<?xml version="1.0" encoding="utf-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: securich</title>
	<atom:link href="http://mysqlpreacher.com/wordpress/securich/feed/" rel="self" type="application/rss+xml" />
	<link>http://mysqlpreacher.com/wordpress</link>
	<description>Because Sharing is Caring</description>
	<lastBuildDate>Thu, 12 Apr 2012 12:35:55 -0700</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.4</generator>
	<item>
		<title>By: Darren Cassar</title>
		<link>http://mysqlpreacher.com/wordpress/securich/comment-page-1/#comment-904</link>
		<dc:creator>Darren Cassar</dc:creator>
		<pubDate>Tue, 05 Oct 2010 19:16:20 +0000</pubDate>
		<guid isPermaLink="false">http://mysqlpreacher.com/wordpress/?page_id=173#comment-904</guid>
		<description>Good question Colin, there is a procedure called password_check which when called with update mysql.user to securich password and log the change in aud_password table so you know who is trying to change his password using mysql set password rather than securich version. With 0.2.5 there was a bug with securich set password which was fixed in 0.3 so you might want to consider the upgrade too.

If you set an event in mysql 5.1 to call the password_check stored proc every day it should be pretty annoying for the users to have to change it daily and if you see a recursive offender you can follow it up with policies etc

let me know if this doesn&#039;t answer your question.
don&#039;t hesitate to email me at info \a\t securich \d\o\t com if you have any issues,  comments, suggestions or feature requests</description>
		<content:encoded><![CDATA[<p>Good question Colin, there is a procedure called password_check which when called with update mysql.user to securich password and log the change in aud_password table so you know who is trying to change his password using mysql set password rather than securich version. With 0.2.5 there was a bug with securich set password which was fixed in 0.3 so you might want to consider the upgrade too.</p>
<p>If you set an event in mysql 5.1 to call the password_check stored proc every day it should be pretty annoying for the users to have to change it daily and if you see a recursive offender you can follow it up with policies etc</p>
<p>let me know if this doesn&#8217;t answer your question.<br />
don&#8217;t hesitate to email me at info \a\t securich \d\o\t com if you have any issues,  comments, suggestions or feature requests</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ColinF</title>
		<link>http://mysqlpreacher.com/wordpress/securich/comment-page-1/#comment-903</link>
		<dc:creator>ColinF</dc:creator>
		<pubDate>Tue, 05 Oct 2010 18:50:57 +0000</pubDate>
		<guid isPermaLink="false">http://mysqlpreacher.com/wordpress/?page_id=173#comment-903</guid>
		<description>Darren - I Installed Securich 2.5 a couple of months ago and have a couple of questions. How do you enforce usage of Securich, aside from password aging,
it seems users can ignore the fact that it is installed?

If I set a strong password using Securich, what is to prevent a user from using the
MySQL set password command to set it to something totally unsecure?</description>
		<content:encoded><![CDATA[<p>Darren &#8211; I Installed Securich 2.5 a couple of months ago and have a couple of questions. How do you enforce usage of Securich, aside from password aging,<br />
it seems users can ignore the fact that it is installed?</p>
<p>If I set a strong password using Securich, what is to prevent a user from using the<br />
MySQL set password command to set it to something totally unsecure?</p>
]]></content:encoded>
	</item>
</channel>
</rss>

