Table 7-2 Account Lockout Policy Attributes - Red Hat DIRECTORY SERVER 7.1 - ADMINISTRATOR Administrator's Manual

Table of Contents

Advertisement

Table 7-2 describes the attributes you can use to configure your account lockout
policy.
Table 7-2
Account Lockout Policy Attributes
Attribute Name
passwordLockout
passwordMaxFailure
passwordLockoutDuration
passwordResetFailureCount
Definition
This attribute indicates whether users are locked out of the directory
after a given number of failed bind attempts. You set the number of
failed bind attempts after which the user will be locked out using the
passwordMaxFailure attribute.
You can lock users out for a specific time or until an administrator
resets the password.
This attribute is set to off by default, meaning that users will not be
locked out of the directory.
This attribute indicates the number of failed bind attempts after which
a user will be locked out of the directory.
This attribute takes affect only if the passwordLockout attribute is
set to on.
This attribute is set to 3 bind failures by default.
This attribute indicates the time, in seconds, that users will be locked
out of the directory. You can also specify that a user is locked out until
the password is reset by an administrator using the
passwordUnlock attribute.
By default, the user is locked out for 3600 seconds.
This attribute specifies the time, in seconds, after which the password
failure counter will be reset.
Each time an invalid password is sent from the user's account, the
password failure counter is incremented. If the passwordLockout
attribute is set to on, users will be locked out of the directory when the
counter reaches the number of failures specified by the
passwordMaxFailure attribute. The account is locked out for the
interval specified in the passwordLockoutDuration attribute, after
which time the failure counter is reset to zero (0).
Because the counter's purpose is to gauge when a hacker is trying to
gain access to the system, the counter must continue for a period long
enough to detect a hacker. However, if the counter were to increment
indefinitely over days and weeks, valid users might be locked out
inadvertently.
The reset password failure count attribute is set 600 seconds by
default.
Managing the Password Policy
Chapter 7
User Account Management
293

Advertisement

Table of Contents
loading

This manual is also suitable for:

Directory server 7.1

Table of Contents