Step
2.
Enable the global password
control feature.
3.
Enable a specific password
control function.
After global password control is enabled, local user passwords configured on the device are not
displayed when you use the corresponding display command.
Setting global password control parameters
The action specified the password-control login-attempt command takes effect immediately, and
thus affects the users already in the password control blacklist. Other password control
configurations take effect only for users logging in later and passwords configured later.
To set global password control parameters:
Step
1.
Enter system view.
2.
Set the password aging
time.
3.
Set the minimum password
update interval.
4.
Set the minimum password
length.
5.
Configure the password
composition policy.
6.
Configure the password
complexity checking policy.
7.
Set the maximum number of
history password records for
each user.
8.
Specify the maximum
number of login attempts
and the action to be taken
when a user fails to log in
after the specified number of
attempts.
Command
password-control enable
password-control { aging |
composition | history | length }
enable
Command
system-view
password-control aging
aging-time
password-control password
update interval interval
password-control length length
password-control composition
type-number type-number
[ type-length type-length ]
password-control complexity
{ same-character | user-name }
check
password-control history
max-record-num
password-control login-attempt
login-times [ exceed { lock |
lock-time time | unlock } ]
437
Remarks
By default, the global password
control feature is disabled.
Optional.
By default, all of the four
password control functions are
enabled.
Remarks
N/A
Optional.
The default setting is 90 days.
Optional.
The default setting is 24 hours.
Optional.
The default setting is 10
characters.
Optional.
•
In non-FIPS mode, a default
password must contain at
least one character type and
at least one character for
each type.
•
In FIPS mode, a default
password must contain four
character types and at least
one character for each type.
Optional.
By default, the system does not
perform password complexity
checking.
Optional.
The default setting is 4.
Optional.
By default, the maximum number
of login attempts is 3 and a user
failing to log in after the specified
number of attempts must wait for
1 minute before trying again.
Need help?
Do you have a question about the FlexNetwork MSR Series and is the answer not in the manual?