| | |
| | | ! |
| | | ! |
| | | ! Copyright 2007-2008 Sun Microsystems, Inc. |
| | | ! Portions Copyright 2012 ForgeRock, AS. |
| | | ! --> |
| | | <adm:managed-object name="attribute-value-password-validator" |
| | | plural-name="attribute-value-password-validators" |
| | |
| | | </ldap:attribute> |
| | | </adm:profile> |
| | | </adm:property> |
| | | <adm:property name="check-substrings" mandatory="false"> |
| | | <adm:synopsis> |
| | | Indicates whether this password validator is to match portions of |
| | | the password string against attribute values. |
| | | </adm:synopsis> |
| | | <adm:description> |
| | | If "false" then only match the entire password against attribute values |
| | | otherwise ("true") check whether the password contains attribute values. |
| | | </adm:description> |
| | | <adm:default-behavior> |
| | | <adm:defined> |
| | | <adm:value>true</adm:value> |
| | | </adm:defined> |
| | | </adm:default-behavior> |
| | | <adm:syntax> |
| | | <adm:boolean /> |
| | | </adm:syntax> |
| | | <adm:profile name="ldap"> |
| | | <ldap:attribute> |
| | | <ldap:name>ds-cfg-check-substrings</ldap:name> |
| | | </ldap:attribute> |
| | | </adm:profile> |
| | | </adm:property> |
| | | <adm:property name="min-substring-length" mandatory="false"> |
| | | <adm:synopsis> |
| | | Indicates the minimal length of the substring within the password |
| | | in case substring checking is enabled. |
| | | </adm:synopsis> |
| | | <adm:description> |
| | | If "check-substrings" option is set to true, then this parameter |
| | | defines the length of the smallest word which should be used for |
| | | substring matching. Use with caution because values below 3 might |
| | | disqualify valid passwords. |
| | | </adm:description> |
| | | <adm:default-behavior> |
| | | <adm:defined> |
| | | <adm:value>5</adm:value> |
| | | </adm:defined> |
| | | </adm:default-behavior> |
| | | <adm:syntax> |
| | | <adm:integer /> |
| | | </adm:syntax> |
| | | <adm:profile name="ldap"> |
| | | <ldap:attribute> |
| | | <ldap:name>ds-cfg-min-substring-length</ldap:name> |
| | | </ldap:attribute> |
| | | </adm:profile> |
| | | </adm:property> |
| | | <adm:property name="test-reversed-password" mandatory="true"> |
| | | <adm:synopsis> |
| | | Indicates whether this password validator should test the reversed |