What We’ve Done ...
Unified Name Space
- One UID, Account Name, and Password per User
- Owner Designated for Supplementary Accounts
- Personal Name on Email
Deployed Kerberos V5
- Password Aging to Populate - 57,000 Accounts
- Clients and Servers Installed on Central Systems
- Desktop Client Testing
- Evaluating Removing Unix Passwords
Notes:
Building a unified name space is critical to our security strategy. We want to ensure that each individual is identified uniquely in the population. We have architected a name space that represents the majority of the university population and have stored these principals in a Kerberos V5 system. Note that since we did not have an existing Kerberos V4 infrastructure, we were able to avoid many of the migration issues facing most K4 sites.