Attribute Value Password Validator

The Attribute Value Password Validator attempts to determine whether a proposed password is acceptable for use by determining whether that password is contained in any attribute within the user's entry.

It can be configured to look in all attributes or in a specified subset of attributes.

Parent

The Attribute Value Password Validator object inherits from Password Validator.

Properties

Use the --advanced option to access advanced properties.

Basic Properties

check-substrings

SynopsisIndicates whether this password validator is to match portions of the password string against attribute values.
DescriptionIf "false" then only match the entire password against attribute values otherwise ("true") check whether the password contains attribute values.
Default Valuetrue
Allowed Valuestrue
false
Multi-valuedNo
RequiredNo
Admin Action RequiredNone
AdvancedNo
Read-OnlyNo

enabled

SynopsisIndicates whether the password validator is enabled for use.
Default ValueNone
Allowed Valuestrue
false
Multi-valuedNo
RequiredYes
Admin Action RequiredNone
AdvancedNo
Read-OnlyNo

match-attribute

SynopsisSpecifies the name(s) of the attribute(s) whose values should be checked to determine whether they match the provided password. If no values are provided, then the server checks if the proposed password matches the value of any attribute in the user's entry.
Default ValueAll attributes in the user entry will be checked.
Allowed ValuesThe name of an attribute type defined in the LDAP schema.
Multi-valuedYes
RequiredNo
Admin Action RequiredNone
AdvancedNo
Read-OnlyNo

min-substring-length

SynopsisIndicates the minimal length of the substring within the password in case substring checking is enabled.
DescriptionIf "check-substrings" option is set to true, then this parameter defines the length of the smallest word which should be used for substring matching. Use with caution because values below 3 might disqualify valid passwords.
Default Value5
Allowed ValuesAn integer. Lower limit: 0.
Multi-valuedNo
RequiredNo
Admin Action RequiredNone
AdvancedNo
Read-OnlyNo

test-reversed-password

SynopsisIndicates whether this password validator should test the reversed value of the provided password as well as the order in which it was given.
Default ValueNone
Allowed Valuestrue
false
Multi-valuedNo
RequiredYes
Admin Action RequiredNone
AdvancedNo
Read-OnlyNo

Advanced Properties

java-class

SynopsisSpecifies the fully-qualified name of the Java class that provides the password validator implementation.
Default Valueorg.opends.server.extensions.AttributeValuePasswordValidator
Allowed ValuesA Java class that extends or implements:
org.opends.server.api.PasswordValidator
Multi-valuedNo
RequiredYes
Admin Action RequiredThe object must be disabled and re-enabled for changes to take effect.
AdvancedYes
Read-OnlyNo