Setup guide
UNCLASSIFIED
UNCLASSIFIED
76
Chapter 6 –
Future Guidance
login password and is automatically unlocked when the user logs in. It remains
unlocked unless the user locks it, or until the user logs off.
The settings for the login keychain should be changed so that the user will be
required to unlock the login keychain when he logs in, or after waking the machine
from sleep.
1. Start the Keychain Access program.
2. If the drawer showing the user’s keychains is not open, click on the Show
Keychains icon to open it.
3. Click on the login keychain to select it.
4. Select Change Password for Keychain “login”… from the Edit menu
(Figure 30).
5. To prevent the login keychain from automatically unlocking upon login, select
a new password different from the user’s login password. This will be the new
password for the keychain.
Inside the Change Keychain Password dialog box, click the 'i' button in
the lower left corner of the box. This will open a Password Assistant dialog
box that provides assistance in choosing a strong password. Enter the current
password for the keychain in the Current Password text box and then enter
the new password in the New Password text box. As the new password is
entered, the Password Assistant dialog box will display messages that provide
guidance to increase the strength of the password. The Password Assistant
dialog box also displays a quality measure and a visible bar that grows with
the length of password. This bar also changes color from red to green as the
quality of the password improves. Choose a password that results in a green
quality bar, a quality score near 100 and no warning messages in the
Password Assistant dialog box.
As noted elsewhere in this document, the Password Assistant utility described
above can be used to help create strong passwords anytime a password is
required, not just within the keychain application. To do this, open the
Keychain Access application and choose Change Password for
keychain “x”, where “x” is any keychain. Then click on the ‘i’ at the bottom
of the Change Keychain Password dialog box, and use the Password
Assistant dialog box to create a password. Once a strong password has been
determined, this dialog box can be cancelled without actually changing the
password of the keychain, and the new password can then be entered where it
is needed.