ACS 5.1 Password rules settings per internal User

Unanswered Question
Sep 28th, 2010


I am looking for a way how to set the password-rules for individually for for some users or identity-groups.

I just can find the global settings

Background of the requirement: We want to use password-aging for most admin-users, for some we dont want that pw expires

(e.g. NMS-Users ect)



I have this problem too.
0 votes
  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 0 (0 ratings)
Waris Hussain Wed, 09/29/2010 - 14:14


I dont see any way you can do that per use level, the only place where  you can change authentication settings is :

System Administration > ... > Users > Authentication Settings

and thats appliacable to all users


Waris Hussain.

MATIJA PETROVIC Wed, 04/06/2011 - 02:15


sorry to raise this old thread but... we have the same requirement - to be able to tune password rules settings for specific user accounts.

I would call this a feature request... Can we have a comment if this feature is ever likely to appear in future ACS releases?


Tiago Antunes Wed, 04/06/2011 - 02:36


Yes this would be considered as PER.

Currently there are no plans for this to be implemented for specifc accounts only, it is possible though in a global way.




If  this helps you and/or answers your question please mark the question as  "answered" and/or rate it, so other users can easily find it.

jrabinow Wed, 04/06/2011 - 02:42

You can disable password aging for specific users

Need to upgrade to ACS 5.2 and install cummulative patch patch or higher that includes the following enhancement

CSCtk32178: Add an option for pass never expired for specific users

There are other threads on this subject that provide more details. When install the patch it includes a document that defines how to configure this

If need more details let me know

HUBERT RESCH Wed, 04/06/2011 - 03:03

unfortunately this bug is not visible,

do you know when this Patch will be available ?

CSCtk32178 Bug Details

This bug ID CSCtk32178 currently has no detailed information associated with it. Please add this bug ID to your watch group, which will notify our system administrators of your interest in this bug. Bug Toolkit will then notify you of any changes to this bug in the future.

jrabinow Wed, 04/06/2011 - 03:53

Patch is already available and can be downloaded from CCO (need to upgrade to ACS 5.2 first)

HUBERT RESCH Thu, 04/07/2011 - 00:19

Hi, I did an upgrade to

Version :

Company Name : customer

User : hresch
Internal Build ID : B.3075

Patches :


but I cannot see any change in the User-configuration, now way to set that password never expires or so ?



jrabinow Thu, 04/07/2011 - 02:21

There are no new specific options you will see in the GUI. It is enabled by created attributes for internal users

This functionality is enabled as follows:

- In : System Administration > Configuration > Dictionaries > Identity > Internal Users add Boolean attribute ACSRESERVEDNeverExpired and set its default value to "false".

- Set this user attribute to be true in the internal user definitions of those users whose password should never expire.

There should be a pdf doc included together with the readme

HUBERT RESCH Thu, 04/07/2011 - 05:28

Thanks a lot now it works! Great !

Btw is there a way to do this as well for the administrative users ?



jrabinow Thu, 04/07/2011 - 05:33

This specific mechanism does not apply to administrators.

However, administrative accounts already have the followig option that can be selected


Account never disabled

Overwrites account blocking in case password expired, account inactivity
period reached or admin exhausted permitted failed attempt


This Discussion