290
C
HAPTER
13: P
ASSWORD
C
ONTROL
C
ONFIGURATION
O
PERATIONS
minimum password length (if available), the enable/disable state of history
password recording, the procession mode for login attempt failures, and the time
when the password history was last cleared.
If all the password attempts of a user fail, the system adds the user to the blacklist.
You can execute the display password-control blacklist command in any view to
check the names and the IP addresses of such users.
Configuring Password
Aging
To cancel the above configurations, you can use the corresponding undo
commands.
CAUTION:
You can configure the password aging parameters when password
aging is not yet enabled, but these parameters will not take effect.
After password aging is enabled, the device will decide whether the user password
ages out when a user logging into the system is undergoing the password
authentication. This has three cases:
■
The password has not expired and its remaining usable time is greater than the
configured alert time. In this case, the user log in successfully.
■
The password has not expired but its remaining usable time is no more than
the configured alert time. In this case, the system alerts the user to the
remaining time (in days) before the password expires and prompt the user to
change the password.
■
If the user chooses to change the password and change it successfully, the
system saves the new password, restarts the password aging procedure,
and at the same time allows the user to log in.
■
If the user chooses to change the password but fails to do so, or the user
chooses not to change the password, the system just allows the user to log
in.
■
The password has already expired. In this case, the system alerts the user to the
expiration, requires the user to change the password, and requires the user to
re-change the password if the user input an inappropriate password or the two
inputs are inconsistent.
Table 336
Configure Password Aging
Operation
Command
Description
Enter system view
system-view
Enable password aging
password-control
aging enable
By default, password aging is
enabled.
Set an aging time for super
passwords
password-control
super aging
aging-time
By default, it is 90 days.
Enable the system to alert
users to change their
passwords when their
passwords will soon expire,
and specify how many days
ahead of the expiration does
the system alert the users.
password-control
alert-before-expire
alert-time
By default, users are alerted
seven days ahead of the
password expiration.
Содержание 400 Family
Страница 12: ......
Страница 16: ...14 ABOUT THIS GUIDE ...
Страница 58: ...56 CHAPTER 2 PORT OPERATION ...
Страница 68: ...66 CHAPTER 3 VLAN OPERATION ...
Страница 98: ...96 CHAPTER 5 NETWORK PROTOCOL OPERATION ...
Страница 124: ...122 CHAPTER 6 IP ROUTING PROTOCOL OPERATION ...
Страница 156: ...154 CHAPTER 8 ACL CONFIGURATION ...
Страница 218: ...216 CHAPTER 11 802 1X CONFIGURATION ...
Страница 298: ...296 CHAPTER 13 PASSWORD CONTROL CONFIGURATION OPERATIONS ...
Страница 336: ...334 APPENDIX B RADIUS SERVER AND RADIUS CLIENT SETUP ...