![Netscape NETSCAPE DIRECTORY SERVER 6.02 Administrator'S Manual Download Page 263](http://html1.mh-extra.com/html/netscape/netscape-directory-server-6-02/netscape-directory-server-6-02_administrators-manual_1674673263.webp)
Managing the Password Policy
Chapter
7
User Account Management
263
passwordWarning
Indicates the number of seconds before a warning message is sent to users
whose password is about to expire.
Depending on the LDAP client application, users may be prompted to
change their password when the warning is sent. Both Netscape Directory
Express and the Directory Server Gateway provide this functionality.
By default, the directory sends the warning 86400 seconds (1day) before the
password is about to expire. However, a password never expires until the
warning message has been set. Therefore, if users don’t bind to the
Directory Server for longer than the passwordMaxAge, they will still get
the warning message in time to change their password.
passwordCheckSyntax
When on, this attribute indicates that the password syntax will be checked
by the server before the password is saved.
Password syntax checking ensures that the password string meets or
exceeds the minimum password length requirements and that the string
does not contain any “trivial” words. A trivial word is any value stored in
the
uid
,
cn
,
sn
,
givenName
,
ou
, or
attributes of the user’s entry.
This attribute is
off
by default.
passwordMinLength
This attribute specifies the minimum number of characters that must be
used in passwords. Shorter passwords are easier to crack.
You can require passwords that are 2 to 512 characters long. Generally, a
length of 6 to 8 characters is long enough to be difficult to crack but short
enough for users to remember without writing it down.
This attribute is set to 6 by default.
passwordMinAge
This attribute indicates the number of seconds that must pass before a user
can change their password. Use this attribute in conjunction with the
passwordInHistory
attribute to discourage users from reusing old
passwords.
For example, setting the minimum password age to 2 days prevents users
from repeatedly changing their passwords during a single session to cycle
through the password history and reuse an old password once it has been
removed from the history list.
You can specify from 0 to 2147472000 seconds (24,855 days). A value of
zero indicates that the user can change the password immediately.
The default value of this attribute is
0
.
Table 7-1
Password Policy Attributes (Continued)
Attribute Name
Definition
Summary of Contents for NETSCAPE DIRECTORY SERVER 6.02
Page 1: ...Administrator s Guide Netscape Directory Server Version6 02 May 2002 ...
Page 16: ...16 Netscape Directory Server Administrator s Guide May 2002 ...
Page 20: ...20 Netscape Directory Server Administrator s Guide May 2002 ...
Page 74: ...Maintaining Referential Integrity 74 Netscape Directory Server Administrator s Guide May 2002 ...
Page 138: ...Using Referrals 138 Netscape Directory Server Administrator s Guide May 2002 ...
Page 432: ...Miscellaneous Tuning Tips 432 Netscape Directory Server Administrator s Guide May 2002 ...
Page 434: ...434 Netscape Directory Server Administrator s Guide May 2002 ...
Page 468: ...PTA Plug In Syntax Examples 468 Netscape Directory Server Administrator s Guide May 2002 ...
Page 488: ...488 Netscape Directory Server Administrator s Guide May 2002 ...
Page 528: ...Examples of LDAP URLs 528 Netscape Directory Server Administrator s Guide May 2002 ...