Configuring Password Security Requirements

About this task

The server allows for configuring password requirements for all Basic Users defined on the server. These requirements can help an Administrator or User Administrator enforce the creation of more secure passwords.
Note: The Password Security Requirements defined on this page are only for Basic Users. Passwords for LDAP, Active Directory or RACF users are defined by those servers. More advance password security rules may require the usage of one of these external authentication servers.
Note: Password Security expiration requirements do not apply for users defined as Automation users. This is to prevent password expiration from disabling any automation running against the server using the Automation user.

Procedure

  1. Login to the server as a user with Administrator or User Administrator privileges.
  2. In the menu bar, click Settings > Administration.
  3. At the top of the Administration page, click the link that says Password Security Requirements.
  4. Update one or more of the following requirement fields to define the security requirements for Basic Users on the server.
    1. Expiration in Days: Specify the number of days before a password will expire and a new password will have to be set. Valid values are 0-365. The default is 0 and indicates that there is no expiration for passwords.
      Note: When the password expires, the user upon logging into the server, will be prompted to change their password. They'll need to type in the old password as well as a new password that meets the requirements.
    2. Minimum Length: Specify the minimum number of characters that the password should contain.
    3. Required Characters Mixed Case: Check this box if the password should have both upper and lower case characters.
    4. Required Characters Numbers: Check this box if the password should contain a numerical character.
    5. Required Characters Symbols: Check this box if the password should contain at least one of the following symbols: ! @ $ % ^ & ( ) _
  5. Click on the OK button to confirm the security requirements.