
Managing the Password Policy
282
Red Hat Directory Server Administrator’s Guide • May 2005
8.
If you want users to change their passwords periodically, select the
“Password expires after X days” radio button, and then enter the number of
days that a user password is valid.
The maximum value for the password age is derived by subtracting January
18, 2038, from today’s date. The value you enter must not be set to the
maximum value or too close to the maximum value. If you set the value to the
maximum value, Directory Server may fail to start because the number of
seconds will go past the epoch date. In such an event, the error log will
indicate that the password maximum age is invalid. To resolve this problem,
you must correct the
passwordMaxAge
attribute value in the
dse.ldif
file.
A common policy is to have passwords expire every 30 to 90 days. By default,
the password maximum age is set to
8640000
seconds (100 days).
9.
If you have selected the “Password expire after X days” radio button, you
need to specify how long before the password expires to send a warning to
the user. In the “Send Warning X Days Before Password Expires” text enter
the number of days before password expiration to send a warning.
10.
If you want the server to check the syntax of a user password to make sure it
meets the minimum requirements set by the password policy, select the
“Check Password Syntax” checkbox. Then, specify the minimum acceptable
password length in the “Password Minimum Length” text box.
11.
From the “Password Encryption” pull-down menu, select the encryption
method you want the server to use when storing passwords.
For detailed information about the encryption methods, refer to the
passwordStorageScheme
attribute in Table 7-1, on page 283.
The Password Encryption menu might contain other encryption methods, as
the directory dynamically creates the menu depending upon the existing
encryption methods it finds in your directory.
12.
When you have finished making changes to the password policy, click Save.
Configuring a Subtree/User Password Policy Using the Console
To set up the password policy for a subtree or user, you need to add the required
entries and attributes at the subtree or user level, set the appropriate values to the
password policy attributes, and enable fine-grained password policy checking.
1.
Enable fine-grained password policy.
a.
In the Directory Server Console, select the Configuration tab.
b.
In the navigation tree, select the Data node.
Содержание DIRECTORY SERVER 7.1
Страница 1: ...Administrator s Guide Red Hat Directory Server Version7 1 May 2005 Updated February 2009 ...
Страница 20: ...20 Red Hat Directory Server Administrator s Guide May 2005 Glossary 619 Index 635 ...
Страница 22: ...22 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 26: ...26 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 78: ...Maintaining Referential Integrity 78 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 200: ...Assigning Class of Service 200 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 278: ...Compatibility with Earlier Releases 278 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 374: ...Troubleshooting Replication Related Problems 374 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 478: ...Using the Management Information Base 478 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 488: ...488 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 528: ...PTA Plug in Syntax Examples 528 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 545: ...About Windows Sync Chapter 18 Windows Sync 545 Figure 18 1 Active Directory Directory Server Synchronization Process ...
Страница 572: ...572 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 586: ...Storing Information in Multiple Languages 586 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 606: ...Searching an Internationalized Directory 606 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 612: ...Examples of LDAP URLs 612 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 634: ...634 Red Hat Directory Server Administrator s Guide May 2005 ...