MSAMM
Back to course

Oracle Apps DBA: Keeping E-Business Suite Alive · Module 9 · Users, responsibilities and access

Password policy, and what it is worth

Lesson 98 of 184 · 2 min

What EBS enforces, what it CANNOT, and where a policy that is TOO STRICT produces PASSWORDS ON NOTES UNDER KEYBOARDS. EBS enforces the mechanical properties: minimum length, expiry, reuse restrictions, failed-attempt lockout, and a check that the password is not the username. Those are configurable and they are worth setting. WHAT IT CANNOT ENFORCE IS EVERYTHING THAT ACTUALLY DETERMINES WHETHER A PASSWORD IS ANY GOOD. It cannot tell that a password is a dictionary word with a digit on the end, or the company name and the year, or last month's password with the number incremented. A policy demanding complexity is satisfied by exactly those, which is why a compliant estate can be full of guessable passwords. AND THAT IS THE WHOLE ARGUMENT AGAINST TIGHTENING FURTHER: THE RULES CONSTRAIN THE FORM AND NOT THE PREDICTABILITY. Every increment of strictness makes the compliant password more mechanical — which is more predictable,

The full lesson is part of the course

The video, the complete written lesson and the module quiz are included in Oracle Apps DBA: Keeping E-Business Suite Alive, with a certificate on completion and a fourteen-day refund window.

Get the free lessons by email

We will email you a link to every free lesson in this course. No account needed, and one message only.

In this module: Module 9 · Users, responsibilities and access

  1. 1Users, responsibilities and menus
  2. 2Why a user cannot see a function
  3. 3Operating units and access
  4. 4End-dating rather than deleting
  5. 5The requests you should refuse
  6. 6Password policy, and what it is worth
  7. 7Single sign-on, briefly
  8. 8What breaks: three access failures
  9. 9Lab briefing · Diagnose four access complaints
Password policy, and what it is worth — Oracle Apps DBA: Keeping E-Business Suite Alive — MSAMM