Difference between revisions of "Login & Security Settings"

From SmartWiki
Jump to: navigation, search
 
(42 intermediate revisions by 3 users not shown)
Line 1: Line 1:
These setting are used to control system security.
+
#REDIRECT [[Security Settings]]
  
[[Image:Glob10.png]]
+
{{DeprecatedPage}}
 
 
==Password Policy==
 
 
 
'''Password Policy''' is used to control the length and complexity of passwords, the number of retries that the [[User|user]] is allowed, and the lockout time for the account if they exceed the number of retries.
 
 
 
[[Image:Glob11.png]]
 
 
The following password settings are available:
 
 
 
'''Password length''' – the minimum length allowed for a [[Password|password]], between 6 and 32 characters.
 
 
 
'''Complexity''' – the level of complexity required in the [[Password|password]], the options are:
 
* '''No Restriction''' – any character can be used.  This is the default.
 
* '''Alpha Only''' – only letters can be used.
 
* '''Alpha & Numeric''' – letters and numbers must be used in the password.
 
* '''Alpha & Numeric & Special characters''' – letters, numbers and special characters must be used.  The following special characters are allowed:
 
~ ! @ # $ % ^ & * ( ) { } [ ] ; : ' " < > ?
 
 
 
If you enable special characters, the special character list will be displayed to the user when they change their password.
 
 
 
[[Image:Glob12.png]]
 
 
'''Intruder Lockout Settings''' – these settings determine the actions that should be taken if someone attempts to log into your copy of [[SmartSimple]].
 
* Number of Attempts''' – the number of attempts to log in with an account before the account is locked.
 
 
 
* Lockout Duration''' – the duration of the account lockout.  The [[User|user]] will not be able to log in during this period.  Period can be set to 5 minutes, 15 minutes, 30 minutes, 1 hour, 3 hours, 12 hours, 24 hours or forever (until unlocked by [[Administrator|administrator]]).
 
 
 
* The '''View Locked Users''' tab will display all [[User|users]] that have had their account locked. <br>
 
 
 
* If a user is locked, you can click on the '''Set Password''' button on the '''View Locked Users''' tab to reactivate the account and send the [[User|user]] a new [[Password|password]].
 
 
 
 
 
* ''Once an account has been locked for exceeding the number of permitted login attempts it will remain on the "locked users" list until the correct password is entered. This allows the administrator to see which users have been unable to log in, even if the configured lockout duration has passed and the account is no longer technically locked.''
 
 
 
* ''When an account has been locked for exceeding the alloted number of attempts, after the lockout time has passed they are permitted only one attempt at the correct password. A single incorrect password at this point will re-lock the account for the configured lockout duration. In other words, once someone is on the "locked user" list they are only permitted a single wrong attempt and they will be locked for the lockout duration again. This prevent would-be intruders from having multiple attempts to guess the password each time the lockout duration has passed. ''
 
 
 
 
 
 
 
'''Intruder Email Alert''' – these settings define who should be informed by email if an intruder alert is detected.
 
* '''Email From''' – the “from” address for the email.  If you do not set this value, the address: '''support@smartsimple.com''' will be used.
 
* '''Email To''' – select the [[Internal|internal]] person to receive the email.
 
* '''Subject''' – the subject of the email. See below for the variables that you can use in the subject.
 
* '''Body''' – the body of the alert email. See below for the variables that you can use in the body.
 
 
 
'''Intruder Alert Email Variables''' – because the [[User|user]] in not logged into the system the amount of information available is limited to IP Address '''@ip@''', the attempted username '''@username@''' and time '''@time@'''.
 
 
 
 
 
 
 
==Intruder Log==
 
 
 
The '''View Log''' tab is used to access the '''Intruder Alert''' log.
 
 
 
[[Image:Glob13.png]]
 
 
 
* The list can be sorted by clicking the column title.
 
* You can filter the list by [[Username|username]], year, and month.
 
 
 
 
 
 
 
==View Locked Users'==
 
 
 
The '''View Locked Users''' tab will display all [[User|users]] that have had their account locked. <br>
 
* Once an account has been locked for exceeding the number of permitted login attempts it will remain on the "locked users" list until the correct password is entered. This allows the administrator to see which users have been unable to log in, even if the configured lockout duration has passed and the account is no longer technically locked.
 
 
 
* When an account has been locked for exceeding the alloted number of attempts, after the lockout time has passed they are permitted only one attempt at the correct password. A single incorrect password at this point will re-lock the account for the configured lockout duration. In other words, once someone is on the "locked user" list they are only permitted a single wrong attempt and they will be locked for the lockout duration again. This prevent would-be intruders from having multiple attempts to guess the password each time the lockout duration has passed.
 
 
 
* If a user is locked, you can click on the '''Set Password''' button to reactivate the account and send the [[User|user]] a new [[Password|password]].
 
 
 
[[Category:Global Settings]][[Category:System Management]][[Category:Security]]
 

Latest revision as of 07:36, 21 July 2017

Redirect to:


Ambox warning pn.png This article is deprecated and the information contained within may no longer be correct.