Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

PowerScale OneFS 9.2.1.0 CLI Administration Guide

PDF

Local password policy settings

You can configure local password policy settings and specify the default for each setting through the isi auth local modify command. Password complexity increases the number of possible passwords that an attacker must check before the correct password is guessed.

Setting Description Comments
min-password-length Minimum password length in characters. Long passwords are best. The minimum length should not be so long that users have a difficult time entering or remembering the password.
password-complexity A list of cases that a new password must contain. By default, the list is empty. You can specify as many as four cases. The following cases are valid:
  • uppercase
  • lowercase
  • numeric
  • symbol (excluding # and @)
min-password-age The minimum password age. You can set this value using characters for units; for example, 4W for 4 weeks, 2d for 2 Days. A minimum password age ensures that a user cannot enter a temporary password and then immediately change it to the previous password. Attempts to check or set a password before the time expires are denied.
max-password-age The maximum password age. You can set this value using characters for units; for example, 4W for 4 weeks, 2d for 2 Days. Attempts to login after a password expires forces a password change. If a password change dialog cannot be presented, the user is not allowed to login.
password-history-length The number of historical passwords to keep. New passwords are checked against this list and rejected if the password is already present. The max history length is 24. To avoid recycling of passwords, you can specify the number of previous passwords to remember. If a new password matches a remembered previous password, it is rejected.
lockout-duration The length of time in seconds that an account is locked after a configurable number of bad passwords are entered. After an account is locked, it is unavailable from all sources until it is unlocked. OneFS provides two configurable options to avoid administrator interaction for every locked account:
  • Specify how much time must elapse before the account is unlocked.
  • Automatically reset the incorrect-password counter after a specified time, in seconds.
lockout-threshold The number of incorrect password attempts before an account is locked. A value of zero disables account lockout. After an account is locked, it is unavailable from all sources until it is unlocked.
lockout-window The time that elapses before the incorrect password attempts count is reset. If the configured number of incorrect password attempts is reached, the account is locked and lockout-duration determines the length of time that the account is locked. A value of zero disables the window.

Rate this content

Accurate
Useful
Easy to understand
Was this article helpful?
0/3000 characters
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please select whether the article was helpful or not.
  Comments cannot contain these special characters: <>()\