|
|
|
|
|
by rkeene2
825 days ago
|
|
Within the DOD the most common solutions are SSH keys using the CAC, Kerberos with PKINIT, or using some type of intermediate systems to handle the auth like CA PAM. There can still be a root password for emergencies, but it wouldn't be available for remote access -- ILOM or some other BMC (or even a serial port concentrator) would be configured for HSPD-12-compliant auth for remote console access, then you would use the root password for system access (though you could also just reboot into a separate operating system, since disk encryption isn't required except for mobile devices). I'm not sure what the above poster's command or organization was doing to comply with HSPD-12, but they were most likely doing something. The compliant reports are generally public, also. |
|