<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Password expired in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/password-expired/m-p/1909413#M182486</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please make sure that your setup has been done according to th following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;STEP 1:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To make internal user accounts never expire, Go to System Administration &amp;gt;&lt;/P&gt;&lt;P&gt;Users &amp;gt; Authentication Settings:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Select the "Advanced" tab and select "Never" under "Account&lt;/P&gt;&lt;P&gt;Disable".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; If you want to notify users for password expiry then under the "Advanced"&lt;/P&gt;&lt;P&gt;tab:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Select "Display Reminder after n days" under "Password Lifetime"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;("n" can be days from 1 to 365)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;STEP 2:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) System Administration &amp;gt; Configuration &amp;gt; Dictionaries &amp;gt; Identity &amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Internal Users add Boolean attribute with name "ACS-RESERVED-Never-Expired"&lt;/P&gt;&lt;P&gt;and set it to false.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) Go to the user you don't want the password to expire and set the&lt;/P&gt;&lt;P&gt;"ACS-RESERVED-Never-Expired" this field to be true, do the same for each&lt;/P&gt;&lt;P&gt;account that you do not want the password to expire&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 15 May 2012 21:36:54 GMT</pubDate>
    <dc:creator>maldehne</dc:creator>
    <dc:date>2012-05-15T21:36:54Z</dc:date>
    <item>
      <title>Password expired</title>
      <link>https://community.cisco.com/t5/network-access-control/password-expired/m-p/1909408#M182481</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;today we had an issue with our ACS 5.2.0.26.8. For some 802.1x Accounts i have configured ACS–RESERVED–Never–Expired=True but today all of them were set to expired as i could see in the ACS Instance Logfile. Blocking Reason=PASSWORD_EXPIRED.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any hints on that?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards, Andreas&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 02:05:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/password-expired/m-p/1909408#M182481</guid>
      <dc:creator>acontes</dc:creator>
      <dc:date>2019-03-11T02:05:05Z</dc:date>
    </item>
    <item>
      <title>Password expired</title>
      <link>https://community.cisco.com/t5/network-access-control/password-expired/m-p/1909409#M182482</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Andreas&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What type of EAP authentication are you using?&lt;/P&gt;&lt;P&gt;Can you please send me screen shots from Users --&amp;gt; Authentication Settings&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Screen shot from the Access Service where the EAP protocols detailed are viewed?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sample screen shot from the settings of internal user?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 14 May 2012 06:21:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/password-expired/m-p/1909409#M182482</guid>
      <dc:creator>maldehne</dc:creator>
      <dc:date>2012-05-14T06:21:51Z</dc:date>
    </item>
    <item>
      <title>Password expired</title>
      <link>https://community.cisco.com/t5/network-access-control/password-expired/m-p/1909410#M182483</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi maldehne&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we have the same problem, I used it for TACACS+ Authentication, here you find the "allowed protocols" for our access service.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/5/7/5/89575-TACACS%2B%20Protocols.png" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do I need to enable MSCHAPv2 for ACS-RESERVED-Never-Expired to work?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;Dominic&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 May 2012 09:37:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/password-expired/m-p/1909410#M182483</guid>
      <dc:creator>Dominic Stalder (old profile)</dc:creator>
      <dc:date>2012-05-15T09:37:36Z</dc:date>
    </item>
    <item>
      <title>Password expired</title>
      <link>https://community.cisco.com/t5/network-access-control/password-expired/m-p/1909411#M182484</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Dominic &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please try to redefine the attribute again by manually&amp;nbsp; entering the attribute, sometimes copy and paste might cause&amp;nbsp; replacement of&amp;nbsp; '-' with space. I have seen that in one case before.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also do you have any policy condition mapped to the attribute , if so try to disable it and let me know how it goes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 May 2012 11:23:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/password-expired/m-p/1909411#M182484</guid>
      <dc:creator>maldehne</dc:creator>
      <dc:date>2012-05-15T11:23:33Z</dc:date>
    </item>
    <item>
      <title>Re: Password expired</title>
      <link>https://community.cisco.com/t5/network-access-control/password-expired/m-p/1909412#M182485</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi maldehne&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for your fast feedback. Indeed, when I entered the attribute manuelly, the dropdown (with previous entered values) of the browser disapeared after the ACS-, so there was a copy/paste problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;BUT this did not solve the problem yet, I still get the following login prompt:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;username: test2&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;password: &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Enter new password:&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Below you see some more configuration details. We use ACS 5.3.0.40.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot and best regards&lt;/P&gt;&lt;P&gt;Dominic&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/6/8/5/89586-Password%20Policy.png" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/7/8/5/89587-ACS-RESERVED-Never-Expired1.png" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/8/8/5/89588-ACS-RESERVED-Never-Expired2.png" class="jive-image" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 May 2012 11:38:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/password-expired/m-p/1909412#M182485</guid>
