29.04.2019 Views

OS6860(E)_AOS_8.1.1.R01_Switch_Management_Guide

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Configuring Password Policy Settings<br />

Managing <strong>Switch</strong> User Accounts<br />

Configuring Password Policy Settings<br />

The global password policy settings for the switch define the following requirements that are applied to all<br />

user accounts:<br />

• Minimum password size.<br />

• Whether or not the password can contain the username.<br />

• The minimum number of uppercase characters required in a password.<br />

• The minimum number of uppercase characters required in a password.<br />

• The minimum number of base-10 digits required in a password.<br />

• The minimum number of non-alphanumeric characters (symbols) required in a password.<br />

• Passwords with non-alphanumeric characters must be enclosed in single quotes.<br />

• Password expiration.<br />

• The maximum number of old passwords that are saved in the password history.<br />

• The minimum number of days during which a user is not allowed to change their password.<br />

Password policy settings are applied when a password is created or modified. The following subsections<br />

describe how to configure these settings using CLI commands.<br />

To view the current policy configuration, use the show user password-policy command. For more information<br />

about this command and those used in the configuration examples throughout this section, see the<br />

Omni<strong>Switch</strong> CLI Reference <strong>Guide</strong>.<br />

Setting a Minimum Password Size<br />

To configure a minimum password size, enter the user password-size min command. For example:<br />

-> user password-size min 10<br />

The minimum length for any passwords configured for users is now 10 characters.<br />

Configuring the Username Password Exception<br />

Use the user password-policy cannot-contain-username command to block the ability to configure a<br />

password that contains the username. For example:<br />

-> user password-policy cannot-contain-username enable<br />

Enabling this functionality prevents the user from specifying the username in the password that is configured<br />

for the same user account. For example, the password for the account username of public can not<br />

contain the word public in any part of the password. However, the username of another account is still<br />

allowed.<br />

page 6-10 Omni<strong>Switch</strong> <strong>AOS</strong> Release 8 <strong>Switch</strong> <strong>Management</strong> <strong>Guide</strong> May 2014

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!