Configuring Advanced Local User Account Features
The following features are configured in this task. All these features are disabled by default:
- Password Length
- Password Combination Rules
- Password Masking
- Password Aging
- Password History
- User Login Attempts
- Password Expiration
All the steps are optional and can be entered in any order. The password length is superceded by the password combination rules if you configure both steps.
- Enter global configuration mode.
- Enable a minimum password length.
By default, no minimum length is specified for a password. The minimum length can be set to a value from 1 through 48.
- Enable a minimum number of, and combination of, characters to ensure secure passwords.
The strict password enforcement feature displays an error message when the password entered does not meet the criteria.
- Enable password masking to hide the password characters from the console display as
they are entered using the CLI.
When password masking is enabled, press the Enter key before entering the password, and enter the password when prompted.
- Enable password aging to force the user to provide a new password every three months.
After 90 days the CLI automatically prompts the user for a new password.
- Configure the device to store up to 15 previous passwords to prevent previous passwords
from being used as a security measure.
An error message will display if a user attempts to use a previous password that is still stored.
- Configure the maximum number of invalid login attempts a user can make before being locked out to 8 with a 15 minute time period before the user account is automatically unlocked.
- Configure a user password to expire in 30 days.
Password expiration can be used for temporary user accounts.
- Display user account information using the
show userscommand.
The following example shows how to configure advanced local user account features
to provide more secure user accounts and passwords. The password length example is
not shown because it is superceded by the
enable strict-password-enforcement command.
device# configure terminal device(config)# enable strict-password-enforcement device(config)# enable user password-masking device(config)# enable user password-aging device(config)# enable user password-history 15 device(config)# enable user disable-on-login-failure 8 login-recovery-time 15 device(config)# username sandy expires 20