Ramon Linan wrote:
    >HI,
    >
    >I have a SharePoint site for a client, it is driving me crazy because


    >the sales people are telling me that the users for this site, cant
    >have their password expiring. The client is a government agency, so I


    >don't want to be responsible for any information being stolen.
    >
    >How big of a security risk is not having password expiring? it seems


    >to me like security 101, but the sales guy is saying that banks don't


    >ask you to change your password every X day, good point.
    >
    >
    >Something I was thinking is having SharePoint authenticating with
    >their LDAP server, is this possible to do? can anybody point to a url


    >on how to do this?
    >
    >thanks
    >
    >Rezuma
    >

Re: SHAREPOINT AND EXTERNAL LDAP


max 4000 letters.
Your nickname that display:
In order to stop the spam: 3 + 2 =
QUESTION ON "Windows"

EMSDN.COM