<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cisco ACS password expiration in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/cisco-acs-password-expiration/m-p/1231725#M373726</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is this bug fixed already??? I need to configure password aging for vpn clients with&lt;/P&gt;&lt;P&gt;users configured on the internal ACS Database.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fernando&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 16 Dec 2009 00:57:43 GMT</pubDate>
    <dc:creator>fernandoaguirre</dc:creator>
    <dc:date>2009-12-16T00:57:43Z</dc:date>
    <item>
      <title>Cisco ACS password expiration</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-password-expiration/m-p/1231716#M373442</link>
      <description>&lt;P&gt;I am trying to configure password aging for my VPN clients.  What I have is a Cisco VPN Concentrator 3000 series that uses an Cisco ACS server 3.3 for user authentication using the local database.  The users are using the Cisco VPN Client, 4.x.  We are upgrading the ACS server to 4.2 shortly if that helps.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I want to be able to do is set the Password Aging rules on the groups in Cisco ACS and have this information pass to the user via the VPN client.  So for example:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;---The user is assigned to group "Accounting" in Cisco ACS.  This group has the Password Aging rule- Apply age-by-uses rules. Issue warning after "2" logins and Require change after "4" logins.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;---The user logs in using the Cisco VPN client and while logging in for the 3rd time receives the message that their account will expire after the next login.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;---This user then has the ability to change their password using the Cisco VPN client.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This seems like it should be fairly straightforward to setup but I have not come across much documentation that spells out the steps to make this work.&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 23:26:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-password-expiration/m-p/1231716#M373442</guid>
      <dc:creator>smolz</dc:creator>
      <dc:date>2019-03-10T23:26:41Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS password expiration</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-password-expiration/m-p/1231717#M373499</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This functionality would be very useful... but its not there.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACS password ageing only works with TACACS+ shell login. AKAIK the password expiry messages are not carried over RADIUS at all.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Apr 2009 13:03:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-password-expiration/m-p/1231717#M373499</guid>
      <dc:creator>darpotter</dc:creator>
      <dc:date>2009-04-17T13:03:58Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS password expiration</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-password-expiration/m-p/1231718#M373563</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I seem to remember reading about using a Microsoft IAS radius server that it would push that through to the VPN client.  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Without the ability for users to change their passwords remotely this seems like an really incomplete solution.  &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Apr 2009 18:04:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-password-expiration/m-p/1231718#M373563</guid>
      <dc:creator>smolz</dc:creator>
      <dc:date>2009-04-17T18:04:06Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS password expiration</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-password-expiration/m-p/1231719#M373605</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;RADIUS Password Expiry is supported with External windows database using MS-CHAPv2. We cannot use RADIUS Password Expiry with local ACS database.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here is a configuration example:&lt;/P&gt;&lt;P&gt;Configure the Cisco VPN 3000 Series Concentrators to Support the NT Password Expiration Feature with the RADIUS Server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Document ID: 12086&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2284/products_configuration_example09186a00800946b9.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2284/products_configuration_example09186a00800946b9.shtml&lt;/A&gt;#&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Apr 2009 18:18:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-password-expiration/m-p/1231719#M373605</guid>
      <dc:creator>ansalaza</dc:creator>
      <dc:date>2009-04-17T18:18:14Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS password expiration</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-password-expiration/m-p/1231720#M373650</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;According to the literature:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Q. Does Cisco Secure ACS support forced password change based on password age and other criteria?&lt;/P&gt;&lt;P&gt;A. Password aging is available for users in the ACS internal database and users in a Microsoft Windows Active Directory database.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does this not apply?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Apr 2009 18:29:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-password-expiration/m-p/1231720#M373650</guid>
      <dc:creator>smolz</dc:creator>
      <dc:date>2009-04-17T18:29:43Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS password expiration</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-password-expiration/m-p/1231721#M373679</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;How does this apply if I am using SSL VPN client/clientless through an Cisco ASA? &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Apr 2009 18:39:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-password-expiration/m-p/1231721#M373679</guid>
