90 day passwords, with multiple internal sites & servers each needing unique ones? I don't understand why we don't have automated client certificates and auto-generated ssh keys.
90 day passwords, with multiple internal sites & servers each needing unique ones? I don't understand why we don't have automated client certificates and auto-generated ssh keys.
For example, in Conjur there is a suite of rotators (https://developer.conjur.net/reference/services/rotation) for rotating things like SSH keys, database passwords, and cloud credentials. In each case, the rotator changes the credential in the backend (e.g. changes the public key in the authorized_keys file), and then stores the new credential behind an access-controlled and audited API where only you (and other authorized roles) can fetch it.
Disclosure: I am CTO of Conjur.
https://github.com/Netflix/bless
http://gravitational.com/teleport
We have actually developed such a service for internal usage (could not use any of these three because of compliance requirements), it works very well.
As for the multiple internal sites and servers thing...well, from a security point of view I totally agree with the requirement for separate passwords but it sounds like you're in need of a proper identity management solution - which isn't really fair to blame security for - it's not usually the security function who are going to implement and own this sort of thing.
Even with the new NIST rec, I can't get him to back off on it, so sadly we'll be stuck on that for a while.
I really wish that had taken off (or, more accurately I guess, had a real business case).
As an industry we tout one set of rules/principles but then enforce a slightly different version.
My main passwords (the ones I have to remember, and not store) are all over 20 characters long and maximally complex and I change them very, very rarely.