Table 7-1 Password Policy Attributes - Netscape DIRECTORY SERVER 6.02 - ADMINISTRATOR Administrator's Manual

Table of Contents

Advertisement

Password Policy Attributes (Continued)
Table 7-1
Attribute Name
passwordWarning
passwordCheckSyntax
passwordMinLength
passwordMinAge
Definition
Indicates the number of seconds before a warning message is sent to users
whose password is about to expire.
Depending on the LDAP client application, users may be prompted to
change their password when the warning is sent. Both Netscape Directory
Express and the Directory Server Gateway provide this functionality.
By default, the directory sends the warning 86400 seconds (1day) before the
password is about to expire. However, a password never expires until the
warning message has been set. Therefore, if users don't bind to the
Directory Server for longer than the passwordMaxAge, they will still get
the warning message in time to change their password.
When on, this attribute indicates that the password syntax will be checked
by the server before the password is saved.
Password syntax checking ensures that the password string meets or
exceeds the minimum password length requirements and that the string
does not contain any "trivial" words. A trivial word is any value stored in
the uid, cn, sn, givenName, ou, or mail attributes of the user's entry.
This attribute is off by default.
This attribute specifies the minimum number of characters that must be
used in passwords. Shorter passwords are easier to crack.
You can require passwords that are 2 to 512 characters long. Generally, a
length of 6 to 8 characters is long enough to be difficult to crack but short
enough for users to remember without writing it down.
This attribute is set to 6 by default.
This attribute indicates the number of seconds that must pass before a user
can change their password. Use this attribute in conjunction with the
passwordInHistory attribute to discourage users from reusing old
passwords.
For example, setting the minimum password age to 2 days prevents users
from repeatedly changing their passwords during a single session to cycle
through the password history and reuse an old password once it has been
removed from the history list.
You can specify from 0 to 2147472000 seconds (24,855 days). A value of
zero indicates that the user can change the password immediately.
The default value of this attribute is 0.
Managing the Password Policy
Chapter 7
User Account Management
263

Advertisement

Table of Contents
loading

This manual is also suitable for:

Directory server 6.02

Table of Contents