JavaScript is required to for searching.
Skip Navigation Links
Exit Print View
Oracle Fusion Middleware Administration Guide for Oracle Unified Directory 11g Release 1 (11.1.1)
search filter icon
search icon

Document Information

Preface

1.  Starting and Stopping the Server

2.  Configuring the Server Instance

3.  Configuring the Proxy Components

4.  Configuring Security Between Clients and Servers

5.  Configuring Security Between the Proxy and the Data Source

6.  Managing Oracle Unified Directory With Oracle Directory Services Manager

7.  Managing Directory Data

8.  Replicating Directory Data

9.  Controlling Access To Data

10.  Managing Users and Groups With dsconfig

11.  Managing Password Policies

Password Policy Components

The Default Password Policy

To View the Properties of the Default Password Policy

Password Policies in a Replicated Environment

Configuring Password Policies by Using the Command Line

To Create a New Password Policy

To Create a First Login Password Policy

To Assign a Password Policy to an Individual Account

To Prevent Password Policy Modifications

To Assign a Password Policy to a Group of Users

To Delete a Password Policy

Configuring Password Policies by Using Oracle Directory Services Manager

List the Configured Password Policy Subentries

Create a Password Policy Subentry

Create a Password Policy Subentry Based on an Existing Password Policy Subentry

Delete a Password Policy Subentry

Display the Configured Password Policies

Modify a Password Policy

Create a Password Policy

Create a Password Policy Based on an Existing Password Policy

Delete a Password Policy

Display the Supported Password Validators

Enable or Disable a Password Validator

Display the Supported Password Storage Schemes

Enable or Disable a Password Storage Scheme

12.  Managing Directory Schema

13.  Monitoring Oracle Unified Directory

14.  Tuning Performance

15.  Advanced Administration

Configuring Password Policies by Using Oracle Directory Services Manager

You can use ODSM to manage password policies, as described in the following sections.

List the Configured Password Policy Subentries

You can display all password policy subentries that are configured in the server by using ODSM, as follows:

  1. Connect to the directory server from ODSM, as described in Connecting to the Server From Oracle Directory Services Manager.

  2. Select the Security tab.

  3. Expand the Password Policy Subentry element.

    The DNs of all password policy subentries are listed.

  4. To display the details of a password policy subentry, select its DN.

    The password policy subentry properties are displayed in the right hand pane.

  5. To modify any aspect of the password policy subentry, change the required value and click Apply.

For a description of all possible properties, and their values, see the Oracle Unified Directory Configuration Reference.

Create a Password Policy Subentry

You can create a new password policy subentry by using ODSM, as follows:

  1. Connect to the directory server from ODSM, as described in Connecting to the Server From Oracle Directory Services Manager.

  2. Select the Security tab.

  3. Expand the Password Policy Subentry element.

  4. Click the Add icon.

    The password policy subentry properties are displayed in the right hand pane.

  5. On the Create new password policy subentry screen, complete the required fields.

    For a description of all possible properties, and their values, see the Oracle Unified Directory Configuration Reference.

  6. When you have completed configuring the password policy subentry, click Create.

Create a Password Policy Subentry Based on an Existing Password Policy Subentry

You can create a new password policy subentry that is based on an existing password policy subentry by using ODSM, as follows:

  1. Connect to the directory server from ODSM, as described in Connecting to the Server From Oracle Directory Services Manager.

  2. Select the Security tab.

  3. Expand the Password Policy Subentry element.

  4. Select the password policy subentry on which you want to base the new subentry.

  5. Click the Add like icon.

    The properties of the original password policy subentry are displayed in the right hand pane.

  6. Modify the required values.

    For a description of all possible properties, and their values, see the Oracle Unified Directory Configuration Reference.

  7. When you have completed configuring the new password policy subentry, click Create.

Delete a Password Policy Subentry

You can delete a password policy subentry by using ODSM, as follows:

  1. Connect to the directory server from ODSM, as described in Connecting to the Server From Oracle Directory Services Manager.

  2. Select the Security tab.

  3. Expand the Password Policy Subentry element.

  4. Select the password policy subentry that you want to deleted.

  5. Click the Delete icon.

    You are prompted to confirm the deletion. Click OK.

