
Chapter 7. Managing User Accounts and Passwords
210
NOTE
The password policy
must
be enabled globally before it will be applied locally. No
other global password policy features must be set, and the global password policy will
not override the local policy if they differ.
2. Create the local password policy for the subtree or user.
a. Select the
Directory
tab.
b. In the navigation pane, select the subtree or user entry for which to set up the password
policy.
c. From the
Object
menu, select the
Manage Password Policy
option, and then select the
For
user
or
For subtree
.
Either the
User Password Policy
or
Subtree Password Policy
window appears.
d. In the
Passwords
tab, select the
Create subtree/user level password policy
checkbox to
add the required attributes, fill in the appropriate values, and click
Save
.
e. In the
Account Lockout
tab, specify the appropriate information, and click
Save
.
7.1.1.3. Configuring a Global Password Policy Using the Command-Line
To set up the password policy for a subtree or user, add the required entries and attributes at the
subtree or user level, set the appropriate values to the password policy attributes, and enable fine-
grained password policy checking.
This section describes the attributes to create a password policy for the entire server (globally) using
ldapmodify
to change these attributes in the
cn=config
entry.
Table 7.1, “Password Policy Attributes”
describes the attributes available to configure the password
policy.
Attribute Name
Definition
passwordGraceLimit
This attribute indicates the number of grace
logins permitted when a user's password is
expired. When set to a positive number, the user
will be allowed to bind with the expired password
for that many times. For the global password
policy, the attribute is defined under
cn=config
.
By default, this attribute is set to
0
, which means
grace logins are not permitted.
passwordMustChange
When
on
, this attribute requires users to change
their passwords when they first login to the
directory or after the password is reset by the
Directory Manager. The user is required to
change their password even if user-defined
passwords are disabled. If this attribute is set
to
off
, passwords assigned by the Directory
Summary of Contents for DIRECTORY SERVER 8.0
Page 18: ...xviii ...
Page 29: ...Configuring the Directory Manager 11 6 Enter the new password and confirm it 7 Click Save ...
Page 30: ...12 ...
Page 112: ...94 ...
Page 128: ...110 ...
Page 190: ...Chapter 6 Managing Access Control 172 4 Click New to open the Access Control Editor ...
Page 224: ...206 ...
Page 324: ...306 ...
Page 334: ...316 ...
Page 358: ...340 ...
Page 410: ...392 ...
Page 420: ...402 ...
Page 444: ...426 ...
Page 454: ...436 ...
Page 464: ...446 ...
Page 484: ...466 ...
Page 512: ...494 ...
Page 522: ...504 ...