12.07.2015 Views

SECURING FIBRE CHANNEL FABRICS - Brocade

SECURING FIBRE CHANNEL FABRICS - Brocade

SECURING FIBRE CHANNEL FABRICS - Brocade

SHOW MORE
SHOW LESS
  • No tags were found...

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 8: Securing FOS-Based FabricsMinPasswordAge. The minimum number of days that must elapsebefore a user can change a password (0–999 days; default = 0). Settingthis parameter to a non-zero value discourages users from rapidlychanging a password in order to circumvent the password history settingto select a recently-used password.MaxPasswordAge. The maximum number of days that can elapsebefore a password must be changed, (0–999 days; default = 0).Warning. The number of days prior to password expiration that a warningabout password expiration is displayed. (0–999 days; default = 0).Example:switch:admin> passwdcfg --set -minpasswordage 7 -maxpasswordage 180 -warning 14This example sets a password expiration policy that specifies thatusers cannot change a password for 7 days after they set a passwordand must change their password after 180 days (a warning is sent tothem 14 days before their password is about to expire).Password lockout is used to disable an account after a series ofunsuccessful login attempts to prevent unauthorized users from enteringconsecutive password guesses until they guess the right one. Thefollowing lists the <strong>Brocade</strong> password lockout parameters:• LockoutThreshold. The number of times a user can attempt to login using an incorrect password before locking out the account (0–999; default = 0). Setting the lockout threshold to 0 (“zero”) disablesthe lockout policy.• LockoutDuration. The time in minutes after which a previouslylocked account is automatically unlocked (0–99999 minutes;default = 30). Setting the lockout duration to 0 (“zero”) requiresadministrative action to unlock the account.Example:switch:admin> passwdcfg --set -lockoutthreshold 5 -lockoutduration 0This example configures a password lockout policy that gives a user 5tries to enter the correct password and specified that once an accountis locked, it can only be unlocked by an administrator.The lockout policy can be used as a denial-of-service (DoS) attackwhen an attacker guesses a user password until the switch locks outthe account. Once the account is locked, then the authorized user isno longer able to access his account. The admin account is particularlyvulnerable to this type of attack and thus has a special policy. The140 Securing Fibre Channel Fabrics

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!