I am looking for a way how to set the password-rules for individually for for some users or identity-groups.
I just can find the global settings
Background of the requirement: We want to use password-aging for most admin-users, for some we dont want that pw expires
(e.g. NMS-Users ect)
I dont see any way you can do that per use level, the only place where you can change authentication settings is :
|System Administration >||... >||Users >||Authentication Settings|
and thats appliacable to all users
sorry to raise this old thread but... we have the same requirement - to be able to tune password rules settings for specific user accounts.
I would call this a feature request... Can we have a comment if this feature is ever likely to appear in future ACS releases?
Yes this would be considered as PER.
Currently there are no plans for this to be implemented for specifc accounts only, it is possible though in a global way.
If this helps you and/or answers your question please mark the question as "answered" and/or rate it, so other users can easily find it.
You can disable password aging for specific users
Need to upgrade to ACS 5.2 and install cummulative patch 188.8.131.52.2 patch or higher that includes the following enhancement
CSCtk32178: Add an option for pass never expired for specific users
There are other threads on this subject that provide more details. When install the patch it includes a document that defines how to configure this
If need more details let me know
unfortunately this bug is not visible,
do you know when this Patch will be available ?
|This bug ID CSCtk32178 currently has no detailed information associated with it. Please add this bug ID to your watch group, which will notify our system administrators of your interest in this bug. Bug Toolkit will then notify you of any changes to this bug in the future.|
Hi, I did an upgrade to
Version : 184.108.40.206.3
but I cannot see any change in the User-configuration, now way to set that password never expires or so ?
There are no new specific options you will see in the GUI. It is enabled by created attributes for internal users
This functionality is enabled as follows:
- In : System Administration > Configuration > Dictionaries > Identity > Internal Users add Boolean attribute ACS‐RESERVED‐Never‐Expired and set its default value to "false".
- Set this user attribute to be true in the internal user definitions of those users whose password should never expire.
There should be a pdf doc included together with the readme
Thanks a lot now it works! Great !
Btw is there a way to do this as well for the administrative users ?
This specific mechanism does not apply to administrators.
However, administrative accounts already have the followig option that can be selected
Overwrites account blocking in case password expired, account inactivity
period reached or admin exhausted permitted failed attempt