- Password synchronization
Password synchronization is defined as any process or technology thathelps users to maintain a single password that is subject to a singlesecurity policy, and changes on a single schedule across multiple systems.
Password synchronization is an effective mechanism for addressing password management problems on an enterprise network:
* Users with synchronized passwords tend to remember their passwords.
* Simpler password management means that users make significantly fewer password-related calls to the help desk.
* Users with just one or two passwords are much less likely to write down their passwords.Password synchronization considered as easier to implement than enterprise single sign-on (SSO), as there is no client software deployment, and user enrollment can be automated.
Some (in particular those who sell single signon systems) claim that password synchronization is less secure than single signon, sincecompromise of one password means compromise of all. The counter-argument is that, with single signon, compromise of the primarypassword (from which an encryption key is derived and used to protect all other, stored passwords) also compromises all, so thesecurity of password synchronization and single signon is similar -- i.e., both systems depend strongly on the security of a single password, and that password must be well defended, regardless of such academic arguments.
Two types of password synchronization processes are commonly availablein commercial software:
* Transparent password synchronization, triggered by a password change on an existing system. The new password is automatically forwarded to other user objects that belong to the same user, on other systems (of the same or different types).
* Web-based password synchronization, initiated by the user with a web browser, in place of the existing native password change process. The web-based process allows the user to set multiple passwords at once.
Password synchronization is a type of
Identity management software.Those contemplating the deployment of a password synchronization system may benefit from this vendor-neutral white paper about how to run a project to deploy this type of software: [http://p-synch.com/docs/password-management-project-roadmap.html]
Wikimedia Foundation. 2010.