Team Security

Each team needs to take basic security precautions:

  1. Disable inactive teammate accounts after >3 months of inactivity
  2. Change passwords for shared root accounts every 6 months. For example, web panels with serial console access should have their passwords reset. This basic precaution helps security leaks.
    • Make sure to share the new passwords with your teammates!
  3. Check /etc/doas.conf, /etc/group, and /etc/master.passwd (use vipw only to prevent file corruption) to make sure that only authorized users are present