Skip Headers

Oracle® Internet Directory Administrator's Guide
10g (9.0.4)

Part Number B12118-01
Go To Documentation Library
Home
Go To Product List
Solution Area
Go To Table Of Contents
Contents
Go To Index
Index

Go to previous page Go to beginning of chapter Go to next page

Password Policies in Oracle Internet Directory, 2 of 4


About Password Policies

This section contains these topics:

What a Password Policy Is

Password polices are sets of rules that govern how passwords are used. They can specify, for example:

Default Password Policy

The default password policy for Oracle Internet Directory enforces:

Beginning in Oracle Internet Directory, Release 9.0.4, the password policy entry in the Root Oracle Context applies to the super user, but only the password policy governing account lockout is enforced on that account.

During Oracle Internet Directory installation, the Oracle Universal Installer creates for each identity management realm a password policy entry. This entry contains all password policy information applicable to all users in that realm.

The installer places this entry as shown in Figure 15-1--namely, immediately below the common entry, which resides under the products entry, which, in turn, resides under the Oracle Context specific to the identity management realm.

Figure 15-1 Location of Password Policy Entries

Text description of oidag081.gif follows

Text description of the illustration oidag081.gif

The Oracle Internet Directory password policy is applicable to simple binds (based on the userpassword attribute), compare operations on the userpassword attribute, and SASL binds. It does not apply to SSL and proxy binds.

To enforce this password policy, set to the appropriate value the orclcommonusersearchbase attribute in the common entry of the realm-specific Oracle Context. Otherwise, no password policy modification can take effect.

Directory Server Verification of Password Policy Information

To ensure that the user password meets the requirements of a given policy, the directory server verifies:

Overview: Establishing a Password Policy for an Identity Management Realm

In general, to establish a password policy:

  1. Create a password policy entry, associate it with the pwdpolicy object class, and populate the corresponding attributes.

  2. Set values for the pwdPolicy object class, which contains password policy information for the entire directory. Do this during installation when the entry of this object class is created.

  3. Verify that the orclpwdpolicyenable attribute in the password policy entry is set to 1.

    See Also:

    "Password Policy Schema Elements" for a list and descriptions of the attributes of the pwdPolicy object class, and those of the top object class that pertain to password policies


Go to previous page Go to beginning of chapter Go to next page
Oracle
Copyright © 1999, 2003 Oracle Corporation.

All Rights Reserved.
Go To Documentation Library
Home
Go To Product List
Solution Area
Go To Table Of Contents
Contents
Go To Index
Index