< Home

password alert original

Function

The password alert original command enables the device to prompt users to change initial passwords.

The undo password alert original command disables the device from prompting users to change initial passwords.

By default, the device prompts users to change initial passwords.

Format

password alert original

undo password alert original

Parameters

None

Views

Local administrator password policy view

Default Level

3: Management level

Usage Guidelines

Usage Scenario

To improve device security, use this command to enable the initial password change prompt function. When a user logs in to the device:
  • If the user enters the initial password, the device displays a message to ask whether to change the initial password. The user can select Y or N:
    • If the user selects Y to change the password, the user needs to enter the old password, new password, and confirm password. The password can be successfully changed only when the old password is correct and the new password and confirm password are the same and meet requirements (password length and complexity). After the password is changed, the user can log in to the device successfully.
    • If the user selects N or fails to change the password, and the initial password is the default password, the device does not allow the user to log in. If the initial password is not the default password, the device allows the user to log in.
  • If the entered password is not the initial password, the device does not display any message and the user can successfully log in.

After the undo password alert original command is executed, the initial password alert will be disabled, causing a security risk.

The initial password may be the default password, the password created by a local user in the first login, or the password changed by another user (for example, user B changes user A's password, and user A uses the changed password to log in. The device displays a prompt message in this situation).

Precautions

This function is only valid for Telnet users, HTTP users, SSH users, and terminal users.

Example

# Enable the device to prompt users to change initial passwords.
<HUAWEI> system-view
[HUAWEI] aaa
[HUAWEI-aaa] local-aaa-user password policy administrator
[HUAWEI-aaa-lupp-admin] password alert original
Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >