HP 6125XLG R2306-HP 6125XLG Blade Switch Security Configuration Guide - Page 119

Setting user group password control parameters, Setting local user password control parameters

Page 119 highlights

Step 7. Set the maximum number of history password records for each user. Command password-control history max-record-num 8. Specify the maximum number of login attempts and the password-control login-attempt action to be taken when a login-times [ exceed { lock | user fails to log in after the lock-time time | unlock } ] specified number of attempts. 9. Set the number of days during which a user is notified of the password-control pending password expiration. alert-before-expire alert-time 10. Set the maximum number of days and maximum number of times that a user can log in after the password expires. password-control expired-user-login delay delay times times 11. Set the maximum account idle password-control login idle-time time. idle-time Remarks The default setting is 4. By default, the maximum number of login attempts is 3 and a user failing to log in after the specified number of attempts must wait for 1 minute before trying again. The default setting is 7 days. By default, a user can log in three times within 30 days after the password expires. The default setting is 90 days. Setting user group password control parameters Step Command Remarks 1. Enter system view. system-view N/A 2. Create a user group and enter user group view. user-group group-name By default, no user group exists. For information about how to configure a user group, see "Configuring AAA." 3. Configure the password expiration time for the user group. password-control aging aging-time By default, the password expiration time of the user group is the same as the global password expiration time. 4. Configure the minimum password length for the user group. password-control length length By default, the minimum password length of the user group is the same as the global minimum password length. 5. Configure the password composition policy for the user group. password-control composition type-number type-number [ type-length type-length ] By default, the password composition policy of the user group is the same as the global password composition policy. Setting local user password control parameters Step 1. Enter system view. Command system-view Remarks N/A 110

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276

110
Step
Command
Remarks
7.
Set the maximum number of
history password records for
each user.
password-control history
max-record-num
The default setting is 4.
8.
Specify the maximum number
of login attempts and the
action to be taken when a
user fails to log in after the
specified number of attempts.
password-control login-attempt
login-times
[
exceed
{
lock
|
lock-time
time
|
unlock
} ]
By default, the maximum number
of login attempts is 3 and a user
failing to log in after the specified
number of attempts must wait for 1
minute before trying again.
9.
Set the number of days during
which a user is notified of the
pending password expiration.
password-control
alert-before-expire
alert-time
The default setting is 7 days.
10.
Set the maximum number of
days and maximum number
of times that a user can log in
after the password expires.
password-control
expired-user-login delay
delay
times
times
By default, a user can log in three
times within 30 days after the
password expires.
11.
Set the maximum account idle
time.
password-control login idle-time
idle-time
The default setting is 90 days.
Setting user group password control parameters
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Create a user group and enter
user group view.
user-group
group-name
By default, no user group exists.
For information about how to
configure a user group, see
"
Configuring AAA
."
3.
Configure the password
expiration time for the user
group.
password-control aging
aging-time
By default, the password
expiration time of the user group is
the same as the global password
expiration time.
4.
Configure the minimum
password length for the user
group.
password-control length
length
By default, the minimum password
length of the user group is the same
as the global minimum password
length.
5.
Configure the password
composition policy for the
user group.
password-control composition
type-number
type-number
[
type-length
type-length
]
By default, the password
composition policy of the user
group is the same as the global
password composition policy.
Setting local user password control parameters
Step
Command
Remarks
1.
Enter system view.
system-view
N/A