Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Ihenock1011
Advisor

Smart Console user password complexity

Hi Teams,

We want to configure password complexity for Smart Console administrators. However, I couldn't find Smart Console user password complexity policies. Within Global Properties > User Directory. Is that policy setting intended for Smart Console users, or is it for a different user directory service?

Thanks

0 Kudos
5 Replies
Vincent_Bacher
Advisor
Advisor

Hi

No, this is not a setting for SmartConsole administrators.

As far as I know, there is unfortunately no setting option for password complexity for SmartCOnsole administrators if they are authenticated locally.

But if you need this, you have to use external authentication and define the complexity there, possibly including MFA

cheery

and now to something completely different - CCVS, CCAS, CCTE, CCCS, CCSM elite
0 Kudos
Bob_Zimmerman
Authority
Authority

It's perhaps worth noting that password complexity requirements have been universally considered counterproductive for quite some time. Even NIST finally updated their guidance to recommend against them in SP 800-63B in 2017-06 (see section 5.1.1.2: "Verifiers SHOULD NOT impose other composition rules (e.g., requiring mixtures of different character types or prohibiting consecutively repeated characters) for memorized secrets.").

SmartConsole administrators shouldn't be using local authentication if central is possible. Password complexity requirements can be implemented with most central authentication systems, but you should think before reducing the security of your environment like that.

0 Kudos
Vincent_Bacher
Advisor
Advisor

Yes, of course. External authentication should always be the preferred method. We also switched our SmartConsole authentication to ISE some time ago.

and now to something completely different - CCVS, CCAS, CCTE, CCCS, CCSM elite
0 Kudos
Lesley
Leader Leader
Leader

If you want to only use local authentication the only thing you can force is a password change upon login and a minimal length. 

 

Smart Console -> Manage & Settings -> Permissions & administrators -> Advanced -> Minimum password length and further below there are login restrictions.
Force a password change is Smart Console -> Manage & Settings -> Permissions & administrators -> Administrators -> under relevant user

 

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos
the_rock
Legend
Legend

Hey bro,

I dont believe that was ever possible for Smart console admins. You can set it for Gaia users on OS level though.

Best,

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events