We are planing to implement Biometric authentication in our organization.
We would be using devices like USB fingerprint scanner connected to desktops, the corresponsing application will store the password only on local pcs.
For user authentication, the user would scan his finger and the sw (that comes with biomentric device) would translate his finger print into a password that would be sent across the network to server. So server hs no clue abt biometric device in place.
Can we use this mechanism to have non expiring user passwords, will this comply with sarbanes-oxley? Or do i need server based finger print SW?
Can someone please guide me into this as I am new to biometric world.
Thanks