Evaluation of effective password policy

Effective password policy of the user is evaluated only if the ibm-pwdPolicy attribute is set to TRUE in the global password policy entry. Other password policies, such as individual and group policy, can still be enabled when the global policy is disabled. However, these policy rules have no effect on the user.

The attribute ibm-pwdPolicyStartTime is set to the current system time when ibm-pwdPolicy is set to TRUE. This setting can be done even if the global password policy entry is set to FALSE. However, the ibm-pwdPolicyStartTime value is not be used for effective policy evaluation unless the global policy is enabled. Once the global policy is enabled, the value of this attribute is selected from an individual, then group and then the global policy. Since ibm-pwdPolicyStartTime exists in every active password policy, the start time of an individual policy, if it exists, always overrides any other policy start time as the start time of the user's effective password policy.

The following table shows a set of examples that explain how an effective password policy of the user is determined.
Table 1. Determining the effective password policy
Individual password policy Group password policy Global password policy Effective password policy

pwdMaxAge = 86400

ibm-pwdPolicy = True

pwdMinAge = 21600

pwdLockout = True

ibm-pwdPolicyStarttime = 20060406200000

pwdMaxAge =43200

ibm-pwdPolicy = True

pwdInHistory = 5

ibm-pwdPolicyStarttime = 20060306200000

ibm-pwdPolicy = True

pwdMinAge = 43200

pwdInHistory = 3

pwdCheckSyntax = 0

pwdMinLength = 0

pwdExpireWarning = 0

pwdGraceLoginLimit = 0

pwdLockoutDuration = 0

pwdMaxFailure =0

pwdFailureCount Interval=0

passwordMinAlpha Chars=0

passwordMinOther Chars=0

passwordMax RepeatedChars=0

passwordMinDiff Chars=0

pwdLockout=False

pwdAllowUser Change=True

pwdMustChange=True

pwdSafeModify =False

ibm-pwdPolicyStarttime = 20060506200000

pwdMaxAge = 86400

ibm-pwdPolicy = True

pwdMinAge = 21600

pwdInHistory = 5

pwdCheckSyntax = 0

pwdMinLength = 0

pwdExpireWarning = 0

pwdGraceLoginLimit = 0

pwdLockoutDuration = 0

pwdMaxFailure =0

pwdFailureCountInterval=0

passwordMinAlphaChars=0

passwordMinOtherChars=0

passwordMaxRepeatedChars=0

passwordMinDiffChars=0

pwdLockout=True

pwdAllowUserChange=True

pwdMustChange=True

pwdSafeModify=False

ibm-pwdPolicyStarttime = 20060406200000

pwdMaxAge = 86400

ibm-pwdPolicy = True

pwdMinAge = 21600

pwdMinLength = 8

pwdLockout = True

ibm-pwdPolicyStarttime = 20060406200000

pwdMaxAge =43200

ibm-pwdPolicy = True

pwdInHistory = 5

ibm-pwdPolicyStarttime = 20060306200000

ibm-pwdPolicy = True

pwdMinAge = 0

pwdInHistory = 3

pwdCheckSyntax = 0

pwdMinLength = 10

pwdExpireWarning = 0

pwdGraceLonginLimit = 0

pwdLockoutDuration = 0

pwdMaxFailure =0

pwdFailureCount Interval=0

passwordMinAlpha Chars=4

passwordMinOther Chars=4

passwordMax RepeatedChars=0

passwordMinDiff Chars=0

pwdLockout=False

pwdAllowUser Change=True

pwdMustChange =True

pwdSafeModify =False

ibm-pwdPolicyStarttime = 20060506200000

pwdMaxAge = 86400

ibm-pwdPolicy = True

pwdMinAge = 21600

pwdInHistory = 5

pwdCheckSyntax = 0

pwdMinLength = 8

pwdExpireWarning = 0

pwdGraceLoginLimit = 0

pwdLockoutDuration = 0

pwdMaxFailure =0

pwdFailureCountInterval=0

passwordMinAlphaChars=0

passwordMinOtherChars=0

passwordMaxRepeatedChars=0

passwordMinDiffChars=0

pwdLockout=True

pwdAllowUserChange=True

pwdMustChange=True

pwdSafeModify=False

ibm-pwdPolicyStarttime = 20060406200000

passwordMaxConsecutive RepeatedChars=1

passwordMaxRepeated Chars=0

ibm-pwdPolicy = True

passwordMaxConsecutive RepeatedChars=1

passwordMaxRepeated Chars=10

ibm-pwdPolicy = True

passwordMaxRepeated Chars=4

ibm-pwdPolicy = True

passwordMaxConsecutive RepeatedChars=1

passwordMaxRepeatedChars=0

ibm-pwdPolicy = True