On Wed, Dec 23, 2020 at 12:06:25PM -0800, Michel Alexandre Salim wrote: > Maybe mandatory password/key rotation is an option? With your account > disabled after a grace period if the password is expired.
I'm not in favor of that -- I think it's generally not the best policy¹ and doesn't address the issue directly. 1. https://www.sans.org/security-awareness-training/blog/time-password-expiration-die -- Matthew Miller <mat...@fedoraproject.org> Fedora Project Leader _______________________________________________ devel mailing list -- devel@lists.fedoraproject.org To unsubscribe send an email to devel-le...@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/devel@lists.fedoraproject.org