Managing the Password Policy
286
Red Hat Directory Server Administrator’s Guide • May 2005
Configuring Subtree/User Password Policy Using the Command-Line
To configure a subtree or user level password policy:
passwordHistory
This attribute indicates whether the directory stores a password history.
When set to
on
, the directory stores the number of passwords you specify
in the
passwordInHistory
attribute in a history. If a user attempts to
reuse one of the passwords, the password will be rejected.
When you set this attribute to
off
, any passwords stored in the history
remain there. When you set this attribute back to
on
, users will not be able
to reuse the passwords recorded in the history before you disabled the
attribute.
This attribute is
off
by default, meaning users can reuse old passwords.
passwordInHistory
This attribute indicates the number of passwords the directory stores in the
history. You can store from
2
to
24
passwords in the history. This feature is
not enabled unless the
passwordHistory
attribute is set to
on
.
This attribute is set to
6
by default.
passwordStorageScheme
This attribute specifies the type of encryption used to store Directory Server
passwords. The following encryption types are supported by Directory
Server:
•
SSHA
(Salted Secure Hash Algorithm). This method is recommended as
it is the most secure. This is the default method.
•
SHA
( Secure Hash Algorithm). A one-way hash algorithm; it is
supported only forbackwards compatibility with Directory Server 4.x
and should not be used otherwise.
•
crypt
. The UNIX crypt algorithm, provided for compatibility with
UNIX passwords.
•
clear
. This encryption type indicates that the password will appear in
plain text.
Passwords stored using
crypt
,
SHA
, or
SSHA
formats cannot be used for
secure login through SASL Digest MD5.
If you want to provide your own customized storage scheme, consult Red
Hat Professional Services.
Table 7-1
Password Policy Attributes
(Continued)
Attribute Name
Definition
Содержание DIRECTORY SERVER 7.1
Страница 1: ...Administrator s Guide Red Hat Directory Server Version7 1 May 2005 Updated February 2009 ...
Страница 20: ...20 Red Hat Directory Server Administrator s Guide May 2005 Glossary 619 Index 635 ...
Страница 22: ...22 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 26: ...26 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 78: ...Maintaining Referential Integrity 78 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 200: ...Assigning Class of Service 200 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 278: ...Compatibility with Earlier Releases 278 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 374: ...Troubleshooting Replication Related Problems 374 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 478: ...Using the Management Information Base 478 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 488: ...488 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 528: ...PTA Plug in Syntax Examples 528 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 545: ...About Windows Sync Chapter 18 Windows Sync 545 Figure 18 1 Active Directory Directory Server Synchronization Process ...
Страница 572: ...572 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 586: ...Storing Information in Multiple Languages 586 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 606: ...Searching an Internationalized Directory 606 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 612: ...Examples of LDAP URLs 612 Red Hat Directory Server Administrator s Guide May 2005 ...
Страница 634: ...634 Red Hat Directory Server Administrator s Guide May 2005 ...