It has become clear that asking users to regularly change their passwords does not improve security, and has thus been forbidden e.g. by NIST and BSI.
Does this advice also apply for technical passwords for e.g. service accounts, that are used only for inter-application communication?
Reasons for:
- expecting regular changes for passwords can lead to mix-ups, sloppy handling (e.g. writing down old and new password for windows ctrl-alt-del dialogue)
Reasons against:
- these are professionals changing passwords in a clearly specified setting
kpasswd
from WSL)...