Setting Global Password Control Parameters - HP 12500 Series Configuration Manual

Routing
Table of Contents

Advertisement

After global password control is enabled, local user passwords configured on the device are not
displayed when you use the corresponding display command.

Setting global password control parameters

The action specified in the password-control login-attempt command takes effect immediately, and thus
affects the users already in the password control blacklist. Other password control configurations take
effect only on users logging in later and passwords configured later.
To set global password control parameters:
Step
1.
Enter system view.
2.
Set the password aging time.
3.
Set the minimum password
update interval.
4.
Set the minimum password
length.
5.
Configure the password
composition policy.
6.
Configure the password
complexity checking policy.
7.
Set the maximum number of
history password records for
each user.
8.
Specify the maximum number
of login attempts and the
action to be taken when a
user fails to log in after the
specified number of attempts.
9.
Set the number of days during
which the user is notified of
the pending password
expiration.
Command
system-view
password-control aging aging-time
password-control password
update interval interval
password-control length length
password-control composition
type-number policy-type
[ type-length type-length ]
password-control complexity
{ same-character | user-name }
check
password-control history
max-record-num
password-control login-attempt
login-times [ exceed { lock |
lock-time time | unlock } ]
password-control
alert-before-expire alert-time
149
Remarks
N/A
Optional.
The default setting is 90 days.
Optional.
The default setting is 24 hours.
Optional.
The default setting is 10
characters.
Optional.
In non-FIPS mode:
By default, a password must
contain at least one type of
characters and each type must
contain at least one character.
In FIPS mode:
A password must contain four
types of characters and each
type must contain at least one
character.
Optional.
By default, the system does not
perform password complexity
checking.
Optional.
The default setting is 4.
Optional.
By default, the maximum number
of login attempts is 3 and a user
failing to log in after the specified
number of attempts must wait for 1
minute before trying again.
Optional.
The default setting is 7 days.

Advertisement

Table of Contents
loading

Table of Contents