HP 6125XLG R2306-HP 6125XLG Blade Switch Security Command Reference - Page 136

password-control { aging | composition | history | length } enable, Usage guidelines, Examples, Syntax

Page 136 highlights

ip ipv4-address: Specifies the IPv4 address of a user. ipv6 ipv6-address: Specifies the IPv6 address of a user. Usage guidelines With no arguments provided, this command displays information about all users in the password control blacklist. If an FTP or virtual terminal line (VTY) user fails authentication, the system adds the user to a password control blacklist. You can use this command to view information about these users in the blacklist. Users accessing the system through the console interface are not blacklisted, because the system is unable to obtain the IP addresses of these users and these users are privileged and therefore relatively secure to the system. Examples # Display information about users in the password control blacklist. display password-control blacklist Username: test IP: 192.168.44.1 Login failures: 1 Lock flag: unlock Blacklist items matched: 1. Table 16 Command output Field IP Login failed times Lock flag Blacklist items matched Description IP address of the user. Number of login failures. Whether the user is prohibited from logging in: • unlock-Not prohibited. • lock-Prohibited temporarily or permanently, depending on the password-control login-attempt command. Number of user entries in the blacklist. password-control { aging | composition | history | length } enable Use password-control { aging | composition | history | length } enable to enable the password expiration, composition restriction, history, or minimum length restriction function. Use undo password-control { aging | composition | history | length } enable to disable a specific password control function. Syntax password-control { aging | composition | history | length } enable undo password-control { aging | composition | history | length } enable Default The password control functions (aging, composition, history, and length) are all enabled. 127

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321

127
ip
ipv4-address
: Specifies the IPv4 address of a user.
ipv6
ipv6-address
: Specifies the IPv6 address of a user.
Usage guidelines
With no arguments provided, this command displays information about all users in the password control
blacklist.
If an FTP or virtual terminal line (VTY) user fails authentication, the system adds the user to a password
control blacklist. You can use this command to view information about these users in the blacklist.
Users accessing the system through the console interface are not blacklisted, because the system is
unable to obtain the IP addresses of these users and these users are privileged and therefore relatively
secure to the system.
Examples
# Display information about users in the password control blacklist.
<Sysname> display password-control blacklist
Username: test
IP: 192.168.44.1
Login failures: 1
Lock flag: unlock
Blacklist items matched: 1.
Table 16
Command output
Field
Description
IP
IP address of the user.
Login failed times
Number of login failures.
Lock flag
Whether the user is prohibited from logging in:
unlock
—Not prohibited.
lock
—Prohibited temporarily or permanently, depending on the
password-control login-attempt
command.
Blacklist items matched
Number of user entries in the blacklist.
password-control { aging | composition | history | length }
enable
Use
password-control
{
aging
|
composition
|
history
|
length
}
enable
to enable the password
expiration, composition restriction, history, or minimum length restriction function.
Use
undo password-control
{
aging
|
composition
|
history
|
length
}
enable
to disable a specific
password control function.
Syntax
password-control
{
aging
|
composition
|
history
|
length
}
enable
undo password-control
{
aging
|
composition
|
history
|
length
}
enable
Default
The password control functions (
aging
,
composition
,
history
, and
length
) are all enabled.