2,299
edits
Changes
no edit summary
|-
||'''Password Length'''
||The minimum length allowed for a password; the number inputted must be between '''6 - 32 characters.'''
|-
||'''Complexity'''
||
Set the level of character-type complexity required for a password. The options are as follows:
* '''No Restriction - '''any character can be used; this is the default.
<pre style="white-space: -o-pre-wrap; word-wrap: break-word;"><!--@sslogic('@langid@'='2')--><br>@system.Password Policy - French@<!--@else--><br>@system.Password Policy@<!--@end--></pre>
===Intruder Lockout Settings and Intruder Email Alert Alert===
The third tab in '''Password and Activation Policies, '''called '''Intruder Alert Settings, '''will determine the actions that should be taken if someone attempts to log into your copy of [[SmartSimple]] but cannot provide accurate credentials.
|}
* The '''Locked Users '''tab will display a [[List View Overview|list]] of all users that have had their account locked.
* If a user is locked, you can click on the '''Set Password''' button on the '''View Locked Users''' tab to reactivate the account and send the [[User|user]] a new [[Password|password]]
** ''Once an account has been locked for exceeding the number of permitted login attempts it will remain on the "locked users" list until the correct password is entered. This allows the administrator to see which users have been unable to log in, even if the configured lockout duration has passed and the account is no longer technically locked.''
** ''When an account has been locked for exceeding the allotted number of attempts, after the lockout time has passed they are permitted only one attempt at the correct password. A single incorrect password at this point will re-lock the account for the configured lockout duration. In other words, once someone is on the "locked user" list they are only permitted a single wrong attempt and they will be locked for the lockout duration again. This prevents would-be intruders from having multiple attempts to guess the password each time the lockout duration has passed.''
The latter half of this page has the heading '''Intruder Email Alert - '''using a default template, it allows you to customize the email alert when someone has been locked out because of intruding attempts.
|-
||'''Subject'''
||The subject of the email. See
|-
||'''Body'''
||'''Sample Template - '''Clicking this will populate the text window automatically with a template of what the email alert will contain. It will include [[System Variables]].
|}
'''Intruder Alert Email Variables''' – because the [[User|user]] is not logged into the system, the amount of information available is limited to IP Address '''@ip@''', the attempted username '''@username@''' and date/time '''@now@''' of the attempted login.
* '''Lockout Message''' - a custom message to display to users when a user is locked out due to too many failed login attempts. This message will only display when a user has been locked out, and attempts to log in again with the correct password. Therefore, no information will be divulged to users that fail their login.
===Hierarchical Password Policy===