![Netscape NETSCAPE DIRECTORY SERVER 6.1 - ADMINISTRATOR Administrator'S Manual Download Page 270](http://html1.mh-extra.com/html/netscape/netscape-directory-server-6-1-administrator/netscape-directory-server-6-1-administrator_administrators-manual_1674675270.webp)
Managing the Password Policy
270
Netscape Directory Server Administrator’s Guide • August 2002
6.
Set the interval you want users to be locked out of the directory.
Select the Lockout Forever radio button to lock users out until their passwords
have been reset by the administrator.
Set a specific lockout period by selecting the Lockout duration radio button
and entering the time (in minutes) in the text box.
7.
When you have finished making changes to the account lockout policy, click
Save.
Configuring the Account Lockout Policy Using the Command Line
This section describes the attributes you set to create an account lockout policy to
protect the passwords stored in your server. Use ldapmodify to change these
attributes in the
cn=config
entry.
Table 7-2 describes the attributes you can use to configure your account lockout
policy.
Table 7-2
Account Lockout Policy Attributes
Attribute Name
Definition
passwordLockout
This attribute indicates whether users are locked out of the directory
after a given number of failed bind attempts. You set the number of
failed bind attempts after which the user will be locked out using the
passwordMaxFailure
attribute.
You can lock users out for a specific time or until an administrator
resets the password.
This attribute is set to
off
by default, meaning that users will not be
locked out of the directory.
passwordMaxFailure
This attribute indicates the number of failed bind attempts after which
a user will be locked out of the directory.
This attribute takes affect only if the
passwordLockout
attribute is
set to
on
.
This attribute is set to 3 bind failures by default.
passwordLockoutDuration
This attribute indicates the time, in seconds, that users will be locked
out of the directory. You can also specify that a user is lock out until
their password is reset by an administrator using the
passwordUnlock
attribute.
By default, the user is locked out for 3600 second.
Summary of Contents for NETSCAPE DIRECTORY SERVER 6.1 - ADMINISTRATOR
Page 1: ...Administrator s Guide Netscape Directory Server Version6 1 August 2002...
Page 20: ...20 Netscape Directory Server Administrator s Guide August 2002...
Page 24: ...24 Netscape Directory Server Administrator s Guide August 2002...
Page 142: ...Using Referrals 142 Netscape Directory Server Administrator s Guide August 2002...
Page 440: ...Miscellaneous Tuning Tips 440 Netscape Directory Server Administrator s Guide August 2002...
Page 442: ...442 Netscape Directory Server Administrator s Guide August 2002...
Page 478: ...PTA Plug In Syntax Examples 478 Netscape Directory Server Administrator s Guide August 2002...
Page 498: ...498 Netscape Directory Server Administrator s Guide August 2002...
Page 538: ...Examples of LDAP URLs 538 Netscape Directory Server Administrator s Guide August 2002...