Security
Polycom, Inc.
139
Changes to most password policy settings do not take effect until the next time the password is changed.
Changes take effect immediately for Minimum Password Age in Days, Maximum Password Age in
Days, and Password Expiration Warning. Changing Minimum Length from Off to some other value also
takes effect immediately.
Account Lockout
RealPresence Group systems provide access controls that prevent unauthorized use of the system. One
way someone might try to discover valid user names and passwords is by exhaustively attempting to log in,
varying the user name and password data in a programmatic way until discovering a combination that
succeeds. Such a method is called a “brute-force” attack.
To mitigate the risk of such an attack, two access control mechanisms are available on RealPresence Group
systems. The first type of access control, account lockout, protects local accounts from being vulnerable to
brute-force attacks, while the second, port lockout, protects login ports themselves from being vulnerable to
brute-force attacks. For more information about that mechanism, refer to
Port Lockout
.
Account lockout temporarily locks a local account from accepting logins after a configurable number of
unsuccessful attempts to log in to that account. It protects only the local RealPresence Group system’s
Admin and User local accounts. When external authentication is used, the Active Directory Server protects
Active Directory accounts.
RealPresence Group systems provide separate account lockout controls for each of their local accounts,
which are named Admin and User. The account lock can be invoked due to failed logins on any of the
following login ports:
●
Local interface
●
Web interface
Minimum Password Age in
Days
Specifies the minimum number of days that must pass before the password can
be changed.
Maximum Password Age in
Days
Specifies the maximum number of days that can pass before the password must
be changed.
Note: This setting is unavailable for Meeting and SNMP passwords.
Minimum Changed
Characters
Specifies the number of characters that must be different or change position in a
new password. If this is set to 3,
123abc
can change to
345cde
but not to
234bcd
.
Note: This setting is unavailable for Meeting and SNMP passwords.
Maximum Consecutive
Repeated Characters
Specifies the maximum number of consecutive repeated characters in a valid
password. If this is set to 3,
aaa123
is a valid password but
aaaa123
is not.
Password Expiration
Warning
Specifies how many days in advance the system displays a warning that the
password will soon expire, if a maximum password age is set.
Note: This setting is unavailable for Meeting and SNMP passwords.
Can Contain ID or Its
Reverse Form
Specifies whether the associated ID or the reverse of the ID can be part of a valid
password. If this setting is enabled and the ID is
admin
, passwords
admin
and
nimda
are allowed.
Note: This setting is unavailable for Meeting passwords.
Setting
Description