If the password is already encrypted and not a plaintext password, this meets this requirement. ![]() When the application is publicly available and or hosting publicly releasable data requiring some degree of need-to-know protection. When a user has been officially designated as temporarily unable to present a CAC for some reason (lost, damaged, not yet issued, broken card reader) (i.e., Temporary Exception User) and to satisfy urgent organizational needs must be temporarily permitted to use user ID/password authentication until the problem with CAC use has been remedied. When the user does not use a CAC and is not a current DoD employee, member of the military, or DoD contractor. Use of passwords for authentication is intended only for limited situations and should not be used as a replacement for two-factor CAC-enabled authentication.Įxamples of situations where a user ID and password might be used include: If passwords are not encrypted, they can be plainly read and easily compromised. ![]() Passwords need to be protected at all times, and encryption is the standard method for protecting passwords. The Apache Tomcat Manager Web app password is stored in plain text in CATALINA_HOME/conf/tomcat-users.xml and should be encrypted so it is not visible to an intruder.
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |