Enabling password control
About password control
Enable global password control to make all password control configurations take effect. For a specific password control feature to take effect, enable its own password control feature.
Restrictions and guidelines
After global password control is enabled, follow these restrictions and guidelines:
You cannot display the password and super password configurations for device management users by using the corresponding display commands. However, the configuration for network access user passwords can be displayed.
The first password configured for device management users must contain a minimum of four different characters.
In FIPS mode, the global password control feature is enabled and cannot be disabled.
To ensure correct function of password control, configure the device to use NTP to obtain the UTC time. After global password control is enabled, password control will record the UTC time when the password is set. The recorded UTC time might not be consistent with the actual UTC time due to power failure or device reboot. The inconsistency will cause the password expiration feature to malfunction. For information about NTP, see Network Management and Monitoring Configuration Guide.
Procedure
Enter system view.
system-view
Enable the global password control feature.
password-control enable
By default, the global password control feature is disabled.
(Optional.) Enable a specific password control feature.
password-control { aging | composition | history | length } enable
By default, all four password control features are enabled.