Configuring The Password Policy Using The Command-Line - Netscape DIRECTORY SERVER 6.02 - ADMINISTRATOR Administrator's Manual

Table of Contents

Advertisement

Managing the Password Policy

Configuring the Password Policy Using the Command-Line

This section describes the attributes you set to create a password policy for your
server. Use ldapmodify to change these attributes in the
Table 7-1 describes the attributes you can use to configure your password policy:
Table 7-1
Password Policy Attributes
Attribute Name
passwordMustChange
passwordChange
passwordExp
passwordMaxAge
262
Netscape Directory Server Administrator's Guide • May 2002
Definition
When on, this attribute requires users to change their passwords when
they first login to the directory or after the password is reset by the
Directory Manager. When on, the user is required to change their
password even if user-defined passwords are disabled.
If you choose to set this attribute to off, passwords assigned by the
Directory Manager should not follow any obvious convention and should
be difficult to discover.
This attribute is off by default.
When on, this attribute indicates that users may change their own
password. Choosing for users to set their own passwords runs the risk of
users choosing passwords that are easy to remember.
However, setting good passwords for the user requires a significant
administrative effort. In addition, providing passwords to users that are
not meaningful to them runs the risk that users will write the password
down somewhere that can be discovered.
This attribute is on by default.
When on, this attribute indicates that the user's password will expire after
an interval given by the passwordMaxAge attribute. Making passwords
expire helps protect your directory data because the longer a password is in
use, the more likely it is to be discovered.
This attribute is off by default.
This attribute indicates the number of seconds after which user passwords
expire. To use this attribute, you must enable password expiration using
the passwordExp attribute.
A common policy is to have passwords expire every 30 to 90 days. By
default, the password maximum age is set to 8640000 seconds (100days).
entry.
cn=config

Advertisement

Table of Contents
loading

This manual is also suitable for:

Directory server 6.02

Table of Contents