Create Password Policy

Contents

1Introduction
1.1Prerequisites

2

Procedure

1   Introduction

This document describes how to create a password policy applicable for local Operation and Maintenance (O&M) user accounts.

1.1   Prerequisites

This section describes the prerequisites, which must be fulfilled before using the procedure.

1.1.1   Conditions

The following conditions must apply:

2   Procedure

To create a password policy:

  1. Navigate to the LocalAuthenticationMethod Managed Object (MO), for example:

    >dn ManagedElement=<Node Name>,SystemFunctions=1,SecM=1,UserManagement=1,LocalAuthenticationMethod=1

  2. Enter Config mode:

    (LocalAuthenticationMethod=1)>configure

  3. Create the PasswordPolicy MO, for example:

    (config-LocalAuthenticationMethod=1)>PasswordPolicy=1

  4. Set the PasswordPolicy attributes according to operators password policy, in case the values differ from default values, for example:

    (config-PasswordPolicy=1)>minLength=12

    Note:  
    This attribute means the minimum length of password, it is necessary to make sure the password is longer than minimum length, otherwise error info will be shown in ECLI.

  5. Set the password quality by giving a reference to the PasswordQuality MO, for example:

    (config-PasswordPolicy=1)>passwordQuality="ManagedElement=NODE06ST,SystemFunctions=1,SecM=1,UserManagement=1,LocalAuthenticationMethod=1,PasswordQuality=1"

  6. Commit the settings:

    (config-PasswordPolicy=1)>commit

  7. Verify the settings:

    (PasswordPolicy=1)>show -v

    The following is an example output:

    PasswordPolicy=1
       expireWarning=7 <default>
       failureCountInterval=1800 <default>
       historyLength=12 <default>
       lockoutDuration=[] <empty>
       maxAge=90 <default>
       maxFailure=3 <default>
       minAge=15 <default>
       minLength=12
       passwordPolicyId="1"
       passwordQuality="ManagedElement=1,⇒
    SystemFunctions=1,SecM=1,UserManagement=1,⇒
    LocalAuthenticationMethod=1,PasswordQuality=1"
       reservedByAccount=[] <empty> <read-only>
       userLabel=[] <empty>



Copyright

© Ericsson AB 2018. All rights reserved. No part of this document may be reproduced in any form without the written permission of the copyright owner.

Disclaimer

The contents of this document are subject to revision without notice due to continued progress in methodology, design and manufacturing. Ericsson shall have no liability for any error or damage of any kind resulting from the use of this document.

Trademark List
All trademarks mentioned herein are the property of their respective owners. These are shown in the document Trademark Information.

    Create Password Policy