Q1. What is the problem that you are trying to solve?
As an administrator I want to be able to prompt my users to rotate their private key passphrase.
Original request:
Hello.
I think about some security feature - to push users in my instance to change their passphrase regularly. Does anybody know how to do it? Maybe some shell script? Or specialized command in CLI (I looked through the mail list and didn`t find something close).
Q2 - Who is impacted?
Administrator that needs to ask their users to rotate their passphrase.
Q3 - Why is it important and/or urgent?
This may be needed in case of security incident, such as passphrase disclosure.
Q4 - What is your proposed solution? (optional)
In the user workspace an administrator can select a user and request for a passphrase rotation. Passphrase rotation on the client side should trigger an event log on the user record.
Additionally an administrator can use additional settings, just like password expiry policy, where they can choose a policy to rotate passphrase after a given amount of time.
Q5. Community support
People can vote for this idea to show traction:
- Must have: this is critical for me to have this
- Should have: this is important for me to have this
- Could have: this could be nice to have
- Won’t have: we should not schedule this (explain why)