cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
668
Views
0
Helpful
1
Replies

Two questions regarding ACS 5.1: Password aging and enabling multiple disabled accounts

zzs-bzwbk
Level 1
Level 1

Hello,

I'm testing password aging in ACS 5.1, and I've found out that one can have only one global setting for the password lifetime for all internal accounts. Is there a possibility to exclude some internal accounts from this global password aging policy? I would like to have certain number of accounts, whose passwords shouldn't be aged at all...

Second question: when i was testing password aging, i've set password lifetime to 4 days with warning after 2 days. All accounts in my test ACS setup are now disabled, because 4 days passed from when i've changed this. Is there a possibility to enable multiple accouns at one time, or do i have to enable 500 internal accounts manually, one by one ?

thanks in advance

WM

1 Accepted Solution

Accepted Solutions

jrabinow
Level 7
Level 7

I am not aware of any way to mark internal users as having passwords that enver expire. This is done for admins to ensure there is always one admin that can access the system

In order to change multiple/all records for the internal users the following approach can be taken:

  1. Go to internal users list and press "Export" then "Start Export" and "Save File" to export the user records to a csv file
  2. Edit the file. In column with title "enabled" change "FALSE" to "TRUE" for all records. Save the updated file
  3. For internal user list page, press "File Options", select "Update" and then next to get to "Import File" section of wizard. Select the file saved in step 2) and press Finish

Afetr imort completes, all the internal user records should now show as "Enabled"

View solution in original post

1 Reply 1

jrabinow
Level 7
Level 7

I am not aware of any way to mark internal users as having passwords that enver expire. This is done for admins to ensure there is always one admin that can access the system

In order to change multiple/all records for the internal users the following approach can be taken:

  1. Go to internal users list and press "Export" then "Start Export" and "Save File" to export the user records to a csv file
  2. Edit the file. In column with title "enabled" change "FALSE" to "TRUE" for all records. Save the updated file
  3. For internal user list page, press "File Options", select "Update" and then next to get to "Import File" section of wizard. Select the file saved in step 2) and press Finish

Afetr imort completes, all the internal user records should now show as "Enabled"