HP 6125XLG R2306-HP 6125XLG Blade Switch Security Configuration Guide - Page 121

Displaying and maintaining password control, Password control configuration example, Network

Page 121 highlights

Displaying and maintaining password control Execute display commands in any view and reset commands in user view. Task Display password control configuration. Display information about users in the password control blacklist. Delete users from the password control blacklist. Clear history password records. Command display password-control [ super ] display password-control blacklist [ user-name name | ip ipv4-address | ipv6 ipv6-address ] reset password-control blacklist [ user-name name ] reset password-control history-record [ user-name name | super [ role role name ] ] NOTE: The reset password-control history-record command can delete the history password records of one or all users even when the password history function is disabled. Password control configuration example Unless otherwise noted, devices in the configuration example are operating in non-FIPS mode. Network requirements Configure a global password control policy to meet the following requirements: • An FTP or VTY user failing to provide the correct password in two successive login attempts is permanently prohibited from logging in. • A user can log in 5 times within 60 days after the password expires. • A password must contain at least 16 characters. • A password expires after 30 days. • The minimum password update interval is 36 hours. • The maximum account idle time is 30 days. • A password cannot contain the username or the reverse of the username. • No character appears consecutively three or more times in a password. • A password must contain at least four character types and at least four characters for each type. Configure a super password control policy for user role network-operator to meet the following requirements: • A super password must contain at least 24 characters. • A super password must contain at least four character types and at least five characters for each type. Configure a password control policy for the local Telnet user test to meet the following requirements: • The password must contain at least 24 characters. • The password must contain at least four character types and at least five characters for each type. • The password for the local user expires after 20 days. 112

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276

112
Displaying and maintaining password control
Execute
display
commands in any view and
reset
commands in user view.
Task
Command
Display password control configuration.
display password-control
[
super
]
Display information about users in the
password control blacklist.
display password-control blacklist
[
user-name
name
|
ip
ipv4-address
|
ipv6
ipv6-address
]
Delete users from the password control
blacklist.
reset password-control blacklist
[
user-name
name
]
Clear history password records.
reset password-control history-record
[
user-name
name
|
super
[
role
role name
] ]
NOTE:
The
reset password-control history-record
command can delete the history password records of one or
all users even when the password history function is disabled.
Password control configuration example
Unless otherwise noted, devices in the configuration example are operating in non-FIPS mode.
Network requirements
Configure a global password control policy to meet the following requirements:
An FTP or VTY user failing to provide the correct password in two successive login attempts is
permanently prohibited from logging in.
A user can log in 5 times within 60 days after the password expires.
A password must contain at least 16 characters.
A password expires after 30 days.
The minimum password update interval is 36 hours.
The maximum account idle time is 30 days.
A password cannot contain the username or the reverse of the username.
No character appears consecutively three or more times in a password.
A password must contain at least four character types and at least four characters for each type.
Configure a super password control policy for user role
network-operator
to meet the following
requirements:
A super password must contain at least 24 characters.
A super password must contain at least four character types and at least five characters for each
type.
Configure a password control policy for the local Telnet user
test
to meet the following requirements:
The password must contain at least 24 characters.
The password must contain at least four character types and at least five characters for each type.
The password for the local user expires after 20 days.