FeatureFuel
1

Standardized API for automated unattended credentials/passwords change/renewal

Source: dani-garcia/vaultwarden#1691 · opened by @dumblob
Does anybody here know about any standard (or at least some example implementation to be followed if there is no standard) API between a service (e.g. some corporate CMS) and credential/secret/password managers (e.g. BitWarden client) allowing these managers to initiate credential change (independent from whether the user is currently logged in or not), make it happen (i.e. generate new credentials, submit them along with original credentials, etc.), and finally re-log in all existing sessions to maintain them without user noticing anything. All that without any user intervention (but with a notification that e.g. some user sessions could not be maintained because the password manager could not reach them which usually means there is an attacker with a parallel opened session). I've googled a bit and couldn't find anything. I'm really surprised because based on latest research user-facing credentials would need to be changed every 2 weeks to avoid biggest harm the…

No pledges yet. Be the first to back this.

Make a pledge

Pledge your monetary support if this feature is added.

$

Comments

No comments yet.

Replying to

Add a comment

What do you think about this feature request?


Similar requests