![Netscape NETSCAPE DIRECTORY SERVER 6.02 Administrator'S Manual Download Page 262](http://html1.mh-extra.com/html/netscape/netscape-directory-server-6-02/netscape-directory-server-6-02_administrators-manual_1674673262.webp)
Managing the Password Policy
262
Netscape Directory Server Administrator’s Guide • May 2002
Configuring the Password Policy Using the Command-Line
This section describes the attributes you set to create a password policy for your
server. Use ldapmodify to change these attributes in the
cn=config
entry.
Table 7-1 describes the attributes you can use to configure your password policy:
Table 7-1
Password Policy Attributes
Attribute Name
Definition
passwordMustChange
When
on
, this attribute requires users to change their passwords when
they first login to the directory or after the password is reset by the
Directory Manager. When
on
, the user is required to change their
password even if user-defined passwords are disabled.
If you choose to set this attribute to off, passwords assigned by the
Directory Manager should not follow any obvious convention and should
be difficult to discover.
This attribute is
off
by default.
passwordChange
When
on
, this attribute indicates that users may change their own
password. Choosing for users to set their own passwords runs the risk of
users choosing passwords that are easy to remember.
However, setting good passwords for the user requires a significant
administrative effort. In addition, providing passwords to users that are
not meaningful to them runs the risk that users will write the password
down somewhere that can be discovered.
This attribute is
on
by default.
passwordExp
When
on
, this attribute indicates that the user’s password will expire after
an interval given by the
passwordMaxAge
attribute. Making passwords
expire helps protect your directory data because the longer a password is in
use, the more likely it is to be discovered.
This attribute is
off
by default.
passwordMaxAge
This attribute indicates the number of seconds after which user passwords
expire. To use this attribute, you must enable password expiration using
the
passwordExp
attribute.
A common policy is to have passwords expire every 30 to 90 days. By
default, the password maximum age is set to 8640000 seconds (100days).
Summary of Contents for NETSCAPE DIRECTORY SERVER 6.02
Page 1: ...Administrator s Guide Netscape Directory Server Version6 02 May 2002 ...
Page 16: ...16 Netscape Directory Server Administrator s Guide May 2002 ...
Page 20: ...20 Netscape Directory Server Administrator s Guide May 2002 ...
Page 74: ...Maintaining Referential Integrity 74 Netscape Directory Server Administrator s Guide May 2002 ...
Page 138: ...Using Referrals 138 Netscape Directory Server Administrator s Guide May 2002 ...
Page 432: ...Miscellaneous Tuning Tips 432 Netscape Directory Server Administrator s Guide May 2002 ...
Page 434: ...434 Netscape Directory Server Administrator s Guide May 2002 ...
Page 468: ...PTA Plug In Syntax Examples 468 Netscape Directory Server Administrator s Guide May 2002 ...
Page 488: ...488 Netscape Directory Server Administrator s Guide May 2002 ...
Page 528: ...Examples of LDAP URLs 528 Netscape Directory Server Administrator s Guide May 2002 ...