Safeguard Reference Manual (G06.24+, H06.03+ )

Safeguard Subsystem Commands
Safeguard Reference Manual520618-013
16-8
ALTER SAFEGUARD Command
against that user ID. The initial value is OFF. (User IDs are not automatically
frozen.)
PASSWORD-HISTORY n
n defines the number of previous passwords to retain in a per-user-ID
password database. Any new password must be different from all the
previously retained passwords to be acceptable. The initial value is 0.
(Passwords are not subject to a history.)
PASSWORD-MINIMUM-LENGTH n
n defines the minimum character length of a new password. (Present
passwords are not affected.) The initial value is 0 and the maximum value is
eight.
PASSWORD-MAY-CHANGE [ n [ DAYS [ BEFORE-EXPIRATION ] ] ]
n defines the number of days before the password expiration date in which the
users can change their own password. If no password expiration date is in
effect, users can change their own password at any time. A value of 0 also
allows the password to be changed at any time. The default value is 0 (no
restrictions on password change date). A null entry for this attribute resets the
value to the default value.
If the PASSWORD-MAY-CHANGE period is greater than the PASSWORD-
MUST-CHANGE period in a user authentication record, that user’s password
can be changed at any time.
PASSWORD-REQUIRED { ON | OFF }
defines whether a password is required for a super ID or group manager ID to
log on as another user. The initial value is OFF. (No password is required.)
PASSWORD-EXPIRY-GRACE [ n [ DAYS ] ]
n defines the number of days after password expiration during which users can
change their expired passwords during logon. The default value is 0 (no
extension period). A null entry for this attribute resets the value to the default
value.
Caution. If you set AUTHENTICATE-FAIL-FREEZE ON, a user can freeze the user IDs of
others by attempting to log on with those other user names or user IDs.
Note. A password can be any length, including a null password. The initial value of
PASSWORD-MINIMUM-LENGTH is six only on systems running G06.29 and later
G-series RVUs and H06.06 and later H-series RVUs.
Note. The owner of a user authentication record can always change the password. After the
owner changes the password, the users can change their own password once before the
PASSWORD-MAY-CHANGE setting is effective.