The appendix aggregates the default password policy settings for each product within the Identity and Access Management for VMware Cloud Foundation validated solution. You can use this password policy settings list for reference when you perform password management.
ESXi Hosts
Setting |
Default |
Description |
---|---|---|
|
99999 (never) |
Maximum number of days before password expiration |
Setting |
Default |
Description |
---|---|---|
|
retry=3 min=disabled,disabled,disabled,7,7 |
|
|
0 |
Maximum number of passwords that the system remembers |
Setting |
Default |
Description |
---|---|---|
|
5 |
Maximum number of authentication failures before the account is locked |
|
900 |
Amount of time in seconds that the account remains locked |
vCenter Server
Setting |
Default |
Description |
---|---|---|
Maximum (days) |
90 | Maximum number of days between password change |
Minimum (days) |
0 | Minimum number of days between password change |
Warning |
7 | Number of days of warning before a password expires |
Setting |
Default |
Description |
---|---|---|
Password Expires |
Yes |
The virtual appliance root password is set to expire |
Password validity |
90 | Maximum number of days before password expiration |
Email for expiration warning |
- | Email for password expiration warnings |
Warning (days) |
7 | Number of days of warning before a password expires |
Setting |
Default |
Description |
---|---|---|
|
-1 |
Maximum number of digits that generate a credit |
|
-1 |
Maximum number of uppercase characters that generate a credit |
|
-1 |
Maximum number of lowercase characters that generate a credit |
|
-1 |
Maximum number of other characters that generate a credit |
|
6 |
Minimum password length (number of characters) |
|
4 |
Minimum number of characters that must be different from the old password |
|
5 |
Maximum number of passwords that the system remembers |
Setting |
Default |
Description |
---|---|---|
|
3 |
Maximum number of authentication failures before account is locked |
|
900 |
Amount of time in seconds that the account remains locked |
|
300 |
Amount of time in seconds that the root account remains locked |
Setting |
Default |
Description |
---|---|---|
Maximum lifetime |
90 | Maximum number of days before expiration |
Setting |
Default |
Description |
---|---|---|
Restrict reuse |
5 | Number of previous passwords that cannot be reused |
Maximum length |
20 | Maximum password length (number of characters) |
Minimum length |
8 | Minimum password length (number of characters) |
Special characters |
1 | Minimum number of special characters |
Alphabetic characters |
2 | Minimum number of alphabetic characters |
Uppercase characters |
1 | Minimum number of uppercase characters |
Lowercase characters |
1 | Minimum number of lowercase characters |
Numeric characters |
1 | Minimum number of numeric characters |
Identical adjacent characters |
1 | Maximum number of identical adjacent characters |
Setting |
Default |
Description |
---|---|---|
Maximum number of failed login attempts |
5 | Maximum number of authentication failures before the account is locked |
Time interval between failures |
180 | Amount of time in seconds within which failed login attempts must occur to trigger a lockout |
Unlock time |
900 | Amount of time in seconds that the account remains locked. If you set it to 0, the administrator must unlock the account explicitly. |
NSX
Setting |
Default |
Description |
---|---|---|
|
90 |
Maximum number of days between password change |
Setting |
Default |
Description |
---|---|---|
|
-1 |
Maximum number of digits that generate a credit |
|
-1 |
Maximum number of uppercase characters that generate a credit |
|
-1 |
Maximum number of lowercase characters that generate a credit |
|
-1 |
Maximum number of other characters that generate a credit |
|
15 |
Minimum password length (number of characters) |
|
0 |
Minimum number of characters that must be different from the old password |
|
3 |
Maximum number of retries |
Method |
Scope |
Setting |
Default |
Description |
---|---|---|---|---|
API |
NSX Local Manager |
|
5 |
Maximum number of authentication failures before the account is locked |
|
180 |
Amount of time in seconds within which failed login attempts must occur to trigger a lockout |
||
|
900 |
Amount of time in seconds that the account remains locked |
||
CLI |
|
|
5 |
Maximum number of authentication failures before the account is locked |
|
900 |
Amount of time in seconds that the account remains locked |
SDDC Manager
Setting |
Default |
Description |
Notes |
---|---|---|---|
|
90 |
Maximum number of days between password change |
VMware Cloud Foundation 4.5 and later |
365 |
VMware Cloud Foundation 4.4 and later |
||
|
0 |
Minimum number of days between password change. |
- |
|
7 |
Number of days of warning before a password expires |
- |
Setting |
Default |
Description |
---|---|---|
|
-1 |
Maximum number of digits that generate a credit |
|
-1 |
Maximum number of uppercase characters that generate a credit |
|
-1 |
Maximum number of lowercase characters that generate a credit |
|
-1 |
Maximum number of other characters that generate a credit |
|
8 |
Minimum password length (number of characters) |
|
4 |
Minimum number of character types that must be used (for example, uppercase, lowercase, digits, and so on) |
|
4 |
Minimum number of characters that must be different from the old password |
|
3 |
Maximum number of reties |
|
0 |
Maximum number of times a single character can be repeated |
|
5 |
Maximum number of passwords the system remembers |
Setting |
Default |
Description |
---|---|---|
|
3 |
Maximum number of authentication failures before the account is locked |
|
86400 |
Amount of time in seconds that the account remains locked |
|
300 |
Amount of time in seconds that the root account remains locked |