Operating System - HP-UX
1833115 Members
2937 Online
110051 Solutions
New Discussion

Alternative for PowerPassword and PowerBroker

 
Shabu Khan-2
Frequent Advisor

Alternative for PowerPassword and PowerBroker

Hi Folks,
I am looking for suggestions and ideas on alternate solutions for PowerPassword and PowerBroker.
We currently use PP/PB for our servers that are SOX/PCI (about 200 of them) but the management just decided to roll this solution out to all servers in the enterprise (~1000).
There are scalability issues with PP, we have had problems/hiccups if we go beyond 50 in a single domain, so even if we decide to architect/implement multiple PP domains managing these will turn out to be a nightmare and hence we are looking at other solutions.

I've read about idMI/HP Openview Select Access with LDAP?, but would like to hear more inputs and real-world experiences about it if any.

Also, how would you handle this situation? what product or products would you choose to implement in such a scenario and environment.

The idea is to have a centralized Account Management solution which would satisfy the SOX/PCI regulations - no direct app logins (root, oracle, app admin acounts etc), ftp/sftp only shells or chroot'ed envs etc to name a few ...

Feel free to respond with approach and solutions and earn 10 points :)

I appreciate your assistance.

Thanks,
Shabu
1 REPLY 1
Shabu Khan-2
Frequent Advisor

Re: Alternative for PowerPassword and PowerBroker


Any suggestions?