![Netscape NETSCAPE DIRECTORY SERVER 6.1 - ADMINISTRATOR Administrator'S Manual Download Page 267](http://html1.mh-extra.com/html/netscape/netscape-directory-server-6-1-administrator/netscape-directory-server-6-1-administrator_administrators-manual_1674675267.webp)
Managing the Password Policy
Chapter
7
User Account Management
267
passwordWarning
Indicates the number of seconds before a warning message is sent to users
whose password is about to expire.
Depending on the LDAP client application, users may be prompted to
change their password when the warning is sent. Both Netscape Directory
Express and the Directory Server Gateway provide this functionality.
By default, the directory sends the warning 86400 seconds (1day) before the
password is about to expire. However, a password never expires until the
warning message has been set. Therefore, if users don’t bind to the
Directory Server for longer than the passwordMaxAge, they will still get
the warning message in time to change their password.
passwordCheckSyntax
When on, this attribute indicates that the password syntax will be checked
by the server before the password is saved.
Password syntax checking ensures that the password string meets or
exceeds the minimum password length requirements and that the string
does not contain any “trivial” words. A trivial word is any value stored in
the
uid
,
cn
,
sn
,
givenName
,
ou
, or
attributes of the user’s entry.
This attribute is
off
by default.
passwordMinLength
This attribute specifies the minimum number of characters that must be
used in passwords. Shorter passwords are easier to crack.
You can require passwords that are 2 to 512 characters long. Generally, a
length of 6 to 8 characters is long enough to be difficult to crack but short
enough for users to remember without writing it down.
This attribute is set to 6 by default.
passwordMinAge
This attribute indicates the number of seconds that must pass before a user
can change their password. Use this attribute in conjunction with the
passwordInHistory
attribute to discourage users from reusing old
passwords.
For example, setting the minimum password age to 2 days prevents users
from repeatedly changing their passwords during a single session to cycle
through the password history and reuse an old password once it has been
removed from the history list.
You can specify from 0 to 2147472000 seconds (24,855 days). A value of
zero indicates that the user can change the password immediately.
The default value of this attribute is
0
.
Table 7-1
Password Policy Attributes (Continued)
Attribute Name
Definition
Summary of Contents for NETSCAPE DIRECTORY SERVER 6.1 - ADMINISTRATOR
Page 1: ...Administrator s Guide Netscape Directory Server Version6 1 August 2002...
Page 20: ...20 Netscape Directory Server Administrator s Guide August 2002...
Page 24: ...24 Netscape Directory Server Administrator s Guide August 2002...
Page 142: ...Using Referrals 142 Netscape Directory Server Administrator s Guide August 2002...
Page 440: ...Miscellaneous Tuning Tips 440 Netscape Directory Server Administrator s Guide August 2002...
Page 442: ...442 Netscape Directory Server Administrator s Guide August 2002...
Page 478: ...PTA Plug In Syntax Examples 478 Netscape Directory Server Administrator s Guide August 2002...
Page 498: ...498 Netscape Directory Server Administrator s Guide August 2002...
Page 538: ...Examples of LDAP URLs 538 Netscape Directory Server Administrator s Guide August 2002...