<?xml version="1.0" encoding="utf-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: What about PWD_NOT_REQD??</title>
	<atom:link href="http://blog.joeware.net/2006/06/29/431/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.joeware.net/2006/06/29/431/</link>
	<description>Information about joeware mixed with wild and crazy opinions...</description>
	<lastBuildDate>Wed, 01 Sep 2010 22:02:17 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
	<item>
		<title>By: joe</title>
		<link>http://blog.joeware.net/2006/06/29/431/comment-page-1/#comment-2545</link>
		<dc:creator>joe</dc:creator>
		<pubDate>Sat, 08 Jul 2006 14:14:32 +0000</pubDate>
		<guid isPermaLink="false">http://blog.joeware.net/2006/06/29/431/#comment-2545</guid>
		<description>Matheesa:
Correct, the issue is that there really are no excuses or cases where an account shouldn&#039;t have a password. Having that bit set allows something that shouldn&#039;t occur... The malicious use occurs if someone takes advantage of not having to have a password.

Mike:
Could you send me more detail about what you mean in an email?</description>
		<content:encoded><![CDATA[<p>Matheesa:<br />
Correct, the issue is that there really are no excuses or cases where an account shouldn&#8217;t have a password. Having that bit set allows something that shouldn&#8217;t occur&#8230; The malicious use occurs if someone takes advantage of not having to have a password.</p>
<p>Mike:<br />
Could you send me more detail about what you mean in an email?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike Kline</title>
		<link>http://blog.joeware.net/2006/06/29/431/comment-page-1/#comment-2540</link>
		<dc:creator>Mike Kline</dc:creator>
		<pubDate>Fri, 07 Jul 2006 13:37:26 +0000</pubDate>
		<guid isPermaLink="false">http://blog.joeware.net/2006/06/29/431/#comment-2540</guid>
		<description>If we prestage computer accounts in a non Windows 2003 Functional level domain then will OldCmp not work because the pwdLastSet attribute is not populated.

Interesting blog as usual.

Thanks
Mike</description>
		<content:encoded><![CDATA[<p>If we prestage computer accounts in a non Windows 2003 Functional level domain then will OldCmp not work because the pwdLastSet attribute is not populated.</p>
<p>Interesting blog as usual.</p>
<p>Thanks<br />
Mike</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: matheesha</title>
		<link>http://blog.joeware.net/2006/06/29/431/comment-page-1/#comment-2536</link>
		<dc:creator>matheesha</dc:creator>
		<pubDate>Fri, 30 Jun 2006 21:22:49 +0000</pubDate>
		<guid isPermaLink="false">http://blog.joeware.net/2006/06/29/431/#comment-2536</guid>
		<description>OK. I just re-read that. Basically its only an issue if the password is not set and the flag PWD-NOT-REQD is set. In that case, its a user account with a blank password. If a password is set, there is no issue. But as best practice the flag should not be used.</description>
		<content:encoded><![CDATA[<p>OK. I just re-read that. Basically its only an issue if the password is not set and the flag PWD-NOT-REQD is set. In that case, its a user account with a blank password. If a password is set, there is no issue. But as best practice the flag should not be used.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: matheesha</title>
		<link>http://blog.joeware.net/2006/06/29/431/comment-page-1/#comment-2532</link>
		<dc:creator>matheesha</dc:creator>
		<pubDate>Fri, 30 Jun 2006 07:21:30 +0000</pubDate>
		<guid isPermaLink="false">http://blog.joeware.net/2006/06/29/431/#comment-2532</guid>
		<description>Thanks for the explanation joe. Could you possibly elaborate on if and how it could be used by someone maliciously?

Thanks

M@</description>
		<content:encoded><![CDATA[<p>Thanks for the explanation joe. Could you possibly elaborate on if and how it could be used by someone maliciously?</p>
<p>Thanks</p>
<p>M@</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Steve Kelly</title>
		<link>http://blog.joeware.net/2006/06/29/431/comment-page-1/#comment-2530</link>
		<dc:creator>Steve Kelly</dc:creator>
		<pubDate>Fri, 30 Jun 2006 03:32:47 +0000</pubDate>
		<guid isPermaLink="false">http://blog.joeware.net/2006/06/29/431/#comment-2530</guid>
		<description>When I look at our user accounts, most are set to this. I believe this is from the old NT 4 accounts that they were upgraded from. We do have a password policy. I am wondering how can I remove this flag from the user accounts? 

Thanks,

Steve</description>
		<content:encoded><![CDATA[<p>When I look at our user accounts, most are set to this. I believe this is from the old NT 4 accounts that they were upgraded from. We do have a password policy. I am wondering how can I remove this flag from the user accounts? </p>
<p>Thanks,</p>
<p>Steve</p>
]]></content:encoded>
	</item>
</channel>
</rss>
