Managing User Passwords 91
Nortel WLAN—Security Switch 2300 Series Configuration Guide

Managing User Passwords

Passwords Overview

Nortel recommends that all users create passwords that are easily remembered, difficult for others to guess, and not
subject to a dictionary attack.
By default, user passwords are automatically encrypted when entered in the local database. However, the encryption
type is not very strong. It is designed to discourage someone from memorizing your password as you display the config-
uration. To maintain security, WSS displays only the encrypted form of the password in show commands.
You can configure WSS so that the following additional restrictions apply to user passwords:
Passwords must be a minimum of 10 characters in length. It should be a mix of uppercase letters, lowercase letters,
numbers, and special characters, including at least two of each (for example, Nor%Pag32!).
Local users cannot reuse any of their 10 previous passwords.
When a user changes password, at least 4 characters must be different from the previous password.
A user password expires after a configurable amount of time.
A user is locked out of the system after a configurable number of failed login attempts. When this happens, a trap is
generated and an alert is logged. (Administrative users can gain access to the system through the console, even
when the account is locked.)
Only one unsuccessful login attempt is allowed in a 10-second period for a user or session.
All administrative logins, logouts, logouts due to idle timeout, and disconnects are logged.
The audit log file on the WSS (command_audit.cur) cannot be deleted, and attempts to delete log files are recorded.
Passwords Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 91
Configuring Passwords . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 92
Displaying Password Information . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 99
Note. The above restrictions are optional.