Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Disabling users from using dicitonary passwords....enabling complex passwords does not seem to do this

Posted on 2004-08-03
3
Medium Priority
?
220 Views
Last Modified: 2012-05-05
I have a security requirment at work where users are supposed to have a complex passwords containing a minumum of 8 characters, upper and lower case, numbers and/or special characters and CAN NOT be a dictionary word. This is for a stand-alone system and I have enabled Complex Passwords in the local group policy, but that does not seem to do the dictionary check? Any suggestions would be appreciated.
0
Comment
Question by:andy86
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
3 Comments
 

Expert Comment

by:theravibes
ID: 11712410
In order to answer this question, we need a little more information...

More specifically...

What operating system?
Are the user accounts managed client-side or server-side?
If it is done server-side, is it done by a local profile with server-side authentication, or is it actually a roaming profile?
What operating system is the server running (if it exists)?
What application on the server are you currently using to manage your accounts (Again, assuming that you use server-side authentication)?

If you could answer these quick few questions, then I can help you with the answer.

Perhaps the best solution that you could do if your profiles are managed server-side is to use a blacklisted passwords list, where you would have a large text document containing any strings that you would not like the end user to be capable of using. (I have only seen this ability in linux-based Windows User Profile management applications such as UMS)

You could also be possible to write a script which would check all passwords on the server before acceptance...

Tyson Edwards
0
 

Author Comment

by:andy86
ID: 11721330
to answer your questions. It is several completely stand alone Windows 2000 systems (not connected in anyway). We are using the local security policy(s) in windows. I wish I could network them and run a server, but can not do to government security requirments. I was looking at EnFIlter at http://security.di.unito.it/software/enfilter.html but need to get some more info on it. Have you used any thing like that before? I really wish I could use your suggestion of the linux based wondows profile thing, but am limited in what I am allowed to do.

Let me know what you thnik. Thanks in advance.
0
 
LVL 1

Accepted Solution

by:
CBF-IT earned 200 total points
ID: 11723108
If you are using a win server, I think you will have to find or create a custom password filter. The article at http://www-nt.stanford.edu/docs/leland.html may be of some interest to you in this regard. Dictionary word files are pretty easy to download any where on the internet, so you could use that to get started with your word filter discussed in that article.
0

Featured Post

Concerto Cloud for Software Providers & ISVs

Can Concerto Cloud Services help you focus on evolving your application offerings, while delivering the best cloud experience to your customers? From DevOps to revenue models and customer support, the answer is yes!

Learn how Concerto can help you.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Check out the latest tech news, community articles, and expert highlights in August's newsletter.
What we learned in Webroot's webinar on multi-vector protection.
Sending a Secure fax is easy with eFax Corporate (http://www.enterprise.efax.com). First, Just open a new email message.  In the To field, type your recipient's fax number @efaxsend.com. You can even send a secure international fax — just include t…
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…

719 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question