slam - info.ornl.gov.ppt


文档分类:高等教育 | 页数:约15页 举报非法文档有奖
1/15
下载提示
  • 1.该资料是网友上传的,本站提供全文预览,预览什么样,下载就什么样。
  • 2.下载该文档所得收入归上传者、原创者。
  • 3.下载的文档,不会出现我们的网址水印。
1/15
文档列表 文档介绍
Lawrence Livermore National LaboratoryA system for strong local account FryeLawrence Livermore National Laboratory, P. O. Box 808, Livermore, CA 94551This work performed under the auspices of the . Department of Energy by Lawrence Livermore National Laboratory under Contract DE-AC52- Subject: Local Accounts?puters have a local account database?Allows people or code to authenticate locally?Enable access to resources locally?At least 1 administrator (full permissions)?Maintained independently?No linkage to Active Directory?No centralized managementUCRL: LLNL-PRES-413302The Problem: Common Passwords?Admin Password typically set build time?Typically the same on all machines (imaging)?Password is seldom if ever changed?Often neglected when joined to DomainUCRL: LLNL-PRES-413302The Problem: Illustrated? Typical AD Environment? Machines built from images? Local Administrator enabled? Password monUCRL: LLNL-PRES-413302The Problem: Illustrated? Machine hack = site hack?AD is immune? AD can’t helpHackerUCRL: LLNL-PRES-413302Disable Local Accounts??Offline without cached credentials?Temporary administration?Scientists on travel w/ need to install sw.?Dropped from domain?OS Virtualization?Re-enable via Recovery Console requires physical : LLNL-PRES-413302The Options: ?Disable all local accounts ?Best option?Not feasible in most environments?Deny “Access puter From work”?Force physical login?Kills remote management capability?Enabled accounts mon static passwords?Most typical?Most dangerous?Other mercial solutions (expensive)UCRL: LLNL-PRES-413302Strong Local Admin Manager (SLAM)UCRL: LLNL-PRES-413302How it puter Last Password Change Date + GUIDSHA-256 HMAC? Crypto-Random 256 bits? RSA 1024 bit encryptedLocal Administrator PasswordUCRL: LLNL-PRES-413302How it works:? OU Administrator uses AD Users & Computers (ADUC)? Custom Context Menu Option for SLAM Recovery? ADUC connects to Web Service & returns passwordUCRL: LLNL-PRES-41330

slam - info.ornl.gov 来自淘豆网m.daumloan.com转载请标明出处.

相关文档 更多>>
非法内容举报中心
文档信息
  • 页数15
  • 收藏数0 收藏
  • 顶次数0
  • 上传人薄荷牛奶
  • 文件大小0 KB
  • 时间2016-01-27
最近更新