HP 6125XLG R2306-HP 6125XLG Blade Switch Security Configuration Guide - Page 118

Setting global password control parameters - default password

Page 118 highlights

After the global password control feature is enabled, you cannot display the password and supper password configurations for device management users by using the corresponding display commands. However, the configuration for network access user passwords can be displayed. To enable password control: Step 1. Enter system view. 2. Enable the global password control feature. 3. (Optional.) Enable a specific password control function. Command system-view password-control enable password-control { aging | composition | history | length } enable Remarks N/A By default, the global password control feature is disabled. By default, all four password control functions are enabled. Setting global password control parameters The password expiration time, minimum password length, and password composition policy can be configured in system view, user group view, or local user view. The password settings with a smaller application scope have higher priority. Global settings in system view apply to the passwords of the local users in all user groups if you do not configure password policies for these users in both local user view and user group view. The password-control login-attempt command takes effect immediately and can affect the users already in the password control blacklist. Other password control configurations do not take effect on users that have been logged in or passwords that have been configured. To set global password control parameters: Step 1. Enter system view. 2. Set the password expiration time. 3. Set the minimum password update interval. 4. Set the minimum password length. 5. Configure the password composition policy. 6. Configure the password complexity checking policy. Command system-view Remarks N/A password-control aging aging-time The default setting is 90 days. password-control update interval interval password-control length length password-control composition type-number type-number [ type-length type-length ] password-control complexity { same-character | user-name } check The default setting is 24 hours. • In non-FIPS mode, the default length is 10 characters. • In FIPS mode, the default length is 15 characters. • In non-FIPS mode, a default password must contain at least one character type and at least one character for each type. • In FIPS mode, a default password must contain four character types and at least one character for each type. By default, the system does not perform password complexity checking. 109

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276

109
After the global password control feature is enabled, you cannot display the password and supper
password configurations for device management users by using the corresponding
display
commands.
However, the configuration for network access user passwords can be displayed.
To enable password control:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enable the global password
control feature.
password-control
enable
By default, the global password
control feature is disabled.
3.
(Optional.) Enable a specific
password control function.
password-control
{
aging
|
composition
|
history
|
length
}
enable
By default, all four password
control functions are enabled.
Setting global password control parameters
The password expiration time, minimum password length, and password composition policy can be
configured in system view, user group view, or local user view. The password settings with a smaller
application scope have higher priority. Global settings in system view apply to the passwords of the local
users in all user groups if you do not configure password policies for these users in both local user view
and user group view.
The
password-control login-attempt
command takes effect immediately and can affect the users already
in the password control blacklist. Other password control configurations do not take effect on users that
have been logged in or passwords that have been configured.
To set global password control parameters:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Set the password expiration
time.
password-control aging
aging-time
The default setting is 90 days.
3.
Set the minimum password
update interval.
password-control update interval
interval
The default setting is 24 hours.
4.
Set the minimum password
length.
password-control length
length
In non-FIPS mode, the default
length is 10 characters.
In FIPS mode, the default length
is 15 characters.
5.
Configure the password
composition policy.
password-control composition
type-number
type-number
[
type-length
type-length
]
In non-FIPS mode, a default
password must contain at least
one character type and at least
one character for each type.
In FIPS mode, a default
password must contain four
character types and at least
one character for each type.
6.
Configure the password
complexity checking policy.
password-control complexity
{
same-character
|
user-name
}
check
By default, the system does not
perform password complexity
checking.