Google Groups no longer supports new Usenet posts or subscriptions. Historical content remains viewable.
Dismiss

Universal Password -History List

110 views
Skip to first unread message

Andy

unread,
Mar 20, 2007, 12:30:30 PM3/20/07
to
Hi,
I have enabled adv. password policies and limit the number of passwords
stored in history .
Is it possible to delete the password history list of user?

Andy


Jeff Johnson

unread,
Mar 20, 2007, 7:25:12 PM3/20/07
to
No you cannot. The only way to do it is to assign him a separate policy with
no history,,,the next time he changes his password it will be zeroed out.
The history list is nice--but it comes with its own set of problems.

Peter Kuo

unread,
Mar 20, 2007, 9:28:00 PM3/20/07
to
Andy wrote:

> Is it possible to delete the password history list of user?

Nope .. at least not at this time.

--


Peter
eDirectory Rules!
(ssAegis powering up to 65% ...)

a...@novell.com

unread,
Mar 21, 2007, 2:12:24 AM3/21/07
to
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

You can set the passwords in the history to expire, though. For
instance, 1 day should take care of them rather well. This is a very
good idea to have set as doing otherwise means after n-password changes
the password cannot be changed again. Erring on the side of security in
this case causes some confusion.

Also rmupwd can clear history but at a cost (UP is also removed (not the
NDS password though, of course), simple password, challenge/response
information, etc.).

Good luck.

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFGAM0n7eGRNwWOK9IRAu/FAJ0TZKjRQ0CEMRaS1RVUTa1Y3APuMgCePzPS
LCHjRCnnaRRfgReiKfn5ek4=
=/E/f
-----END PGP SIGNATURE-----

Peter Kuo

unread,
Mar 21, 2007, 2:24:52 AM3/21/07
to
a...@novell.com wrote:

> but at a cost

And one may as well go buy some beach front property in Florida during
hurrican season <g>

Andy

unread,
Mar 21, 2007, 11:18:29 AM3/21/07
to
Is there another chance to configure a unique password without history list?
Is there a internal limit of unique passwords, if i do not configure "limit
number of pw in history list" and "limit the number of days stored in
history list?

Andy

<a...@novell.com> schrieb im Newsbeitrag
news:c14Mh.362$lj2...@prv-forum2.provo.novell.com...

a...@novell.com

unread,
Mar 21, 2007, 11:53:01 AM3/21/07
to
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

New NMAS (current I believe) and new plugins that come with IDM 3.5 will
allow this I believe. Makes it less-secure but it's more-like microsoft
so you can do it though it won't be default. Look for the new plugins
within a couple weeks.

Good luck.

Andy wrote:
> Is there another chance to configure a unique password without history list?
> Is there a internal limit of unique passwords, if i do not configure "limit
> number of pw in history list" and "limit the number of days stored in
> history list?
>
> Andy
>
> <a...@novell.com> schrieb im Newsbeitrag
> news:c14Mh.362$lj2...@prv-forum2.provo.novell.com...

> You can set the passwords in the history to expire, though. For
> instance, 1 day should take care of them rather well. This is a very
> good idea to have set as doing otherwise means after n-password changes
> the password cannot be changed again. Erring on the side of security in
> this case causes some confusion.
>
> Also rmupwd can clear history but at a cost (UP is also removed (not the
> NDS password though, of course), simple password, challenge/response
> information, etc.).
>
> Good luck.
>
> Jeff Johnson wrote:
>>>> No you cannot. The only way to do it is to assign him a separate policy
>>>> with
>>>> no history,,,the next time he changes his password it will be zeroed out.
>>>> The history list is nice--but it comes with its own set of problems.
>>>>
>>>> Andy wrote:
>>>>
>>>>> Hi,
>>>>> I have enabled adv. password policies and limit the number of passwords
>>>>> stored in history .
>>>>> Is it possible to delete the password history list of user?
>>>>>
>>>>> Andy
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.2 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFGAVU87eGRNwWOK9IRAtEtAJ9HCRSJMDeAgnxwy++Ya9uYIL3BGgCfT4YR
L74/VYGPCYojH8nLh3oQvoI=
=zyCc
-----END PGP SIGNATURE-----

0 new messages