Password/Auth Security

Keep this at a level beyond simple user authentication that you use to log into your home windows PC and keep this focused around a higher level IT/SysAdmin discussion.

With more and more security issues coming up and most are related to password cracking, what methods do you IT people use to secure things such as Admin access to DC, root access to servers, network devices, etc.

I have been looking at certain Password keyring applications (http://keepass.info/index.html) that generate the uncrackable passwords using characters like ♀■£æΦ♠ and storing them into a program keyring. Anyone familar with these? I also am looking into securing SU privilages to root on some core linux servers using only correct keys.

Anyone else have methods they keep long passwords safe?

Password rotation…

Complex password phrases…

Disable LM hashes on windows…

I use E-Wallet to store passwords we also are putting some new product in place for SAS 70 compliance lets you give other admins access to certian passwords and audits when they get them.

ironkey.