Hello,
we currently do not allow to safe RDM User password for security Reasons.
Entering the password in RDM each time is petty annoying. Especially when you are using the Devolution Web Login Plugin. I would like to use the Plugin with DPS, but each time i want to auto fill a password it does not work because i have to enter the DPS Password first.
So why we do not allow to safe passwords? Our employee are IT Administrators which have Administrative access to our own Infrastructure. But they do not have access to all Passwords. Especially for Passwords in private Vault. (DPS Server is not part of the Domain.)
I have tested to safe the RDM Password on a Domain Joined Computer. Then i changed the Active Directory User Password for this User.
Next i logged in to the Computer with the Password i have set and opened RDM with the safed Password.
I expected that the stored credentials do not word and the password cache would be deleted because of this manipulation.
But RDM gave me access to all passwords for this user.
I think this can be avoided when you check the password hash of the current windows user. Or even bether wen you encrypt the RDM password with the Windows User password Hash.
When the User changes his password he have to retype the Password in RDM. But that's ok. You do not Change your Windows Password once a day.
Regards
Hello Thomas,
What data source type do you use?
Regards
David Hervieux
We use DPS Server only to prevent Users to see the complete database.
Hello,
I have opened a ticket for that.
Regards
David Hervieux
any news?
Hello,
I had a discussion with our Chief Security Officer and we need to ensure that any security concern follows a very strict procedure. Not doing so would may lead to revealing a zero-day vulnerability that would put our whole community at risk while we study, implement, and deploy a version that contains the fix.
We will transfer your case to our ticketing system as we have a lot of questions on your description.
For the sake of transparency, I will come post a reply to this topic when the case is closed.
Maurice