cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
364
Views
0
Helpful
3
Replies

Account Policy - Trivial Passwords

joe.conger
Level 1
Level 1

There seems to be a bug in the way that trivial passwords are detected during a password change. Unity correctly detects a trivial password if I change it in the SA. However it does not detect the trivial password if I check "Force user to change password at next logon". It bacically accepts any password that meets the minimum length requirement.

3 Replies 3

lindborg
Cisco Employee
Cisco Employee

Full Unity version?

Just tried this on my 4.2(1) installs and it works as it should...

Unity 4.1

Pri Ext: 6253

Min. PW length: 5

PW to remember: 2

Through SA it fails with trivial password error if I enter 62533. If I force the user to change it through the phone "User must change password at next login" it accepts the 62533. I also have the "Prompt for phone password/ Only when user calls from an unknown extension" turned on/enabled.

THX

Well, I know the TUI password checks don't look for the PW to be a subset of the primary extension or vice versa - it looks only for repeated digits, being equal to an extension (primary or alternate), length and making sure it's not in the history list of PWs - The SA must be making it's own checks if it's flagging a PW that is a superset of teh extension like that...