贵公司如何做“企业”? 密码管理?

发布于 2024-07-07 16:32:42 字数 153 浏览 8 评论 0原文

We've talked about personal password management here but how do you guys manage your passwords at a company wide level?

如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。

扫码二维码加入Web技术交流群

发布评论

需要 登录 才能够评论, 你可以免费 注册 一个本站的账号。

评论(13

国粹 2024-07-14 16:32:42

我想我会在一周的搜索后报告...

我已经决定使用 PassPack 我我已经使用它作为我的个人密码几天了,我是它的忠实粉丝。

他们使用主机证明托管模式,因此唯一可以访问您的内容的人就是您如果您忘记密码,他们将无法帮助您。

他们有一些用 Adob​​e AIR 和 Google Gears 编写的不错的离线应用程序。

但是,最重要的是,它们符合我的“企业”要求,因为即将发布的版本将支持 在受信任的群组内共享

另外,我在他们的论坛中了解了“不必要的”引号的“博客”

I thought I'd report back after my week of searching...

I've settled on PassPack I've been using it for a few days now for my personal passwords and I'm a total fanboy.

They use the Host-Proof Hosting pattern so the only one that can access your stuff is you and if you forget your password they can't help you.

They have some nice Offline apps written with Adobe AIR and Google Gears.

But, best of all, they fit my "enterprise" requirement because an upcoming release will support sharing within a trusted group.

Plus, I learned about The "Blog" of "Unnecessary" Quotation Marks in their forum.

在巴黎塔顶看东京樱花 2024-07-14 16:32:42

我们已经成功地规划了我们公司的应用程序,因此它们主要是基于网络的、开源的或内部开发的。 然后,我们就可以使用 LDAP 连接到 Active Directory 来登录我们的 Intranet。 从那里,我们修改了我们使用的各种产品(MediaWiki、Wordpress、SugarCRM 等)的登录信息,以便如果用户在内联网中通过身份验证,他们也会自动登录到这些其他产品。

设置流程并创建脚本以在有人加入公司时在每个系统中设置所有适当的用户详细信息需要一些时间,但是现在我们遇到的情况是每个人只需要记住一个密码,从而无需管理不断增长的密码列表。

显然,这在许多公司中可能不可行,但现在我们已经设置好了,这是值得的。

We have managed to plan our company applications so they are mainly web based and open source or in-house developed. This then allowed us to use LDAP to hook into active directory for logging into our intranet. From there we modified the logins into various products we use (MediaWiki, Wordpress, SugarCRM etc.) so that if the user is authenticated in the intranet, they are automatically logged into these other products as well.

This has taken some time setting up the process and creating a script to set all the appropriate user details in each system when someone joins the company, however now we have a situation where everyone only has to remember one password, removing the need for managing a growing list of passwords.

Obviously this may not be viable in many companies, but now that we have it setup it was worth the effort.

绝不放开 2024-07-14 16:32:42

我们使用密码代理: http://www.moonsoftware.com/pwagent.asp

它存储从 PC 管理员登录到网站登录以及我们都使用的产品的产品密钥等一切内容。

We use Password Agent: http://www.moonsoftware.com/pwagent.asp

It stores everything from PC admin logins to website logins and product keys for products we all use.

梦萦几度 2024-07-14 16:32:42

我们使用 Active Directory 来存储用户凭据,并为桌面和 Web 开发了自定义库

We use Active Directory to store user credentials, and developed custom library for Desktop and Web

这个俗人 2024-07-14 16:32:42

我们正在成功使用 KeePass 应用程序。
我们为每个项目和/或每个业务领域创建文件。
我们在有权访问的人员之间共享相应 KeePass 文件的密码。

这不是最好的解决方案。 我们还在公司范围内安装了 Cyber​​-Ark 软件,但由于一些奇怪的配置规则,它对我们的作用不如以前的解决方案。 这也可能与我们使用旧版本有关。

We are using KeePass application with success.
We create file per project and/or per business domain.
We share the password to appropriate KeePass file between people who should have access.

It's not the best solution. We also have Cyber-Ark software installed corporate-wide, but due to some strange configuration rules it does not work for us as good as the previous solution. It might be also related to the fact that we have an old version.

不一样的天空 2024-07-14 16:32:42

我们维护一个内部 Lotus Notes 数据库,该数据库存储从密码到服务器更改记录的所有内容。 它又大又笨重,需要很长时间才能加载,而且通常不太好。

不,这不是一个明智的做法。 :-|

We maintain an in-house Lotus Notes database that stores absolutely everything from passwords to server change records. It is big, cumbersome, takes an age to load, and is generally not, uh, nice.

