Win2K Complex Password Enforcement

Win2K Complex Password Enforcement

Secure Home | Search | About
 Computer Software Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Win2K Complex Password Enforcement Mr. Security 08-01-2005
Posted by Mr. Security on August 1, 2005, 3:49 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Hey all,

I'm new to the group and had a quick question:

Anyone know how to fully enforce complex passwords (4 of 4 Uppercase,
Lowercase, Number, Special Char.) with Win2K. W2K will only
enforce/require 3 of the 4. Government standards require 4 of 4. Are
there .dll's out there I don't know about. I'm trying to avoid third party
software.

Any help/ideas is greatly appreciated.

KB


Posted by David H. Lipman on August 1, 2005, 4:30 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

| Hey all,
|
| I'm new to the group and had a quick question:
|
| Anyone know how to fully enforce complex passwords (4 of 4 Uppercase,
| Lowercase, Number, Special Char.) with Win2K. W2K will only
| enforce/require 3 of the 4. Government standards require 4 of 4. Are
| there .dll's out there I don't know about. I'm trying to avoid third party
| software.
|
| Any help/ideas is greatly appreciated.
|
| KB

Contact you associated Gov't. CERT or DOIM. They should have a support contract
with
Microsoft and should be able to provide any DLL to support such standards that
are set in
AR-25-2 or other Gov't. regulations.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm




Posted by Mr. Security on August 1, 2005, 4:58 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

>
>| Hey all,
>|
>| I'm new to the group and had a quick question:
>|
>| Anyone know how to fully enforce complex passwords (4 of 4 Uppercase,
>| Lowercase, Number, Special Char.) with Win2K. W2K will only
>| enforce/require 3 of the 4. Government standards require 4 of 4.
>| Are there .dll's out there I don't know about. I'm trying to avoid
>| third party software.
>|
>| Any help/ideas is greatly appreciated.
>|
>| KB
>
> Contact you associated Gov't. CERT or DOIM. They should have a
> support contract with Microsoft and should be able to provide any DLL
> to support such standards that are set in AR-25-2 or other Gov't.
> regulations.
>

Thanks...

We've installed the enpasflt.dll, but it hasn't solved our problem. My
tech just asked if this could be on conflict with the passfilt.dll used by
default. Looking at what else I could find online, this may be an issue.
Unless I'm mistaken, the group policy is what determines what .dll is used
(in rough terms). Is there a way to direct a policy to one .dll over
another?

Thanks again.

KB


Posted by David H. Lipman on August 3, 2005, 2:09 pm
If you were  Registered and logged in, you could reply and use other advanced thread options


| Thanks...
|
| We've installed the enpasflt.dll, but it hasn't solved our problem. My
| tech just asked if this could be on conflict with the passfilt.dll used by
| default. Looking at what else I could find online, this may be an issue.
| Unless I'm mistaken, the group policy is what determines what .dll is used
| (in rough terms). Is there a way to direct a policy to one .dll over
| another?
|
| Thanks again.
|
| KB

I don't know ... Sorry :-(

--
Dave
http://www.claymania.com/removal-trojan-adware.html
http://www.ik-cs.com/got-a-virus.htm




Posted by Catherder2000 on August 5, 2005, 9:41 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

>
> | Hey all,
> |
> | I'm new to the group and had a quick question:
> |
> | Anyone know how to fully enforce complex passwords (4 of 4 Uppercase,
> | Lowercase, Number, Special Char.) with Win2K. W2K will only
> | enforce/require 3 of the 4. Government standards require 4 of 4. Are
> | there .dll's out there I don't know about. I'm trying to avoid third
> party
> | software.
> |
> | Any help/ideas is greatly appreciated.
> |
> | KB
>
> Contact you associated Gov't. CERT or DOIM. They should have a support
> contract with
> Microsoft and should be able to provide any DLL to support such standards
> that are set in
> AR-25-2 or other Gov't. regulations.
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> http://www.ik-cs.com/got-a-virus.htm
>
>
The Password BBP allows you to use the maximum complexity settings in the
GPO as long as you use the maximum password length required by AR 25-2/BBP
is used and you require password changes not more than every 90 days (the
minimum allowed by AR 25-2).

I don't think a support contract with Microsoft will get you the
passfilt.dll you need, because it is not something you can just pick out of
a catalog (no money in that). NSA had a CD a few years ago that had a
passfilt.dll that had a minimum password length of 12 characters and
required characters from all four fields. The only CD I can find at the
moment is the one that has the 8 character version of the DLL. If I find
the other one I will let you know.

Have a nice day,
Catherder2000




Similar ThreadsPosted
Getting win2k admin password? October 27, 2005, 3:06 pm
win2k machine hacked with Serv-U FTP etc May 29, 2006, 11:37 pm
Simple security software for Win2k October 16, 2006, 9:49 pm
Re: Win2k Netstat sockets interpretation January 29, 2007, 6:20 am
"process deneid" running on win2k machine June 16, 2005, 6:16 pm
Re: Anti-malware on Win2K: Run as administrator or user February 4, 2006, 6:48 am
How to set a password on a cd/dvd? August 1, 2007, 4:11 am
Password Generator October 7, 2005, 7:24 am
Boot password November 2, 2005, 8:35 pm
SYSTEM PASSWORD November 16, 2005, 8:17 pm

The site map in XML format XML site map

Contact Us | Privacy Policy