| | |
| | | </adm:property> |
| | | |
| | | <adm:property name="state-update-failure-policy" mandatory="false" |
| | | multi-valued="false"> |
| | | multi-valued="false"> |
| | | <adm:synopsis> |
| | | Specifies how the server should deal with the inability to update password |
| | | policy state information during an authentication attempt. In particular, |
| | |
| | | </adm:profile> |
| | | </adm:property> |
| | | |
| | | <adm:property name="password-history-count" mandatory="false" |
| | | multi-valued="false"> |
| | | <adm:synopsis> |
| | | Specifies the maximum number of former passwords to maintain in the |
| | | password history. When choosing a new password, the proposed password |
| | | will be checked to ensure that it does not match the current password, nor |
| | | any other password in the history list. A value of zero indicates that |
| | | either no password history is to be maintained (if the password history |
| | | duration has a value of zero seconds), or that there is no maximum number |
| | | of passwords to maintain in the history (if the password history duration |
| | | has a value greater than zero seconds). |
| | | </adm:synopsis> |
| | | <adm:default-behavior> |
| | | <adm:defined> |
| | | <adm:value>0</adm:value> |
| | | </adm:defined> |
| | | </adm:default-behavior> |
| | | <adm:syntax> |
| | | <adm:integer lower-limit="0" upper-limit="2147483647" /> |
| | | </adm:syntax> |
| | | <adm:profile name="ldap"> |
| | | <ldap:attribute> |
| | | <ldap:oid>1.3.6.1.4.1.26027.1.1.444</ldap:oid> |
| | | <ldap:name>ds-cfg-password-history-count</ldap:name> |
| | | </ldap:attribute> |
| | | </adm:profile> |
| | | </adm:property> |
| | | |
| | | <adm:property name="password-history-duration" mandatory="false" |
| | | multi-valued="false"> |
| | | <adm:synopsis> |
| | | Specifies the maximum length of time that passwords should remain in the |
| | | password history. When choosing a new password, the proposed password |
| | | will be checked to ensure that it does not match the current password, nor |
| | | any other password in the history list. A value of zero seconds indicates |
| | | that either no password history is to be maintained (if the password |
| | | history count has a value of zero), or that there is no maximum duration |
| | | for passwords in the history (if the password history count has a value |
| | | greater than zero). |
| | | </adm:synopsis> |
| | | <adm:default-behavior> |
| | | <adm:defined> |
| | | <adm:value>0 seconds</adm:value> |
| | | </adm:defined> |
| | | </adm:default-behavior> |
| | | <adm:syntax> |
| | | <adm:duration base-unit="s" lower-limit="0" upper-limit="2147483647" |
| | | allow-unlimited="false" /> |
| | | </adm:syntax> |
| | | <adm:profile name="ldap"> |
| | | <ldap:attribute> |
| | | <ldap:oid>1.3.6.1.4.1.26027.1.1.445</ldap:oid> |
| | | <ldap:name>ds-cfg-password-history-duration</ldap:name> |
| | | </ldap:attribute> |
| | | </adm:profile> |
| | | </adm:property> |
| | | |
| | | </adm:managed-object> |
| | | |