Previous Topic: Use a Password Proxy User

Next Topic: Connect to LDAP Clients

Operational Attributes for User Accounts

CA Directory uses operational attributes with some password settings, as shown in the following table.

You can use these operational attributes to diagnose problems with user accounts.

Password Command

Operational Attribute

set password-age command

dxPwdLastChange

set password-history command

dxPwdHistory

set password-min-age command

dxPwdLastChange

set password-grace-logins command

dxPwdGraceLogins

dxPwdGraceUseTime

set password-allow-ignore-expired command

dxPwdIgnoreExpired

set password-allow-ignore-suspended command

dxPwdIgnoreSuspended

set password-force-change command

dxPwdMustChange

set password-last-use command

dxPwdLoginTime

set password-retries command

dxPwdFailedAttempts

set password-max-suspension command

dxPwdFailedTime

set password-allow-locking command

dxPwdLocked