<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic can not use previous password in ISE 1.1.2 patch-5 in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/can-not-use-previous-password-in-ise-1-1-2-patch-5/m-p/2203608#M137297</link>
    <description>&lt;P&gt;this is my password-policy:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;password-policy&lt;/P&gt;&lt;P&gt;&amp;nbsp; lower-case-required&lt;/P&gt;&lt;P&gt;&amp;nbsp; upper-case-required&lt;/P&gt;&lt;P&gt;&amp;nbsp; digit-required&lt;/P&gt;&lt;P&gt;&amp;nbsp; no-username&lt;/P&gt;&lt;P&gt;&amp;nbsp; disable-cisco-passwords&lt;/P&gt;&lt;P&gt;&amp;nbsp; min-password-length 6&lt;/P&gt;&lt;P&gt;&amp;nbsp; password-lock-retry-count 5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also entered the followings:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;conf t&lt;/P&gt;&lt;P&gt;&amp;nbsp; password-policy&lt;/P&gt;&lt;P&gt;&amp;nbsp; no password-locked-enabled&lt;/P&gt;&lt;P&gt;&amp;nbsp; no no-previous-password&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;my initial "admin" account has the password of "Checkpoint1234".&amp;nbsp; It locked me out after 5 attempts from the webUI.&amp;nbsp; Fine, I CLI into the box and reset &lt;/P&gt;&lt;P&gt;the password, when I tried to reset the password for "admin" to "Checkpoint1234", it tells me that I can NOT use a previous password.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How do I disable this option altogether?&amp;nbsp; In other words, I want to use previous password.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By the way, in the webUI password-policy, you have to set the "Password History" between 1 and 10.&amp;nbsp; WTF!!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
    <pubDate>Mon, 11 Mar 2019 03:20:51 GMT</pubDate>
    <dc:creator>david.tran</dc:creator>
    <dc:date>2019-03-11T03:20:51Z</dc:date>
    <item>
      <title>can not use previous password in ISE 1.1.2 patch-5</title>
      <link>https://community.cisco.com/t5/network-access-control/can-not-use-previous-password-in-ise-1-1-2-patch-5/m-p/2203608#M137297</link>
      <description>&lt;P&gt;this is my password-policy:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;password-policy&lt;/P&gt;&lt;P&gt;&amp;nbsp; lower-case-required&lt;/P&gt;&lt;P&gt;&amp;nbsp; upper-case-required&lt;/P&gt;&lt;P&gt;&amp;nbsp; digit-required&lt;/P&gt;&lt;P&gt;&amp;nbsp; no-username&lt;/P&gt;&lt;P&gt;&amp;nbsp; disable-cisco-passwords&lt;/P&gt;&lt;P&gt;&amp;nbsp; min-password-length 6&lt;/P&gt;&lt;P&gt;&amp;nbsp; password-lock-retry-count 5&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also entered the followings:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;conf t&lt;/P&gt;&lt;P&gt;&amp;nbsp; password-policy&lt;/P&gt;&lt;P&gt;&amp;nbsp; no password-locked-enabled&lt;/P&gt;&lt;P&gt;&amp;nbsp; no no-previous-password&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;my initial "admin" account has the password of "Checkpoint1234".&amp;nbsp; It locked me out after 5 attempts from the webUI.&amp;nbsp; Fine, I CLI into the box and reset &lt;/P&gt;&lt;P&gt;the password, when I tried to reset the password for "admin" to "Checkpoint1234", it tells me that I can NOT use a previous password.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;How do I disable this option altogether?&amp;nbsp; In other words, I want to use previous password.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;By the way, in the webUI password-policy, you have to set the "Password History" between 1 and 10.&amp;nbsp; WTF!!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 03:20:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-not-use-previous-password-in-ise-1-1-2-patch-5/m-p/2203608#M137297</guid>
      <dc:creator>david.tran</dc:creator>
      <dc:date>2019-03-11T03:20:51Z</dc:date>
    </item>
    <item>
      <title>can not use previous password in ISE 1.1.2 patch-5</title>
      <link>https://community.cisco.com/t5/network-access-control/can-not-use-previous-password-in-ise-1-1-2-patch-5/m-p/2203609#M137300</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Admin account for the web UI seems to be locked out. So it needs to be reset from CLI. