HP 6125G HP 6125G & 6125G/XG Blade Switches Security Configuration Gui - Page 151

Setting global password control parameters

Page 151 highlights

• When global password control is enabled but the minimum password length restriction function is disabled, the minimum password length is four characters, and the password must have at least four different characters. • When global password control and the minimum password length restriction function are both enabled, the minimum password length is that configured by the password-control length length command. About password history control: • When global password control is disabled, or when global password control is enabled but the password history control is disabled, the device does not record history passwords and allows a user to set a new password the same as a previously used one. • When global password control and password history control are both enabled, the system records history passwords for users. When a user changes the password, the system compares the new password against the history passwords and the current password. The new password must be different from the used ones by at least four characters and the four characters must not be the same. Otherwise, the user will fail to change the password. Setting global password control parameters Step Command Remarks 1. Enter system view. system-view N/A Optional. 2. Set the password aging time. password-control aging aging-time 90 days by default. 3. Set the minimum password update interval. password-control password update interval interval Optional. 24 hours by default. 4. Set the minimum password length. password-control length length Optional. 10 characters by default. 5. Configure the password composition policy. password-control composition type-number policy-type [ type-length type-length ] Optional. By default, the minimum number of password composition types is 1 and the minimum number of characters of a password composition type is 1 too. 6. Configure the password complexity checking policy. password-control complexity { same-character | user-name } check Optional. By default, the system does not perform password complexity checking. 7. Set the maximum number of history password records for each user. password-control history max-record-num Optional. 4 by default. Optional. 8. Specify the maximum number of login attempts and the password-control login-attempt By default, the maximum number action to be taken when a login-times [ exceed { lock | unlock of login attempts is 3 and a user user fails to log in after the | lock-time time } ] failing to log in after the specified specified number of attempts. number of attempts must wait for one minute before trying again. 141

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285

141
When global password control is enabled but the minimum password length restriction function is
disabled, the minimum password length is four characters, and the password must have at least four
different characters.
When global password control and the minimum password length restriction function are both
enabled, the minimum password length is that configured by the
password-control length
length
command.
About password history control:
When global password control is disabled, or when global password control is enabled but the
password history control is disabled, the device does not record history passwords and allows a
user to set a new password the same as a previously used one.
When global password control and password history control are both enabled, the system records
history passwords for users. When a user changes the password, the system compares the new
password against the history passwords and the current password. The new password must be
different from the used ones by at least four characters and the four characters must not be the same.
Otherwise, the user will fail to change the password.
Setting global password control parameters
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Set the password aging time.
password-control aging
aging-time
Optional.
90 days by default.
3.
Set the minimum password
update interval.
password-control password
update interval
interval
Optional.
24 hours by default.
4.
Set the minimum password
length.
password-control length
length
Optional.
10 characters by default.
5.
Configure the password
composition policy.
password-control composition
type-number
policy-type
[
type-length
type-length
]
Optional.
By default, the minimum number of
password composition types is 1
and the minimum number of
characters of a password
composition type is 1 too.
6.
Configure the password
complexity checking policy.
password-control complexity
{
same-character
|
user-name
}
check
Optional.
By default, the system does not
perform password complexity
checking.
7.
Set the maximum number of
history password records for
each user.
password-control history
max-record-num
Optional.
4 by default.
8.
Specify the maximum number
of login attempts and the
action to be taken when a
user fails to log in after the
specified number of attempts.
password-control login-attempt
login-times
[
exceed
{
lock
|
unlock
| lock-time
time
} ]
Optional.
By default, the maximum number
of login attempts is 3 and a user
failing to log in after the specified
number of attempts must wait for
one minute before trying again.