Configuring The Password Policy Using The Command-Line - Netscape DIRECTORY SERVER 6.01 - ADMINISTRATOR Administrator's Manual

Table of Contents

Advertisement

Managing the Password Policy

Configuring the Password Policy Using the Command-Line

This section describes the attributes you set to create a password policy for your
server. Use ldapmodify to change these attributes in the
The following table describes the attributes you can use to configure your
password policy:
Table 7-1
Password Policy Attributes
Attribute Name
passwordMustChange
passwordChange
passwordExp
passwordMaxAge
260
Netscape Directory Server Administrator's Guide • January 2002
Definition
When on, this attribute requires users to change their passwords when they
first login to the directory or after the password is reset by the Directory
Manager. When on, the user is required to change their password even if
user-defined passwords are disabled.
If you choose to set this attribute to off, passwords assigned by the Directory
Manager should not follow any obvious convention and should be difficult to
discover.
This attribute is off by default.
When on, this attribute indicates that users may change their own password.
Choosing for users to set their own passwords runs the risk of users choosing
passwords that are easy to remember.
However, setting good passwords for the user requires a significant
administrative effort. In addition, providing passwords to users that are not
meaningful to them runs the risk that users will write the password down
somewhere that can be discovered.
This attribute is on by default.
When on, this attribute indicates that the user's password will expire after an
interval given by the passwordMaxAge attribute. Making passwords expire
helps protect your directory data because the longer a password is in use, the
more likely it is to be discovered.
This attribute is off by default.
This attribute indicates the number of seconds after which user passwords
expire. To use this attribute, you must enable password expiration using the
passwordExp attribute.
A common policy is to have passwords expire every 30 to 90 days. By default,
the password maximum age is set to 8640000 seconds (100days).
entry.
cn=config

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the NETSCAPE DIRECTORY SERVER 6.01 - ADMINISTRATOR and is the answer not in the manual?

Questions and answers

This manual is also suitable for:

Directory server 6.01

Table of Contents