No, this is not a sane way to do it. :-|

一梦浮鱼 2024-07-14 16:32:42

显然我有偏见,因为我在那里工作,但我们使用 Lieberman Software 的企业随机密码管理器。 是的,我们实际上在自己的网络中测试了自己的工具。 它有一些不错的功能,例如带委派的 Web 可访问性、带重试的计划操作、使用帐户(服务、COM+ 应用程序等)传播到其他事物、系统/帐户发现、Linux/Unix 帐户管理等。

我确信销售人员可以提供更好的推销,但我不是。 我鼓励你去看看。 :)

Obviously I'm biased because I work there, but we use Enterprise Random Password Manager from Lieberman Software. Yes, we do actually dogfood our own tool in our own network. It has some nice features, like web accessibility with delegation, scheduled operation with retry, propagation to other things using accounts (services, COM+ apps, etc.), system/account discovery, Linux/Unix account management, etc.

I'm sure a salesperson could give a better pitch, but that I am not. I'd encourage you to check it out. :)

还在原地等你 2024-07-14 16:32:42

对于与我的工作相关的密码,我将它们存储在公司主文件服务器上用户存储区域中的普通未加密 passwords.txt 文件中。 一般情况下,公司其他人无法读取我的用户存储区中的文件,因此暴露的风险很小。 然而,如果我发生了什么事,那么我所有与公司相关活动的密码都会被公司内部的其他人轻易获得——只需询问 MIS 即可。

当然,这是一种与我用于个人密码的安全模型截然不同的安全模型。

For passwords related to my work, I store them in a plain unencrypted passwords.txt file in my user storage area on the main company file server. Normally, other people in the company can't read files in my user storage area, so there is little risk of exposure. However, if something were to happen to me, then all my passwords for company related activities would be trivially available to others inside the company - just ask MIS.

This is a very different security model than what I use for my personal passwords, of course.

A君 2024-07-14 16:32:42

请注意:Microsoft 有一款跨不同系统管理凭据/密码/身份的产品:Identity Lifecycle Manager

Just a heads up: Microsoft have a product managing credentials/passwords/identity across varied systems: Identity Lifecycle Manager

嘴硬脾气大 2024-07-14 16:32:42

Secret Server 是从内部需求(我们软件公司内部)发展成为现在在世界各地使用的可行产品。 它基于 Web,允许您存储密码,然后与其他用户和组(甚至 AD 用户和组)安全地共享它们。 它还能够按照自动计划主动联系并更改密码,甚至处理相关的依赖项,例如服务帐户的 Windows 服务。

企业密码管理(30 天免费试用)。

Secret Server is something that grew from an internal need (within our software company) to a viable product that is now used all over the world. It is web-based and allows you to store passwords and then securely share them with other users and groups (even AD users and groups). It is also able to actively reach out and change passwords on automatic schedules, even handling associated dependencies such as Windows Services for service accounts.

Enterprise Password Management (free 30 day trial).

口干舌燥 2024-07-14 16:32:42

使用 Apache Directory Server,这是一个 LDAP-标准实现。

您可以使用 Apache Directory Studio 管理目录数据库,因此它非常用户友好(或者至少对管理员友好)。

然后,您可以以编程方式将目录挂接到任何需要访问凭据的应用程序,LDAP 客户端库在流行的编程平台(如 Java、C++、PHP、Ruby 等)上广泛可用。

Use Apache Directory Server, which is an LDAP-standard implementation.

You can manage the directory database using Apache Directory Studio so it's quite user friendly (or at least, admin-friendly).

Then you can hook the directory programmatically to any application that requires access to the credentials, LDAP client libraries are widely available on popular programming platforms such as Java, C++, PHP, Ruby, etc.

国产ˉ祖宗 2024-07-14 16:32:42

我的商业朋友建议我查看 Passwork (https://passwork.me)。 他们在自己的服务器上使用自托管版本,我发现 Passwork 也有 SaaS。
所以我和我的同事将我们公司的密码存储在 Passwork 中。

我们之前曾尝试过另一位企业的密码经理,但无法信任他们。

My business friend adviced me to check out Passwork (https://passwork.me). They use self-hosted version on own servers, i found out that Passwork also has SaaS.
So i and my colleagues store our company passwords in Passwork.

We had tried another enterprise pw managers before but weren't able to trust them.

街道布景 2024-07-14 16:32:42

我们研究了具有以下功能的产品:

  • 可以使用角色授予密码访问权限。
  • 处理代表团。
  • 记录对密码的访问。
  • 可以随机化密码。
  • 可以在访问密码 X 天后自动重新随机化密码。

不幸的是,当我发布这篇文章时,我不能不知道它的名字......它是“秘密服务器”

We had a look at a product that had these features:

  • Can give access privleges to password using roles.
  • Handles delegation.
  • Logs access to passwords.
  • Can Randomize passwords.
  • Can automatically re-randomize a password X days after access to it.

Unfortunately, I can't couldn't it's name when I posted this... It was "Secret Server"

~没有更多了~
我们使用 Cookies 和其他技术来定制您的体验包括您的登录状态等。通过阅读我们的 隐私政策 了解更多相关信息。 单击 接受 或继续使用网站,即表示您同意使用 Cookies 和您的相关数据。
原文