Contact Information
Marvin Huffaker Consulting
1311 W Chandler Blvd
Suite 160A
Chandler, AZ 85224

Toll Free: 1-888-690-0013
Local AZ: 480-988-7215
Fax: 480-988-7216

http://www.redjuju.com

Feature Article: Novell Password Security
By Marvin Huffaker

In just about every company I've ever worked with, I have found that some of the most basic security concepts and precautions are often overlooked. Since the topic of security is undoubtedly very complex, the focus of this article is basic and deals only with passwords. The following are general guidelines for protecting passwords on a Novell NetWare and eDirectory system. If you've already got these guidelines covered, great, you're on the right track. These general concepts could also apply to any other systems as well.

This article does not cover more complex security topics. It also does not discuss the Universal Password, which introduces stronger password policies into any eDirectory environment.

Passwords too short
Passwords should be a minimum of 8 characters and include non-alpha characters (letters besides A-Z). A long password is more difficult to guess or crack. In general terms, a short password can be cracked almost instantaneously, while a longer password could take several thousand years.

Passwords not being changed
Users should never be allowed to keep the same password for an extended period of time. In the event that a malicious user or intruder does find someone's password, it will become worthless if the users are changing their passwords regularly.

Passwords not Unique
Some users have figured out that they can rotate back and forth between two different passwords each time they are required to make a change. This is almost as bad as not changing the passwords at all. It's important to implement a policy that forces and requires unique passwords that are actually unique.

Passwords and Sticky Notes
Under no circumstances whatsoever should an employee write their user ID and password on a sticky note and tack it to the monitor. Don't make it so easy for a bystander, the janitor, or a malicious coworker to gain unauthorized access. All employees should be instructed to keep their User ID's and passwords private.

Administrator Passwords
Password guidelines for administrators should be even more strict than regular users. Longer, more complex, and changed regularly. Furthermore, use a variety of passwords for different things. For example, if you have an "Admin" account, make the password different than the remote console password and SNMP community strings.


ENFORCING PASSWORD POLICIES
It's important to define a password policy for your company and then stick to it. There are no password restrictions in place on a default Novell NetWare system installation. You must define and implement these policies yourself. A full tutorial of how to set and enforce password policies can be found in our 'Tutorials and White Papers' section.

About Marvin Huffaker Consulting
Marvin Huffaker Consulting, Inc. specializes in Novell solutions and support. If you are having trouble implementing security restrictions in your network, call us today 100% Guaranteed Service. Find out how we can make your network run more reliable, faster, and secure.

novell support consultant
we are novell experts
Marvin Huffaker Consulting: Novell Support Specialist. Nationwide Support. Based in Phoenix and serving the entire Phoenix Metro Area including Tempe, Scottsdale, Mesa, Chandler, Tempe, and Gilbert.

Marvin Huffaker Consulting, Inc. is a professional services consulting firm. Our areas of expertise are with network operating systems running NetWare and Linux, messaging and collaboration, and virtualization and storage. We deliver premium contract services, high availability, disaster recovery / business continuity, workgroup network solutions. Our comprehensive offerings include email management and support, server infrastructure support, managed services, email implementation and support, and more. We utilize virtualization in many of our solution sets, and we recommend and support best in class solutions from Compellent, Novell, Gwava, Messaging Architects, Astaro, and more. Copyright © 2002-2008 Marvin Huffaker Consulting, Inc. all rights reserved. REDJUJU and the MHC logo are trademarks of Marvin Huffaker Consulting, Inc. All other trademarks are property of their respective owners. Read our Privacy Statement