Chapter 7. Managing User Accounts and Passwords
214
Attribute Name
Definition
passwordMinUppers
This attribute sets the minimum number of
upper case alphabetic characters, A to Z, which
must be used in the password. By default, this
attribute is set to
0
, meaning there is no required
minimum.
passwordTokenLength
This attribute sets the minimum length for any
tokens used with Directory Server. The token
length can be from
1
to
64
characters. This
attribute is set to
3
by default.
passwordMin8bit
This attribute sets the minimum number of 8-
bit chracters used in the password. The default
number is
0
, meaning none are required.
passwordStorageScheme
This attribute specifies the type of encryption
used to store Directory Server passwords. The
following encryption types are supported by
Directory Server:
SSHA (Salted Secure Hash Algorithm).
This
method is recommended as it is the most secure.
The Directory Server supports
SSHA
,
SSHA-256
,
SSHA-384
, and
SSHA-512
. SSHA is the default
method.
SHA (Secure Hash Algorithm).
A one-way hash
algorithm; it is supported only for backwards
compatibility with Directory Server 4.x and
should not be used otherwise. This includes
support for
SHA
,
SHA-256
,
SHA-384
, and
SHA-512
algorithms, which protects against
some insecurities in the SHA-1 algorithm.
MD5.
MD5 is not as secure as SSHA but is
available for legacy applications require it.
crypt.
The UNIX crypt algorithm, provided for
compatibility with UNIX passwords.
clear.
This encryption type indicates that the
password will appear in plain text.
The only password storage scheme that can
be used with SASL DIGEST-MD5 is
CLEAR
.
Passwords stored using
crypt
,
SHA
, or
SSHA
formats cannot be used for secure login through
SASL Digest MD5. To provide a customized
storage scheme, consult Red Hat professional
services.
Table 7.1. Password Policy Attributes
7.1.1.4. Configuring Subtree/User Password Policy Using the Command-
Line
To configure a subtree or user level password policy, do the following:
Содержание DIRECTORY SERVER 8.0
Страница 18: ...xviii ...
Страница 29: ...Configuring the Directory Manager 11 6 Enter the new password and confirm it 7 Click Save ...
Страница 30: ...12 ...
Страница 112: ...94 ...
Страница 128: ...110 ...
Страница 190: ...Chapter 6 Managing Access Control 172 4 Click New to open the Access Control Editor ...
Страница 224: ...206 ...
Страница 324: ...306 ...
Страница 334: ...316 ...
Страница 358: ...340 ...
Страница 410: ...392 ...
Страница 420: ...402 ...
Страница 444: ...426 ...
Страница 454: ...436 ...
Страница 464: ...446 ...
Страница 484: ...466 ...
Страница 512: ...494 ...
Страница 522: ...504 ...