HP 6125XLG R2306-HP 6125XLG Blade Switch Security Configuration Guide - Page 120

Setting super password control parameters

Page 120 highlights

Step Command Remarks By default, no local user exists. Local user password control applies to device management 2. Create a device management user and enter local user view. local-user user-name class manage users instead of network access users. For information about how to configure a local user, see "Configuring AAA." 3. Configure the password expiration time for the local user. password-control aging aging-time By default, the setting equals that for the user group to which the local user belongs. If no expiration time is configured for the user group, the global setting applies to the local user. 4. Configure the minimum password length for the local password-control length length user. By default, the setting equals that for the user group to which the local user belongs. If no minimum password length is configured for the user group, the global setting applies to the local user. 5. Configure the password composition policy for the local user. password-control composition type-number type-number [ type-length type-length ] By default, the settings equal those for the user group to which the local user belongs. If no password composition policy is configured for the user group, the global settings apply to the local user. Setting super password control parameters Step 1. Enter system view. 2. Set the password expiration time for super passwords. Command system-view password-control super aging aging-time 3. Configure the minimum length password-control super length for super passwords. length 4. Configure the password composition policy for super passwords. password-control super composition type-number type-number [ type-length type-length ] Remarks N/A The default setting is 90 days. • In non-FIPS mode, the default length is 10 characters. • In FIPS mode, the default length is 15 characters. • In non-FIPS mode, a default super password must contain at least one character type and at least one character for each type. • In FIPS mode, a default super password must contain four character types and at least one character for each type. 111

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276

111
Step
Command
Remarks
2.
Create a device management
user and enter local user view.
local-user
user-name
class manage
By default, no local user exists.
Local user password control
applies to device management
users instead of network access
users.
For information about how to
configure a local user, see
"
Configuring AAA
."
3.
Configure the password
expiration time for the local
user.
password-control aging
aging-time
By default, the setting equals that
for the user group to which the
local user belongs. If no expiration
time is configured for the user
group, the global setting applies to
the local user.
4.
Configure the minimum
password length for the local
user.
password-control length
length
By default, the setting equals that
for the user group to which the
local user belongs. If no minimum
password length is configured for
the user group, the global setting
applies to the local user.
5.
Configure the password
composition policy for the
local user.
password-control composition
type-number
type-number
[
type-length
type-length
]
By default, the settings equal those
for the user group to which the
local user belongs. If no password
composition policy is configured
for the user group, the global
settings apply to the local user.
Setting super password control parameters
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Set the password expiration
time for super passwords.
password-control super aging
aging-time
The default setting is 90 days.
3.
Configure the minimum length
for super
passwords.
password-control super length
length
In non-FIPS mode, the default
length is 10 characters.
In FIPS mode, the default length
is 15 characters.
4.
Configure the password
composition policy for super
passwords.
password-control super
composition type-number
type-number
[
type-length
type-length
]
In non-FIPS mode, a default
super password must contain at
least one character type and at
least one character for each
type.
In FIPS mode, a default super
password must contain four
character types and at least
one character for each type.