Display the Configured Password Policies

You can display the list of password policies by using ODSM, as follows:

  1. Connect to the directory server from ODSM, as described in Connecting to the Server From Oracle Directory Services Manager.

  2. Select the Security tab.

  3. Expand the Password Policy element.

    The list of configured password policies is displayed.

  4. Select a password policy to display its properties in the right hand pane.

For a description of all possible properties, and their values, see the Oracle Unified Directory Configuration Reference.

Modify a Password Policy

You can modify a configured password policy by using ODSM, as follows:

  1. Connect to the directory server from ODSM, as described in Connecting to the Server From Oracle Directory Services Manager.

  2. Select the Security tab.

  3. Expand the Password Policy element.

    The list of configured password policies is displayed.

  4. Select the password policy whose properties you want to modify.

For a description of all possible properties, and their values, see the Oracle Unified Directory Configuration Reference.

Create a Password Policy

You can create a new password policy by using ODSM, as follows:

  1. Connect to the directory server from ODSM, as described in Connecting to the Server From Oracle Directory Services Manager.

  2. Select the Security tab.

  3. Expand the Password Policy element.

  4. Click the Add icon.

  5. On the Create New Password Policy screen, configure the required properties.

    For a description of all possible properties, and their values, see the Oracle Unified Directory Configuration Reference.

  6. When you have configured the new password policy, click Create.

Create a Password Policy Based on an Existing Password Policy

You can create a new password policy that is based on an existing password policy by using ODSM, as follows:

  1. Connect to the directory server from ODSM, as described in Connecting to the Server From Oracle Directory Services Manager.

  2. Select the Security tab.

  3. Expand the Password Policy element.

  4. Select the password policy on which you want to base the new policy.

  5. Click the Add like icon.

  6. On the Create New Password Policy screen, modify the properties to create the new policy.

    For a description of all possible properties, and their values, see the Oracle Unified Directory Configuration Reference.

  7. When you have configured the new password policy, click Create.

Delete a Password Policy

You can delete a password policy by using ODSM, as follows:

  1. Connect to the directory server from ODSM, as described in Connecting to the Server From Oracle Directory Services Manager.

  2. Select the Security tab.

  3. Expand the Password Policy element.

  4. Select the password policy that you want to delete.

  5. Click the Delete icon.

  6. Click OK to confirm the deletion.

Display the Supported Password Validators

A password validator is a component of the password policy that determines whether a proposed password is acceptable for use. Oracle Unified Directory provides the following password validators:

You can use ODSM to display the list of password validators, as follows:

  1. Connect to the directory server from ODSM, as described in Connecting to the Server From Oracle Directory Services Manager.

  2. Select the Security tab.

  3. Expand the Password Validators element.

  4. The list of password validators is displayed.

Enable or Disable a Password Validator

You can use ODSM to enable or disable a password validator, as follows:

  1. Connect to the directory server from ODSM, as described in Connecting to the Server From Oracle Directory Services Manager.

  2. Select the Security tab.

  3. Expand the Password Validators element.

  4. Select the password validator that you want to enable or disable.

  5. In the right hand pane, check or uncheck the Enabled box, as required.

  6. Click Apply to save your changes.

Display the Supported Password Storage Schemes

A password storage scheme provides a mechanism for encoding user passwords for storage in the server. In most cases, the password is encoded in a manner that prevents users from determining what the clear-text password is, while still allowing the server to determine whether the user-supplied password is correct. Oracle Unified Directory supports a number of password storage schemes. For more information, see password storage scheme in Oracle Fusion Middleware Glossary for Oracle Unified Directory.

You can use ODSM to display the list of password storage schemes, as follows:

  1. Connect to the directory server from ODSM, as described in Connecting to the Server From Oracle Directory Services Manager.

  2. Select the Security tab.

  3. Expand the Password Storage element.

  4. The list of password storage schemes is displayed.

Enable or Disable a Password Storage Scheme

You can use ODSM to enable or disable a password storage scheme, as follows:

  1. Connect to the directory server from ODSM, as described in Connecting to the Server From Oracle Directory Services Manager.

  2. Select the Security tab.

  3. Expand the Password Storage element.

  4. Select the password storage scheme that you want to enable or disable.

  5. In the right hand pane, check or uncheck the Enabled box, as required.

  6. Click Apply to save your changes.