IETF-SSH archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: WG Last Call (third time's the charm?) for SSH core drafts



> Actually it might even be better to have it as a MUST since not doing
> so allows for the potential of a client/server pair that can bypass admin
> policy and we shouldn't really encourage that.

Well, the password policy should be entirely enforced by the server.

MUST would rule out a "soft password expiration" policy where the
server could strongly suggest, but not require, a password change, for
some time interval before the change became mandatory..

					- Bill



Home | Main Index | Thread Index | Old Index