22.12.2012 Views

Front cover - IBM Redbooks

Front cover - IBM Redbooks

Front cover - IBM Redbooks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

404 Lotus Security Handbook<br />

Setting user password options<br />

Table 9-2 lists recommended values for some security attributes related to user<br />

passwords. Password options are located in the /etc/usr/security file.<br />

This file can be edited to include any defaults that need to be defined in order to<br />

administer user passwords. Alternatively, the chsec command can be used (note<br />

that the values presented in the following table are taken from the <strong>IBM</strong> Redbook<br />

AIX Security Tools, SG24-XXXX).<br />

Table 9-2 Password options<br />

Attribute Description Recommended value<br />

dictionlist Verifies passwords do not include<br />

standard UNIX words<br />

histexpire Number of weeks before password can<br />

be reused<br />

histsize Number of password iterations allowed 20<br />

maxage Maximum number of weeks before<br />

password must be changed<br />

maxexpired Maximum number of weeks beyond<br />

maxagethat an expired password can be<br />

changed by the user<br />

maxrepeats Maximum number of characters that can<br />

be repeated in passwords<br />

minage Minimum number of weeks before a<br />

password can be changed<br />

minalpha Minimum number of alphabetic<br />

characters required on passwords<br />

mindiff Minimum number of unique characters<br />

that passwords must contain<br />

/usr/share/dict/words<br />

minlen Minimum length of password 6 (8 for root user)<br />

minother Minimum number of non-alphabetic<br />

characters required on passwords<br />

pwdwarntime Number of days before the system issues<br />

a warning that a password change is<br />

required<br />

26<br />

4<br />

2<br />

1<br />

2<br />

4<br />

2<br />

2<br />

5

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!