Skip to Content.
Sympa Menu

eic-bnl-comp-l - Re: [Eic-bnl-comp-l] SDCC/RACF password policy change

eic-bnl-comp-l AT lists.bnl.gov

Subject: EIC/BNL Computing discussion

List archive

Chronological Thread  
  • From: Kolja Kauder <kkauder AT gmail.com>
  • To: Aschenauer Elke-Caroline via Eic-bnl-soft-l <eic-bnl-soft-l AT lists.bnl.gov>, "EIC/BNL Computing discussion" <eic-bnl-comp-l AT lists.bnl.gov>
  • Subject: Re: [Eic-bnl-comp-l] SDCC/RACF password policy change
  • Date: Tue, 22 Sep 2020 11:48:58 -0400

Hi all,

Just to clarify a few things:
- You use this login in a few places, most prominently when you use
kinit or connect to a node like eic104, but also for example in the
bnl mattermost.
- I would google a pass phrase generator. I used
https://urldefense.com/v3/__https://randompassphrasegenerator.com/?r=3__;!!P4SdNyxKAPE!RdNEJY0pQ9Puf4XBCSe7t9thXdAxh8L_9RLdNOZSsRyUlChpfDXCL89zR4kaofQcgPOaeOsA0mA$

but I have no higher knowledge how good or safe this one is.

- Don't forget, you probably have two logins! For eic and your
experiment, so update both. I actually used a private tab but also
contacted support to provide a "logout" button to the website.

Kolja



On Wed, Sep 16, 2020 at 2:07 PM Kolja Kauder <kkauder AT gmail.com> wrote:
>
> Hi all,
>
> SDCC has now formally announced the password policy change and
> provided information and tools here:
> https://www.racf.bnl.gov/docs/authentication/passwords
>
> IMPORTANT: Please update your password by OCTOBER 12th to avoid being
> locked out of
> your account.
>
> Thanks,
> Kolja
>
>
> On Mon, Sep 14, 2020 at 9:49 AM Kolja Kauder <kkauder AT gmail.com> wrote:
> >
> > Hi all,
> >
> > The SDCC/RACF password policy is changing (as of Monday 9/14/2020) to
> > conform with new requirements from the DOE. The new policy is that:
> >
> > 1. Passwords will not ever expire.
> > 2. Passwords do not have to satisfy any specific complexity rules or
> > have any
> > specific set of special characters.
> >
> > However,
> >
> > 3. Passwords must be at least 16 characters long (!)
> > 4. New passwords will be compared to a database of insecure and/or
> > cracked passwords when they are created, and will be rejected if they
> > exist
> > on the list of insecure passwords.
> > 5. Passwords will be rejected if they match any of your previous 24
> > passwords.
> >
> > As of this time, only the SDCC/RACF password will be affected. This is
> > the password that is used for logging into the SDCC facility and which
> > is used for your kerberos credentials. In particular, the RACF email
> > account passwords are not affected by this policy change.
> >
> > There should be an official announcement from the SDCC tomorrow
> > announcing this change and providing links for a web based application
> > to change the password. You should also be able to change the password
> > as normal from the SDCC linux command line. After the official
> > announcement, I will forward any instructions or links to this mailing
> > list as well.
> >
> > You will have 1 month to change your password to comply with the new
> > policy. If you fail to do so within that time period you will be
> > locked out of your account, and need to fill out an RT ticket to restore
> > access.
> >
> > Thank you,
> > Kolja
> >
> > (Thanks to Jeff Landgraf whose wording I stole)
> >
> > --
> > ________________________
> > Kolja Kauder, Ph.D.
> > Post-Doctoral Research Associate,
> > Brookhaven National Lab, Upton, NY
> > +1 (631) 344-5935
> > ________________________
>
>
>
> --
> ________________________
> Kolja Kauder, Ph.D.
> Post-Doctoral Research Associate,
> Brookhaven National Lab, Upton, NY
> +1 (631) 344-5935
> ________________________



--
________________________
Kolja Kauder, Ph.D.
Post-Doctoral Research Associate,
Brookhaven National Lab, Upton, NY
+1 (631) 344-5935
________________________




Archive powered by MHonArc 2.6.24.

Top of Page