#2574 Perform regular inactive account prunings and possibly a password reset policy.
Closed: Fixed None Opened 9 years ago by ricky.

We should definitely do regular pruning of inactive accounts. We should also discuss whether we should implement a password expiration policy.

Note that this includes some of the service accounts that we have, like our various non-human FAS accounts, our bugzilla account, etc.

Also discuss adding password complexity requirements to FAS. We currently only have a min length requirement of 8 - what's a good line between enforcing good passwords vs. putting too many restrictions?

Sorry I'm turning this into a dumping ground of ideas - but need to audit what FAS should send emails on

We need FAS to email notifications on yubikey changes and password resets or changes of any kind.

We decided to do prunings on sysadmin* groups per cycle. See:

As to a wider housecleaning on inactive accounts, perhaps we should ask the Board if this is something they would like us to do?

