Command Reference
204
ETEP CLI User Guide
When strong password enforcement is enabled, the Administrator can also modify the settings for
password expiration and maximum login sessions. If the last time the a user’s password was changed
exceeds the password expiration days, the ETEP will require the password to be reset before allowing
you to modify other user settings.
The valid values for the password expiration settings depend on the ETEP’s password enforcement policy,
as shown in
. These parameters are user-configurable only when strong password enforcement is
enabled.
The EncrypTight system supports the use of smart cards such as the DoD Common Access Card (CAC).
CACs provide user authorization in addition to certificate-based authentication. You need to add a
common name to a user account only if you are implementing this feature in your EncrypTight system.
To remove a common name from a user account, enter “none” as the common name attribute.
Related topics:
●
“Understanding User Roles” on page 21
●
“Password Enforcement Options” on page 17
●
●
“Enabling and Disabling Accounts” on page 29
Examples
This example changes the tech1 user’s role from ops to admin. Default password enforcement is in effect
on the ETEP.
user-config>
user-modify tech1 admin
In the next example the ETEP is configured for strong password enforcement. The Administrator changes
the tech1 Ops user warning days to 3. The password maximum is 60, and the password minimum is 3.
user-config>
user-modify tech1 ops
Maximum days before password expires [60]:
Minimum days between password reset [1]:
3
Password expiration warning days [10]:
3
Expiration grace period days [10]:
Maximum login sessions [2]:
The following example removes a common name from an Administrator user named dallas.
admin>
configure
config>
user-config
user-config>
user-modify dallas admin none
Table 79
Password enforcement values
Parameter
Default password
enforcement
Standard password
enforcement
Password expiration
99999 days
Default is 60. Range is 1-60.
Password reset minimum
0 days
Default is 1. Range is 1-7.
Password warning
7 days
Default is 10. Range is 1-30.
Password grace period
0 days
Default is 10. Range is 1-30.
Maximum login sessions
2 days
Default is 2. Range is 1-5.
Содержание ET0010A
Страница 7: ...8 ETEP CLI User Guide Contents...
Страница 15: ...Getting Started 16 ETEP CLI User Guide...
Страница 33: ...User Administration 34 ETEP CLI User Guide...
Страница 55: ...Configuring the ETEP 56 ETEP CLI User Guide...
Страница 97: ...Creating Policies 98 ETEP CLI User Guide...
Страница 101: ...Maintenance 102 ETEP CLI User Guide...
Страница 119: ...Troubleshooting 120 ETEP CLI User Guide...
Страница 123: ...FIPS 140 2 Level 2 Operation 124 ETEP CLI User Guide...
Страница 205: ...Command Reference 206 ETEP CLI User Guide...
Страница 211: ...Index 212 ETEP CLI User Guide...