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;An incorrect password for your administrator user ID entered enough times to disable the administrator password. The minimum and default number is five. The Cisco ISE user interface “locks you out” of the system and suspends the credentials for that administrator ID until you have an opportunity to reset the password that is associated with that administrator ID. It does not affect the CLI password for the specified administrator ID&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Step 1&amp;nbsp;&amp;nbsp;&amp;nbsp; Access the direct-console CLI and enter the following command:&lt;/P&gt;&lt;P&gt;admin# application reset-passwd ise &lt;ADMINISTRATOR id=""&gt;&lt;/ADMINISTRATOR&gt;&lt;/P&gt;&lt;P&gt;Step 2&amp;nbsp;&amp;nbsp;&amp;nbsp; Specify a new password that is different from the previous two passwords that were used for this administrator ID:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Enter new password:&lt;/P&gt;&lt;P&gt;Confirm new password:&lt;/P&gt;&lt;P&gt;Password reset successfully&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you only want to use the previous password, you should change the password policy first. After you have successfully reset the administrator password, the credentials become immediately active in the Cisco ISE and you can log in with the new password without having to reboot your system.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Review the section "&lt;STRONG&gt;Password Negated Due to Administrator Lockout&lt;/STRONG&gt;" at the folowing location:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/en/US/docs/security/ise/1.1.1/installation_guide/ise_postins.html"&gt;http://www.cisco.com/en/US/docs/security/ise/1.1.1/installation_guide/ise_postins.html&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 27 Apr 2013 00:06:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-not-use-previous-password-in-ise-1-1-2-patch-5/m-p/2203609#M137300</guid>
      <dc:creator>askhuran</dc:creator>
      <dc:date>2013-04-27T00:06:09Z</dc:date>
    </item>
    <item>
      <title>can not use previous password in ISE 1.1.2 patch-5</title>
      <link>https://community.cisco.com/t5/network-access-control/can-not-use-previous-password-in-ise-1-1-2-patch-5/m-p/2203610#M137302</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Perhaps I did NOT make the question clear.&amp;nbsp; Here we go again:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1- I know how to reset the password and I know how to do it,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2- the original question is:&amp;nbsp; I want to disable the option on ISE so that I can re-use previous password for admin user when connecting via the webUI.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For example, let say I have an account called "admin" that I have during the original setup with a password of "Checkpoint1234"...&amp;nbsp; Let say I type the wrong password 10 times and now the "admin" account is locked-out.&lt;/P&gt;&lt;P&gt;So, I have to CLI into the ISE and reset the password BUT I want to reset the password back to "Checkpoint1234" but&amp;nbsp; the ISE will NOT let me.&amp;nbsp;&amp;nbsp; By the way, I did change the password policy first before intentionally typing the wrong password so that I can reset the password for the account "admin".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I want to disable this feature completely in ISE.&amp;nbsp; The question is, how do I go about doing that? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The question is, how do I go about doing that? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 27 Apr 2013 01:56:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-not-use-previous-password-in-ise-1-1-2-patch-5/m-p/2203610#M137302</guid>
      <dc:creator>david.tran</dc:creator>
      <dc:date>2013-04-27T01:56:01Z</dc:date>
    </item>
    <item>
      <title>Re: can not use previous password in ISE 1.1.2 patch-5</title>
      <link>https://community.cisco.com/t5/network-access-control/can-not-use-previous-password-in-ise-1-1-2-patch-5/m-p/2203611#M137304</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;ISE 1.2 will have the option to disable password history. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There was a defect in earlier version of ISE.&lt;/P&gt;&lt;P&gt;ISE 1.0.x/1.1.x admin password policies for web UI and CLI are set&amp;nbsp; separately. That is why the defect was declared Junked. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISE 1.2.0 will&amp;nbsp; sync the ones set in the web UI to the CLI.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/cisco/psn/bssprt/bss?searchType=bstbugidsearch&amp;amp;page=bstBugDetail&amp;amp;BugID=CSCtt15284" rel="nofollow" target="_blank"&gt;CSCtt15284&lt;/A&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; password policy no-previous-password does not work &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __jive_macro_name="quote" class="jive_text_macro jive_macro_quote"&gt;&lt;P&gt;In GUI, if you try to set the value as 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You will see a pop-up saying "Password history field value should be between 1 and 10.