Password Guidelines

Password guidelines include the details of the supported values of the IBM® Security Directory Server password attribute for user entries in IBM Verify Directory. These guidelines also include the account details that are used to administer the LDAP environment.

The guidelines include of what characters to avoid for reducing confusion when you run the IBM Verify Directory command-line tools and C-API interfaces.

IBM Verify Directory has two types of user accounts:
  • Administration accounts (LDAP Administrator (cn=root), members of the Administrator Group, or the master server DN) that are stored in the <instance_directory>/etc/ibmslapd.conf file.
  • User entries (iNetOrgPerson) that have a password attribute that is used with Directory Server C and IBM Semeru Runtime Certified Edition (Java) (JNDI) APIs. These entries are the interfaces that applications, such as IBM Security Access Manager and WebSphere® Application Server use. While the Directory Server supports a wide variety of values for password entries, you need to review the application documentation to confirm what guidelines or restrictions apply.
    Note: Global administration group member entries are stored in the directory and are considered as User entries.
Details of the supported password values that use IBM Verify Directory are explained in the following sections.
Note: The LDAP DB2® user is stored in the configuration file, but is not subject to password policy.