11-02-2017 07:29 AM - edited 03-08-2019 12:35 PM
Hi,
i have a Cisco 4500X-16 with IOS-XE 15.2(4)E5
The maximum password length is 26 characters. Does anyone knows how to increase this value in combination with aaa?
I don't have this issue with IOS-XE 15.2(3)E2
regards,
Pascal
11-02-2017 08:20 AM
Hello,
I think you can set this under the common criteria policy:
aaa common-criteria policy policy-name
max-length number
11-02-2017 08:22 AM
Hi George,
i have already tried that, but that doesn't work.
regards,
Pascal
11-02-2017 08:43 AM
Hello,
what is the output of 'show aaa common-criteria policy name policy-name '
Does it work when you define a user as below:
username username common-criteria-policy policy-name password password
11-02-2017 09:35 AM
How did you configure this is IOS-XE 15.2(3)E2 ? Are you running the same license now as in IOS-XE 15.2(3)E2 ?
11-03-2017 02:31 AM
i didn't need to configure this for IOS-XS 15.2(3)E2. It just works.
License 152-4.E5:
License Information for 'WS-C4500X-16'
License Level: entservices Type: Permanent Right-To-Use
License 15.2(3)E2:
License Information for 'WS-C4500X-16'
License Level: entservices Type: Permanent
11-03-2017 02:36 AM
i have configured a username attachted to a policy, but that doesn't work.
username test common-criteria-policy test password xxx
#sh aaa common-criteria policy all
=======================================================
Policy name: test
Minimum length: 1
Maximum length: 127
Upper Count: 0
Lower Count: 0
Numeric Count: 0
Special Count: 0
Number of character changes 4
Valid forever. User tied to this policy will not expire
=======================================================
This is the message i receive back when i log in with a password more then 26 characters:
username/password incorrect: EOF received from remote side [Unknown cause]
07-04-2018 12:54 AM
Dear all,
I have the same problem on a 4500X running IOS 15.2(6)E.
We use TACACS+ with Cisco ACS and some of our static management system users have more than 25 characters in their password.
They can't login to the switch, but there is also no failed message on the Cisco ACS for this login.
Is this max number of 26 characters also in use for TACACS+ users? And if yes, is it possible to increase this?
Thanks!
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: