10.02.2013 Views

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

IBM Tivoli Access Manager for e-business: WebSEAL Administration ...

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Configuring<br />

password<br />

strength<br />

policy<br />

Password<br />

strength<br />

policy<br />

refers<br />

to<br />

the<br />

stipulations<br />

placed<br />

on<br />

the<br />

construction<br />

of<br />

a<br />

password<br />

by<br />

password<br />

policy<br />

rules.<br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

provides<br />

two<br />

means<br />

of<br />

controlling<br />

password<br />

strength<br />

policy:<br />

v<br />

Five<br />

pdadmin<br />

password<br />

policy<br />

commands<br />

v<br />

You<br />

can<br />

write<br />

a<br />

customized<br />

authentication<br />

module<br />

to<br />

en<strong>for</strong>ce<br />

your<br />

password<br />

policy<br />

Refer<br />

to<br />

the<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

<strong>for</strong><br />

e-<strong>business</strong><br />

Web<br />

Security<br />

Developer<br />

Reference.<br />

Password<br />

strength<br />

policy<br />

set<br />

by<br />

the<br />

pdadmin<br />

utility<br />

The<br />

five<br />

password<br />

strength<br />

attributes<br />

implemented<br />

through<br />

the<br />

pdadmin<br />

utility<br />

include:<br />

v<br />

Minimum<br />

password<br />

length<br />

v<br />

Minimum<br />

alphabetic<br />

characters<br />

v<br />

Minimum<br />

non-alphabetic<br />

characters<br />

v<br />

Maximum<br />

repeated<br />

characters<br />

v<br />

Spaces<br />

allowed<br />

These<br />

policies<br />

are<br />

en<strong>for</strong>ced<br />

when<br />

you<br />

create<br />

a<br />

user<br />

with<br />

pdadmin<br />

or<br />

the<br />

Web<br />

Portal<br />

<strong>Manager</strong>,<br />

and<br />

when<br />

a<br />

password<br />

is<br />

changed<br />

with<br />

pdadmin,<br />

the<br />

Web<br />

Portal<br />

<strong>Manager</strong>,<br />

or<br />

the<br />

pkmspasswd<br />

utility.<br />

Syntax<br />

<strong>for</strong><br />

password<br />

strength<br />

policy<br />

commands<br />

The<br />

following<br />

pdadmin<br />

commands,<br />

used<br />

to<br />

set<br />

password<br />

strength<br />

policy,<br />

are<br />

appropriate<br />

<strong>for</strong><br />

use<br />

only<br />

with<br />

an<br />

LDAP<br />

registry.<br />

The<br />

unset<br />

option<br />

disables<br />

this<br />

policy<br />

attribute—that<br />

is,<br />

the<br />

policy<br />

is<br />

not<br />

en<strong>for</strong>ced.<br />

Command<br />

Description<br />

policy<br />

set<br />

min-password-length<br />

{|unset}<br />

[-user<br />

]<br />

policy<br />

get<br />

min-password-length<br />

[-user<br />

]<br />

Manages<br />

the<br />

policy<br />

controlling<br />

the<br />

minimum<br />

length<br />

of<br />

a<br />

password.<br />

As<br />

the<br />

administrator,<br />

you<br />

can<br />

apply<br />

this<br />

policy<br />

to<br />

a<br />

specific<br />

user<br />

or<br />

apply<br />

the<br />

policy<br />

globally<br />

to<br />

all<br />

users<br />

listed<br />

in<br />

the<br />

default<br />

registry.<br />

The<br />

default<br />

setting<br />

is<br />

8.<br />

policy<br />

set<br />

min-password-alphas<br />

{|unset}<br />

[-user<br />

]<br />

policy<br />

get<br />

min-password-alphas<br />

[-user<br />

]<br />

Manages<br />

the<br />

policy<br />

controlling<br />

the<br />

minimum<br />

number<br />

of<br />

alphabetic<br />

characters<br />

allowed<br />

in<br />

a<br />

password.<br />

As<br />

the<br />

administrator,<br />

you<br />

can<br />

apply<br />

this<br />

policy<br />

to<br />

a<br />

specific<br />

user<br />

or<br />

apply<br />

the<br />

policy<br />

globally<br />

to<br />

all<br />

users<br />

listed<br />

in<br />

the<br />

default<br />

registry.<br />

The<br />

default<br />

setting<br />

is<br />

4.<br />

policy<br />

set<br />

min-password-non-alphas<br />

{|unset}<br />

[-user<br />

]<br />

policy<br />

get<br />

min-password-non-alphas<br />

[-user<br />

]<br />

114<br />

<strong>IBM</strong><br />

<strong>Tivoli</strong><br />

<strong>Access</strong><br />

<strong>Manager</strong><br />

<strong>for</strong><br />

e-<strong>business</strong>:<br />

<strong>WebSEAL</strong><br />

<strong>Administration</strong><br />

Guide

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!