A Password policy can be used to specify the following attributes related to password-based authentication:
Note: If the user status check is enabled, then the authentication for users in inactive state results in failure.
When CA AuthMinder Server receives the partial password authentication request, the user will be challenged with the number of characters from their password at various positions. For example, if the password is welcome1 and the Number of Password Characters to Challenge field is set to 4. The challenge might look like "Enter the characters at positions 2, 4, and 7". If the user enters ece, then the authentication will be successful.
Follow these steps:
If you choose to create a new policy, then:
If you choose to update an existing policy, then select the policy that you want to update from the Select Configuration list that appears.
Enable this option if you want to create the policy by copying the configurations from an existing policy.
Note: You can also copy from configurations that belong to other organizations that you have scope on.
Select the policy from which the configurations will be copied.
Specify the number of failed attempts after which the user credential will be locked.
Select this option if you want to verify whether the user is active, before authenticating them.
Specify the number of days before the warning is sent to the calling application about the user’s impending credential expiration.
Specify the number of days for which the users can use an expired credential to successfully log in.
Select this option if you want the credential to be automatically unlocked after the time you specify in the following field.
This field is valid only if you specify the corresponding value in the Lockout Credential After field.
Note: The credential does not get automatically unlocked after the unlock period. The credential has to be used for successful authentication after the unlock period to get it unlocked.
Specify the number of hours after which a locked credential can be used again for authentication.
Specify the duration for which the password challenge has to be valid.
Specify the total number of password characters that have to be challenged. The number of random positions challenged by CA AuthMinder Server is equal to this value.
The CA AuthMinder Server acts as a proxy and passes the authentication requests to other authentication servers, based on the following conditions:
See "Configuring CA AuthMinder as RADIUS Proxy Server" for more information to enable this feature.
Choose the Any Usage Type option if you want to authenticate users with any of their passwords. For example, if the user has two passwords, welcome123 with usage type as permanent and hello123 with usage type as temporary, then the user will be authenticated if they provide either of the passwords.
If you want the user to authenticate with the particular password, then enter the name of its usage type in the UsageType field.
|
Copyright © 2014 CA Technologies.
All rights reserved.
|
|