&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://community.cisco.com/" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In CLI even if you make changes under password-policy and remove "no-previous-password". After that when you try to reset password with the previous one. It throws an error message.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;admin# application reset-passwd ise admin &lt;/P&gt;&lt;P&gt;Enter new password: &lt;/P&gt;&lt;P&gt;Confirm new password: &lt;/P&gt;&lt;P&gt;Password can't be set to one of the earlier 2 password(s)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 27 Apr 2013 11:51:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-not-use-previous-password-in-ise-1-1-2-patch-5/m-p/2203611#M137304</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-04-27T11:51:18Z</dc:date>
    </item>
    <item>
      <title>Re: can not use previous password in ISE 1.1.2 patch-5</title>
      <link>https://community.cisco.com/t5/network-access-control/can-not-use-previous-password-in-ise-1-1-2-patch-5/m-p/2203612#M137306</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I can NOT see this bug ID.&amp;nbsp; I dont' think the bug ID is available to cisco customers unless you work for Cisco&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 27 Apr 2013 18:24:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-not-use-previous-password-in-ise-1-1-2-patch-5/m-p/2203612#M137306</guid>
      <dc:creator>david.tran</dc:creator>
      <dc:date>2013-04-27T18:24:27Z</dc:date>
    </item>
    <item>
      <title>Re: can not use previous password in ISE 1.1.2 patch-5</title>
      <link>https://community.cisco.com/t5/network-access-control/can-not-use-previous-password-in-ise-1-1-2-patch-5/m-p/2203613#M137309</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You might not be able to see as it's an internal defect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is what we have in the contents.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The password policy no-previous-password option is for CLI users (admin) and it is working properly as below&lt;/P&gt;&lt;P&gt;ISEVM-22/admin(config)# username admin password plain Lab123 role ?&lt;/P&gt;&lt;P&gt;&amp;nbsp; admin&amp;nbsp; Specifies user with administrative role privileges&lt;/P&gt;&lt;P&gt;&amp;nbsp; user&amp;nbsp;&amp;nbsp; Specifies user with read-only role privileges&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For application reset-passwd ise &lt;GUI admin=""&gt; is for ISE application and password policy configured in ISE admin settings will enforce the password policy as configured, by default it is last three passwords&lt;/GUI&gt;&lt;/P&gt;&lt;P&gt;To set this option from ISE UI, see below navigation Administration--&amp;gt; System-&amp;gt; Admin Access -&amp;gt; Authentication --&amp;gt; Password Policy --&amp;gt; Password History&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; &lt;BR /&gt; &lt;BR /&gt;- Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 27 Apr 2013 19:20:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-not-use-previous-password-in-ise-1-1-2-patch-5/m-p/2203613#M137309</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-04-27T19:20:09Z</dc:date>
    </item>
    <item>
      <title>Re: can not use previous password in ISE 1.1.2 patch-5</title>
      <link>https://community.cisco.com/t5/network-access-control/can-not-use-previous-password-in-ise-1-1-2-patch-5/m-p/2203614#M137312</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for confirming this.&amp;nbsp; I opened a TAC case with Cisco last week and they also told me the same thing.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 27 Apr 2013 22:39:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-not-use-previous-password-in-ise-1-1-2-patch-5/m-p/2203614#M137312</guid>
      <dc:creator>david.tran</dc:creator>
      <dc:date>2013-04-27T22:39:57Z</dc:date>
    </item>
    <item>
      <title>Re: can not use previous password in ISE 1.1.2 patch-5</title>
      <link>https://community.cisco.com/t5/network-access-control/can-not-use-previous-password-in-ise-1-1-2-patch-5/m-p/2203615#M137315</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I see...I would appreciate if you can mark this thread resolved so that other's can benefit from it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jatin Katyal &lt;BR /&gt; - Do rate helpful posts -&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 28 Apr 2013 05:53:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/can-not-use-previous-password-in-ise-1-1-2-patch-5/m-p/2203615#M137315</guid>
      <dc:creator>Jatin Katyal</dc:creator>
      <dc:date>2013-04-28T05:53:34Z</dc:date>
    </item>
  </channel>
</rss>

