Enabling Password Control; Setting Global Password Control Parameters - HPE FlexNetwork 10500 Series Security Configuration Manual

Hide thumbs Also See for FlexNetwork 10500 Series:
Table of Contents

Advertisement

Tasks at a glance
(Optional.)
Setting local user password control parameters
(Optional.)
Setting super password control parameters

Enabling password control

To successfully enable the global password control feature and allow device management users to
log in to the device, the device must have sufficient storage space.
Enabling the global password control feature is the prerequisite for all password control
configurations to take effect. Then, for a specific password control feature to take effect, enable this
password control feature.
After the global password control feature is enabled, you cannot display the password and super
password configurations for device management users by using the corresponding display
commands. However, the configuration for network access user passwords can be displayed. The
first password configured for device management users must contain a minimum of four different
characters.
To ensure correct function of password control, configure the device to use NTP to obtain the UTC
time. After global password control is enabled, password control will record the UTC time when the
password is set. The recorded UTC time might not be consistent with the actual UTC time due to
power failure or device reboot. The inconsistency will cause the password expiration feature to
malfunction. For information about NTP, see Network Management and Monitoring Configuration
Guide.
To enable password control:
Step
1.
Enter system view.
2.
Enable the global password
control feature.
3.
(Optional.) Enable a specific
password control feature.

Setting global password control parameters

The password expiration time, minimum password length, and password composition policy can be
configured in system view, user group view, or local user view. The password settings with a smaller
application scope have higher priority. Global settings in system view apply to the passwords of the
local users in all user groups if you do not configure password policies for these users in both local
user view and user group view.
The password-control login-attempt command takes effect immediately and can affect the users
already in the password control blacklist. Other password control configurations do not take effect on
users that have been logged in or passwords that have been configured.
To set global password control parameters:
Command
system-view
password-control enable
password-control { aging |
composition | history | length }
enable
269
Remarks
N/A
In non-FIPS mode, the
global password control
feature is disabled by
default.
In FIPS mode, the global
password control feature is
enabled, and cannot be
disabled by default.
By default, all four password
control features are enabled.

Advertisement

Table of Contents
loading

Table of Contents