19.12.2012 Views

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

IT Baseline Protection Manual - The Information Warfare Site

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Safeguard Catalogue - Hardware & Software Remarks<br />

____________________________________________________________________ .........................................<br />

S 4.46 Use of the log-on password under WfW and<br />

Windows 95<br />

Initiation responsibility: Administrators<br />

Implementation responsibility: <strong>IT</strong>-user<br />

If a new user logs on to a computer under WfW or Windows 95, he will be<br />

asked whether he would like to set up a code word list ([logonname].pwl)<br />

under his log-on name. This list will then record all the passwords which have<br />

to be transmitted by this user on connection with the resources of others.<br />

However, this only happens if this “caching“ of passwords on the computer is<br />

explicitly permitted and the user also desires it in individual cases.<br />

<strong>The</strong> WfW log-on password serves solely to protect this password list. Only on<br />

correct entry of the password belonging to the log-on name will this be<br />

decrypted and made available.<br />

<strong>Protection</strong> of the stored code words with respect to the users of the same<br />

computer is only guaranteed by an individual log-on password, particularly<br />

when a WfW or Windows 95 computer is utilised by several users.<br />

<strong>The</strong> respective password must be selected appropriately, changed regularly<br />

and deposited securely (see S 2.11 Provisions governing the use of passwords<br />

and S 2.22 Depositing of passwords).<br />

Notes:<br />

No log-on password is necessary under WfW if no passwords are stored in the<br />

password list by the user. <strong>The</strong>refore, if password caching is deactivated on<br />

principle by the administrator via ADMINCGF.EXE under WfW, or via the<br />

system guidelines under Windows 95, the log-on password is superfluous.<br />

Even masquerading on the PC cannot be prevented with this authentication<br />

mechanism as every password list may be renamed, the original log-on name<br />

may be re-used and the original password list may then be changed back<br />

again.<br />

However, if password caching is permitted and also used, the administrator<br />

must set the minimum length of the log-on password to 6 using<br />

ADMINCFG.EXE under WfW, or the system guidelines under Windows 95.<br />

<strong>The</strong>n entry of the password is obligatory when logging on under WfW and<br />

Windows 95 and cannot be deactivated. In exceptional cases, e.g. if the<br />

computer is only being utilised by one user and there is adequate access<br />

protection (BIOS password, screen lock, etc.), the log-on password may be<br />

deactivated. Deactivation is possible if the minimum length of the password is<br />

set to zero.<br />

If passwords are inadvertently stored in the password list by the user, the file<br />

[logonname].pwl must be deleted.<br />

Additional controls:<br />

- Will the WfW or Windows 95 users be told that, in addition to password<br />

protection on the PC (e.g. BIOS password), the log-on password is also<br />

necessary for protection of the individual password list under WfW or<br />

Windows 95?<br />

____________________________________________________________________ .........................................<br />

<strong>IT</strong>-<strong>Baseline</strong> <strong>Protection</strong> <strong>Manual</strong>: Oktober 2000

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!