Cisco Servers User Manual page 179

For windows 2000/nt servers
Table of Contents

Advertisement

Chapter 6
Setting Up and Managing User Groups
To allow users to log in an unlimited number of times without changing their
Tip
passwords, type -1.
The password aging rules are not mutually exclusive; a rule is applied for each
check box that is selected. For example, users can be forced to change their
passwords every 20 days, and every 10 logins, and to receive warnings and grace
periods accordingly.
If no options are checked, passwords never expire.
Unlike most other parameters, which have corresponding settings at the user level,
password aging parameters are configured only on a group basis.
Users who fail authentication because they have not changed their passwords and
have exceeded their grace periods are logged in the Failed Attempts log. The
accounts are expired and appear in the Accounts Disabled list.
Before You Begin
To set password aging rules for a user group, follow these steps:
In the navigation bar, click Group Setup.
Step 1
Result: The Group Setup Select page opens.
From the Group list, select a group, and then click Edit Settings.
Step 2
Result: The Group Settings page displays the name of the group at its top.
78-13751-01, Version 3.0
Apply password change rule—Selecting this check box forces new users to
change their password the first time they log in.
Generate greetings for successful logins—Selecting this check box enables
a "Greetings" message to display whenever users log in successfully via the
CAA client. The message contains up-to-date password information specific
to this user's account.
Verify that your AAA client is running the TACACS+ or RADIUS protocol.
(TACACS+ only supports password aging for device-hosted sessions.)
Set up your AAA client to perform authentication and accounting using the
same protocol, either TACACS+ RADIUS.
Set up your AAA client to use Cisco IOS Release 11.2.7 or later and to send
a watchdog accounting packet (aaa accounting new-info update) with the IP
address of the calling station.
Cisco Secure ACS 3.0 for Windows 2000/NT Servers User Guide
Configuration-specific User Group Settings
6-23

Advertisement

Table of Contents
loading

This manual is also suitable for:

Secure acs 3.0

Table of Contents