Managing accounts, passwords, and authorizations

Just as with keys and certificates, accounts and passwords should be actively managed. Passwords used for remote access to IoT devices, or used to restrict operational IoT activities (for example, pub/sub message handling) should be rotated regularly. This is not possible using manual methods, so automation is key here. Tools, such as those from ForgeRock, provide options to enable automated account and password management.

ForgeRock allows you to pair their identity management platform with identity edge controllers that are installed on IoT devices. This pairing supports password policy enforcement, including password strength, age, and reuse, and supports dynamic authorization decisions ...

Get Practical Internet of Things Security - Second Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.