Password DictionaryPassword Dictionary
The password dictionary is a text file that contains words that cannot be used as passwords. When an administrator or user creates or changes a user’s password, the password is validated against the password dictionary. If the new password matches any words found in the password dictionary, the password is not accepted.
You associate the password dictionary with each security domain through the security domain password policy, using the Exclude Words Dictionary field. If you do not select the password dictionary, the security domain does not validate passwords against it, even if a password dictionary is installed. For more information,see Password Policy.
Add a Password DictionaryAdd a Password Dictionary
A password dictionary is a text file that contains words that cannot be used as passwords. You can import a password dictionary.
Before you begin
Create a password dictionary. Create a text file and enter each dictionary entry on a separate line. When you save the file, verify that the file is smaller than 200 MB.
Procedure
-
In the Security Console, click Setup > System Settings.
-
Under Authentication Settings, click Password Dictionary.
-
Under Password Dictionary, make sure that the status is No password dictionary found. If the status is Password dictionary imported, you must first delete the existing password dictionary before adding a new one. For instructions, see Delete a Password Dictionary.
-
In the Password Dictionary Name list, click Import Password Dictionary File.
-
Under Password Dictionary Basics, enter the name of the password dictionary that you are importing in the Password Dictionary Name field.
-
Under Password Dictionary File, browse to the password dictionary file that you are importing.
-
When prompted, select the password dictionary filename, and click Open.
-
Click Import File.
The import process can take several minutes.
-
Click Update Status to refresh. When the status shows Password dictionary imported, the name of the new password dictionary is displayed in the Password Dictionary Name list.
-
Click Done.
Export a Password DictionaryExport a Password Dictionary
When an administrator or user creates or changes a user's password, the password is validated against the password dictionary. If the new password matches any words found in the password dictionary, the password is not accepted.
To make a copy of the password dictionary for your deployment, export the dictionary.
Before you begin
Verify that the password dictionary file is smaller than 200 MB.
Procedure
-
In the Security Console, click Setup > System Settings.
-
Click Password Dictionary.
-
Click the password dictionary that you want to export, and select Export Dictionary File.
-
Save the dictionary file.
Delete a Password DictionaryDelete a Password Dictionary
Your deployment supports one password dictionary. To change password dictionaries, or to remove a dictionary that is not in use, delete the password dictionary.
Before you begin
Verify whether the password dictionary you want to delete is in use. Check the Exclude Words Dictionary field for each security domain password policy. For more information, see Password Policy.
Procedure
-
In the Security Console, click Setup > System Settings.
-
Click Password Dictionary.
-
Click the password dictionary that you want to delete, and select Delete.
-
Click OK to confirm the deletion.