3Com Switch 8800 Advanced Software V5 Configuration Guide
74
PASSWORD CONTROL CONFIGURATION
When configuring password control, go to these sections for information you are
interested in:
■ “Password Control Overview” on page 973
■ “Password Control Configuration Task List” on page 975
■ “Configuring Password Control” on page 975
■ “Displaying and Maintaining Password Control” on page 978
■ “Password Control Configuration Example” on page 978
Password Control
Overview
Password control refers to a set of functions provided by the local authentication
server to achieve password security based on predefined policies. The password
control functions include the following nine.
1 Minimum password length
With this function, you can set a minimum password length as required for system
security. As such, when a user enters a shorter password, the system considers it
invalid and prompts the user to re-enter a password.
n
A password cannot exceed 63 characters.
2 Password aging
Password aging imposes a lifecycle on a user password. After the password aging
time expires, the user needs to change the password.
If a user enters an expired password, the system displays an error message and
prompts the user to provide a new password and to confirm it by entering it again.
The new password must be a valid one and the user must enter exactly the same
password when confirming it. Otherwise, the login will fail.
3 Early notice on pending password expiration
When a user logs in, the system checks whether the password will expire in a time
equal to or less than the specified period. If so, the system notifies the user of the
expiry time and provides a choice for the user to change the password. If the user
provides a new password, the system records the new password and the time. If
the user chooses to leave the password or the user fails to change it, the system
allows the user to log in using the present password until the password expires.
n
Telnet, SSH, and terminal users can change their passwords by themselves. FTP
users, on the contrary, can only have their passwords changed by the
administrator.