      <dc:creator>smolz</dc:creator>
      <dc:date>2009-04-17T18:39:27Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS password expiration</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-password-expiration/m-p/1231722#M373683</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, it does: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACS 3.3:&lt;/P&gt;&lt;P&gt;Cisco Secure ACS supports four distinct password aging mechanisms: &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/3.3/user/guide/g.html#wp479534" target="_blank"&gt;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/3.3/user/guide/g.html#wp479534&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACS 4.2:&lt;/P&gt;&lt;P&gt;Varieties of Password Aging Supported by ACS &lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.2/user/guide/GrpMgt.html#wp525115" target="_blank"&gt;http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.2/user/guide/GrpMgt.html#wp525115&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Apr 2009 18:42:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-password-expiration/m-p/1231722#M373683</guid>
      <dc:creator>ansalaza</dc:creator>
      <dc:date>2009-04-17T18:42:49Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS password expiration</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-password-expiration/m-p/1231723#M373704</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;For SSL:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make sure you have MS-CHAP V2 enabled on AD.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Add password management to the tunnel-group.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;tunnel-group DefaultWEBVPNGroup general-attributes&lt;/P&gt;&lt;P&gt; password-management&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Password-management command support on ASA:&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/webvpn.html#wp1000458" target="_blank"&gt;http://www.cisco.com/en/US/docs/security/asa/asa80/configuration/guide/webvpn.html#wp1000458&lt;/A&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Apr 2009 18:51:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-password-expiration/m-p/1231723#M373704</guid>
      <dc:creator>ansalaza</dc:creator>
      <dc:date>2009-04-17T18:51:26Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS password expiration</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-password-expiration/m-p/1231724#M373716</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is an enhancement request filed for this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CSCsj50218 Bug Details&lt;/P&gt;&lt;P&gt;Password expiry feature should be support for users local to ACS&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Symptom:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ACS currently does not support password expiry / password management feature for locally configured users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Conditions:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;users are configured locally on ACS as opposed to an external database such as active directory.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Workaround:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;user external database / server where user profiles are setup.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Apr 2009 19:09:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-password-expiration/m-p/1231724#M373716</guid>
      <dc:creator>ansalaza</dc:creator>
      <dc:date>2009-04-17T19:09:21Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS password expiration</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-password-expiration/m-p/1231725#M373726</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is this bug fixed already??? I need to configure password aging for vpn clients with&lt;/P&gt;&lt;P&gt;users configured on the internal ACS Database.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Fernando&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Dec 2009 00:57:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-password-expiration/m-p/1231725#M373726</guid>
      <dc:creator>fernandoaguirre</dc:creator>
      <dc:date>2009-12-16T00:57:43Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS password expiration</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-password-expiration/m-p/1231726#M373732</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Password expiry for internal users is supported in ACS 5.1. ACS 5.1 is&lt;/P&gt;&lt;P&gt;available for download from CCO.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Dec 2009 06:13:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-password-expiration/m-p/1231726#M373732</guid>
      <dc:creator>jrabinow</dc:creator>
      <dc:date>2009-12-16T06:13:29Z</dc:date>
    </item>
    <item>
      <title>Re: Cisco ACS password expiration</title>
      <link>https://community.cisco.com/t5/network-access-control/cisco-acs-password-expiration/m-p/1231727#M373739</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is rather old topic but I hope to find help here &lt;SPAN __jive_emoticon_name="happy" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/happy.gif"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Our users are connecting to VPN3000 and authenticated from internal database of ACS 5.1 via RADIUS between these devices. We've installed UCP service. Now I want to remind user whose password should be expired soon that he can change it via UCP (e. g. with link to UCP page). Is there any way to do it with standard features of ACS 5.1 and VPN3000 ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance for any help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Pavel.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Feb 2011 01:31:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/cisco-acs-password-expiration/m-p/1231727#M373739</guid>
      <dc:creator>pbaleshenko</dc:creator>
      <dc:date>2011-02-28T01:31:52Z</dc:date>
    </item>
  </channel>
</rss>

