Quantcast
Channel: SCN: Message List - Security
Viewing all articles
Browse latest Browse all 5338

Re: Are forbidden passwords taken into account when password is generated?

$
0
0

Hi

 

1. RSEC_GENERATE_PASSWORD  is doing 1000 loop with check FM PASSWORD_FORMAL_CHECK.

 

 

2. One of the parameters for RSEC_GENERATE_PASSWORD and PASSWORD_FORMAL_CHECK is SECURITY_POLICY.

You can use system default (set by parameters) or modified policy (SECPOL since EHP6).

 

 

3. RSEC_GEN_PASSWD have no arguments for any policy check.

 

So forbidden password patterns can't be effectively checked by RSEC_GEN_PASSWD.

 

 

Reards

Przemek


Viewing all articles
Browse latest Browse all 5338

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>