      <dc:creator>Dominic Stalder (old profile)</dc:creator>
      <dc:date>2012-05-15T11:38:30Z</dc:date>
    </item>
    <item>
      <title>Re: Password expired</title>
      <link>https://community.cisco.com/t5/network-access-control/password-expired/m-p/1909413#M182486</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Please make sure that your setup has been done according to th following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;STEP 1:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To make internal user accounts never expire, Go to System Administration &amp;gt;&lt;/P&gt;&lt;P&gt;Users &amp;gt; Authentication Settings:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Select the "Advanced" tab and select "Never" under "Account&lt;/P&gt;&lt;P&gt;Disable".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; If you want to notify users for password expiry then under the "Advanced"&lt;/P&gt;&lt;P&gt;tab:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;.&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Select "Display Reminder after n days" under "Password Lifetime"&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;("n" can be days from 1 to 365)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;STEP 2:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1) System Administration &amp;gt; Configuration &amp;gt; Dictionaries &amp;gt; Identity &amp;gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Internal Users add Boolean attribute with name "ACS-RESERVED-Never-Expired"&lt;/P&gt;&lt;P&gt;and set it to false.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2) Go to the user you don't want the password to expire and set the&lt;/P&gt;&lt;P&gt;"ACS-RESERVED-Never-Expired" this field to be true, do the same for each&lt;/P&gt;&lt;P&gt;account that you do not want the password to expire&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 May 2012 21:36:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/password-expired/m-p/1909413#M182486</guid>
      <dc:creator>maldehne</dc:creator>
      <dc:date>2012-05-15T21:36:54Z</dc:date>
    </item>
    <item>
      <title>Re: Password expired</title>
      <link>https://community.cisco.com/t5/network-access-control/password-expired/m-p/1909414#M182487</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Great, I did not know, that the default value has to be FALSE in anyway, I thought I can use TRUE OR FALSE, but it is definitely only FALSE.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot and best regards (5 points to go... &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Dominic&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 15 May 2012 22:31:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/password-expired/m-p/1909414#M182487</guid>
      <dc:creator>Dominic Stalder (old profile)</dc:creator>
      <dc:date>2012-05-15T22:31:26Z</dc:date>
    </item>
    <item>
      <title>Re: Password expired</title>
      <link>https://community.cisco.com/t5/network-access-control/password-expired/m-p/1909415#M182488</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; BTW Dominic please make sure to flag the thread as solved.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/4.5.4/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 May 2012 06:22:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/password-expired/m-p/1909415#M182488</guid>
      <dc:creator>maldehne</dc:creator>
      <dc:date>2012-05-16T06:22:56Z</dc:date>
    </item>
    <item>
      <title>Re: Password expired</title>
      <link>https://community.cisco.com/t5/network-access-control/password-expired/m-p/1909416#M182489</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I would like, but because it is not MY discussion, I can not mark your great answer as the correct one!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry for that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;Dominic&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 May 2012 06:34:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/password-expired/m-p/1909416#M182489</guid>
      <dc:creator>Dominic Stalder (old profile)</dc:creator>
      <dc:date>2012-05-16T06:34:34Z</dc:date>
    </item>
    <item>
      <title>Password expired</title>
      <link>https://community.cisco.com/t5/network-access-control/password-expired/m-p/1909417#M182490</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Before, authentication failed because of "password expired".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But now I am struggling with an another issue. The password now will not expire, but authentications failed because of the following reason "24203 User need to change password".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cant believe that...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have to say this: ACS 5 is a really epic fail with these user specific parameters. i cant migrate my 802.1x users, my vpn users and my technical users (i.e. for cisco works). all because of this password expire "thing".&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Looks like i really have to buy 2 acs systems. one with tacacs config for device administration and password expiration and one with radius config for network access without password expiration &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 28 Sep 2012 08:25:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/password-expired/m-p/1909417#M182490</guid>
      <dc:creator>acontes</dc:creator>
      <dc:date>2012-09-28T08:25:58Z</dc:date>
    </item>
  </channel>
</rss>

