this post was submitted on 02 Apr 2025
51 points (98.1% liked)

Sysadmin

9013 readers
257 users here now

A community dedicated to the profession of IT Systems Administration

No generic Lemmy issue posts please! Posts about Lemmy belong in one of these communities:
[email protected]
[email protected]
[email protected]
[email protected]

founded 2 years ago
MODERATORS
 

From a simple KeePass database to enterprise credential management solutions—what’s your setup at work?

(page 2) 8 comments
sorted by: hot top controversial new old
[–] [email protected] 2 points 1 month ago

KeePassXC. We have an enterprise secret management product, but I don't think we're using this functionality yet.

[–] [email protected] 3 points 1 month ago (8 children)

I don't understand the extreme love for Bitwarden. I understand it's useful, but I want as few things with a webui and server instance as possible, especially passwords, the thing that should be most secure.

KeePass, vault saved into the user's One Drive synced folder is sufficient. It's secure, offline, and automatically makes backups. And migrates to the new system just by logging into One Drive.

Bitwarden and others worry me because they have a lot of exposed attack surface, comparatively, and require much more maintenance to keep secure imo. I don't want to expose any of that to a portal or anything.

That said, I don't hate Bitwarden, the bitwarden/vault warden software is incredibly solid for what it is.

load more comments (8 replies)
[–] [email protected] 3 points 1 month ago* (last edited 1 month ago) (4 children)

Personally, 1Password, but their enshittifaction is serious.

Work, Password Safe. But we’re moving to CyberArk.

[–] [email protected] 0 points 1 month ago (6 children)

Why do companies name their password safe "Password Safe"? Thats about as relevant as naming a phone "Phone".

load more comments (6 replies)
load more comments (3 replies)
[–] [email protected] 29 points 1 month ago

more dev than sysop, but: bitwarden

[–] [email protected] 11 points 1 month ago* (last edited 1 month ago)

We use Netwrix Password Secure at work. They just announced this week they have found a RCE vulnerability in their software...

[–] [email protected] 5 points 1 month ago* (last edited 1 month ago)

We have a KeePass DB as a fallback but mostly use a PAM solution to manage server access.

[–] [email protected] 8 points 1 month ago

We use PasswordState at work and KeePassXC for personal passwords.

load more comments
view more: ‹ prev next ›