Skip to content

Commit 2a17c13

Browse files
committed
add password policy example
1 parent b7da890 commit 2a17c13

File tree

4 files changed

+40
-8
lines changed
  • content/vault

4 files changed

+40
-8
lines changed

content/vault/v1.18.x/content/docs/secrets/ldap.mdx

Lines changed: 10 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -85,7 +85,7 @@ parameter:
8585

8686
- `password` (Default): The engine will generate and manage standard RACF passwords.
8787

88-
- `phrase`: The engine will generate and manage case-sensitive password phrases (14-100 characters).
88+
- `phrase`: The engine will generate and manage case-sensitive password phrases.
8989

9090
#### Configuring Password Rules
9191

@@ -101,7 +101,15 @@ password phrases, and links a password policy to enforce length and
101101
complexity.
102102

103103
```shell-session
104-
vault write ldap/config \
104+
$ cat > /tmp/password_policy.hcl <<-EOF
105+
length = 20
106+
rule "charset" {
107+
charset = "abcdefghijklmnopqrstuvwxyz"
108+
min-chars = 1
109+
}
110+
EOF
111+
$ vault write sys/policies/password/racf_password_policy policy=@/tmp/password_policy.hcl
112+
$ vault write ldap/config \
105113
binddn="$USERNAME" \
106114
bindpass="$PASSWORD" \
107115
url="ldaps://138.91.247.105" \

content/vault/v1.19.x/content/docs/secrets/ldap.mdx

Lines changed: 10 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -85,7 +85,7 @@ parameter:
8585

8686
- `password` (Default): The engine will generate and manage standard RACF passwords.
8787

88-
- `phrase`: The engine will generate and manage case-sensitive password phrases (14-100 characters).
88+
- `phrase`: The engine will generate and manage case-sensitive password phrases.
8989

9090
#### Configuring Password Rules
9191

@@ -101,7 +101,15 @@ password phrases, and links a password policy to enforce length and
101101
complexity.
102102

103103
```shell-session
104-
vault write ldap/config \
104+
$ cat > /tmp/password_policy.hcl <<-EOF
105+
length = 20
106+
rule "charset" {
107+
charset = "abcdefghijklmnopqrstuvwxyz"
108+
min-chars = 1
109+
}
110+
EOF
111+
$ vault write sys/policies/password/racf_password_policy policy=@/tmp/password_policy.hcl
112+
$ vault write ldap/config \
105113
binddn="$USERNAME" \
106114
bindpass="$PASSWORD" \
107115
url="ldaps://138.91.247.105" \

content/vault/v1.20.x/content/docs/secrets/ldap.mdx

Lines changed: 10 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -85,7 +85,7 @@ parameter:
8585

8686
- `password` (Default): The engine will generate and manage standard RACF passwords.
8787

88-
- `phrase`: The engine will generate and manage case-sensitive password phrases (14-100 characters).
88+
- `phrase`: The engine will generate and manage case-sensitive password phrases.
8989

9090
#### Configuring Password Rules
9191

@@ -101,7 +101,15 @@ password phrases, and links a password policy to enforce length and
101101
complexity.
102102

103103
```shell-session
104-
vault write ldap/config \
104+
$ cat > /tmp/password_policy.hcl <<-EOF
105+
length = 20
106+
rule "charset" {
107+
charset = "abcdefghijklmnopqrstuvwxyz"
108+
min-chars = 1
109+
}
110+
EOF
111+
$ vault write sys/policies/password/racf_password_policy policy=@/tmp/password_policy.hcl
112+
$ vault write ldap/config \
105113
binddn="$USERNAME" \
106114
bindpass="$PASSWORD" \
107115
url="ldaps://138.91.247.105" \

content/vault/v1.21.x (rc)/content/docs/secrets/ldap.mdx

Lines changed: 10 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -85,7 +85,7 @@ parameter:
8585

8686
- `password` (Default): The engine will generate and manage standard RACF passwords.
8787

88-
- `phrase`: The engine will generate and manage case-sensitive password phrases (14-100 characters).
88+
- `phrase`: The engine will generate and manage case-sensitive password phrases.
8989

9090
#### Configuring Password Rules
9191

@@ -101,7 +101,15 @@ password phrases, and links a password policy to enforce length and
101101
complexity.
102102

103103
```shell-session
104-
vault write ldap/config \
104+
$ cat > /tmp/password_policy.hcl <<-EOF
105+
length = 20
106+
rule "charset" {
107+
charset = "abcdefghijklmnopqrstuvwxyz"
108+
min-chars = 1
109+
}
110+
EOF
111+
$ vault write sys/policies/password/racf_password_policy policy=@/tmp/password_policy.hcl
112+
$ vault write ldap/config \
105113
binddn="$USERNAME" \
106114
bindpass="$PASSWORD" \
107115
url="ldaps://138.91.247.105" \

0 commit comments

Comments
 (0)