1-6
In this section, you must note the effective range of the same commands when executed in different
views or to different types of passwords:
z
Global settings in system view apply to all local user passwords and super passwords.
z
Settings in the local user view apply to the local user password only.
z
Settings on the parameters of the super passwords apply to super passwords only.
The priority of these settings is as follows:
z
For local user passwords, the settings in local user view override those in system view unless the
former are not provided.
z
For super passwords, the separate settings for super password override those in system view
unless the former are not provided.
Configuring History Password Recording
With this function enabled, when a login password expires, the system requires the user to input a new
password and save the old password automatically. You can configure the maximum number of history
records allowed for each user. The purpose is to inhibit the users from using one single password or
using an old password for a long time to enhance the security.
Table 1-4
Configure history password recording
Operation
Command
Description
Enter system view
system-view
—
Enable history password
recording
password-control history enable
Optional
By default, history password
recording is enabled.
Configure the maximum
number of the history
password records
password-control history
max-record-number
Optional
By default, the maximum
number is 4.
z
When the system adds a new record but the number of the recorded history passwords has
reached the configured maximum number, the system replaces the oldest record with the new
one.
z
When you configure the maximum number of history password records for a user, the excessive
old records will be lost if the number of the history password records exceeds the configured
number.
z
When changing a password, do not use the recorded history password; otherwise, the system will
prompt you to reset a password.
The system administrator can perform the following operations to manually remove history password
records.