assurance - Re: [Assurance] Renewing an Expired authentication secret: 4.2.4.3
Subject: Assurance
List archive
- From: Eric Goodman <>
- To: "" <>
- Subject: Re: [Assurance] Renewing an Expired authentication secret: 4.2.4.3
- Date: Fri, 11 Jan 2013 23:52:58 +0000
- Accept-language: en-US
Hmm…
Typically a user will not change their password until it has actually expired and the system forces them to do so, human nature being what it is. E.g., if my login service tells me my password has expired (not "is going to" but "has") and forces me to
reset it immediately, the language below seems to indicate that my account is no longer Silver assurance compliant, since I used an expired password for my credential renewal. Thus I need to go through a more burdensome re-issuance process (and the login server
needs to track that that's how I did my password change to remove my Silver assertion).
It's a little fuzzy because the language in the intro refers to "in response to compromise", but the section seems to refer to any password change.
I don't expect that this is the intention for the common scenario, but that seems to be what's stated in the section.
--- Eric
From: David Walker <>
Reply-To: "" <> Date: Friday, January 11, 2013 10:20 AM To: "" <> Subject: Re: [Assurance] Renewing an Expired authentication secret: 4.2.4.3 Jeffrey,
The theory is that an expired password cannot be trusted sufficiently to authenticate the subject; it is no longer considered "current." (Otherwise, why would you have expired it in the first place?) So, yes, under the Silver profile, 4.2.4.3 requires use of one of the other methods to renew / re-issue a credential with an expired password. David Walker On Thu, 2013-01-10 at 15:09 +0000, Capehart,Jeffrey D wrote: Based on your reading of 4.2.4.3 for credential renewal… |
- [Assurance] Renewing an Expired authentication secret: 4.2.4.3, Capehart,Jeffrey D, 01/10/2013
- Re: [Assurance] Renewing an Expired authentication secret: 4.2.4.3, David Walker, 01/11/2013
- RE: [Assurance] Renewing an Expired authentication secret: 4.2.4.3, Dunker, Mary, 01/11/2013
- Re: [Assurance] Renewing an Expired authentication secret: 4.2.4.3, Eric Goodman, 01/11/2013
- Re: [Assurance] Renewing an Expired authentication secret: 4.2.4.3, David Walker, 01/13/2013
- RE: [Assurance] Renewing an Expired authentication secret: 4.2.4.3, Eric Goodman, 01/14/2013
- Re: [Assurance] Renewing an Expired authentication secret: 4.2.4.3, David Walker, 01/13/2013
- Re: [Assurance] Renewing an Expired authentication secret: 4.2.4.3, David Walker, 01/11/2013
Archive powered by MHonArc 2.6.16.