168
To do…
Use the command…
Remarks
Set the minimum password
update interval
password-control password
update interval
interval
Optional
24 hours by default
Set the minimum password length
password-control length
length
Optional
10 characters by default
Configure the password
composition policy
password-control composition
type-number
policy-type
[
type-
length
type-length
]
Optional
By default, the minimum number
of password composition types is
1 and the minimum number of
characters of a password
composition type is 1 too.
Configure the password
complexity checking policy
password-control complexity
{
same-character
|
user-name
}
check
Optional
By default, the system does not
perform password complexity
checking.
Set the maximum number of
history password records for each
user
password-control history
max-
record-num
Optional
4 by default
Specify the maximum number of
login attempts and the action to
be taken when a user fails to log
in after the specified number of
attempts
password-control login-attempt
login-times
[
exceed
{
lock
|
unlock | lock-time
time
|
unlock
}
]
Optional
By default, the maximum number
of login attempts is 3 and a user
failing to log in after the specified
number of attempts must wait for
one minute before trying again.
Set the number of days during
which the user is warned of the
pending password expiration
password-control alert-before-
expire
alert-time
Optional
7 days by default
Set the maximum number of days
and maximum number of times
that a user can log in after the
password expires
password-control expired-user-
login delay
delay
times
times
Optional
By default, a user can log in three
times within 30 days after the
password expires.
Set the authentication timeout time
password-control authentication-
timeout
authentication-timeout
Optional
60 seconds by default
Set the maximum account idle
time
password-control login idle-time
idle-time
Optional
90 days by default
CAUTION:
The specified action to be taken after a user fails to log in for the specified number of attempts takes
effect immediately, and can affect the users already in the blacklist. Other configurations take effect
only for users logging in later and passwords configured later.
Setting user group password control parameters
Follow these steps to set password control parameters for a user group: