The user-security-policy enable command configures a user security policy.
The undo user-security-policy enable command cancels the configuration.
By default, a user security policy is configured.
Usage Scenario
To prevent account stealing due to simple passwords, run the user-security-policy enable command to configure a user security policy.
Prerequisites
A level-3 or higher-level local user has logged in to the device.
Configuration Impact
After the user-security-policy enable command is run, the user name and password in the AAA view or local AAA server view must comply with the following rules:
Precautions
After the password is reset, the user is required to change the password upon the first login.
If the login password does not satisfy the user security policy, the system prompts you to change your password. Change your password based on the prompted message.
The undo user-security-policy enable command deletes a security policy for local user names and passwords, which reduces local user account security. Therefore, configuring a local user account security policy is recommended.
The user-security-policy enable command takes effect for new users and does not affect existing users.
After you configure the user-security-policy enable command, the restrictions on local user names and passwords are as follows:
A changed local account irreversible password will be saved as a ciphertext password that cannot be used for CHAP authentication users, such as PPP users. But a changed local account of reversible password will be saved as a ciphertext password that can be used for CHAP authentication users when a user password is modified, the old password should be input.