HP StorageWorks XP Command View Advanced Edition Software 6.4 Server Administrator Guide for Device Manager and Provisioning Manager (web) (T1780-96341, July 2010)

Table Of Contents
Settings required for managing user accounts
76
Table 3-1 Password conditions set in the security.conf file
Item Description
password.check.userID
Specifies whether the password can be the same as
the user ID. Specify true or false. If true is
specified, passwords cannot be the same as the
corresponding user ID. If false is specified,
passwords can be the same as the corresponding
user ID.
Default: false
When you change a setting in the security.conf file, the change takes effect immediately. The
password conditions that you set in the security.conf file are applied when a user account is
created or when a password is changed, and are not applied to passwords of existing user
accounts. As a result, even if an existing password does not satisfy the password conditions, a user
can continue to use the password to log in to the system.
CAUTION:
Password conditions can also be set from web client. However, if the system is in a cluster configuration,
the settings from web client are only applied to the executing node. To apply the settings to the standby
node, switch the nodes, and then specify the same settings. For details on how to use web client, see the
HP StorageWorks XP Command View Advanced Edition software Device Manager Help.
If XP Command View AE Suite product versions 5.1 or later are installed, password conditions can be
set. The password conditions are applied to all users registered in XP Command View AE Suite products.
Therefore, if you are unable to change a password or add a user account while using XP Command View
AE Suite product versions 5.0 or earlier, the reason might be that the specified character string does not
satisfy the password conditions. Follow the output message and specify an appropriate password.
If an external authentication server is used to authenticate users, passwords are checked by using a
combination of character types specified on the external authentication server. However, if you register a
password for an XP Command View AE Suite product user, you need to use character types specified in
the XP Command View AE Suite products.
3-2 Settings for locking user accounts
This section describes the settings related to locking user accounts.
3-2-1 Settings for automatic locking
Device Manager provides settings by which a user account is automatically locked after repeated
unsuccessful login attempts to web client. Such automatic locking reduces the risk of unauthorized
access to web client.
The settings related to automatic locking are set using the account.lock.num property in the
security.conf file, which is stored in the following locations:
In Windows:
installation-folder-for-Common-Component\conf\sec\security.conf
In Linux:
installation-directory-for-Common-Component/conf/sec/security.conf
Specify a value from 0 to 10 (default: 0). If a user makes the specified number of unsuccessful logon
attempts, his or her user account will be locked. If you specify 0, any number of unsuccessful logon
attempts is allowed. When you change a setting in the security.conf file, the change takes
effect immediately.
Unsuccessful attempts to log in to other products in the XP Command View AE Suite that use the
Single Sign-On feature count towards the number of unsuccessful login attempts. For example, if