Lock Expired Initial Passwords Task
Description
Server task that checks all users for too old initial passwords.
If a user account satisfies all of the following conditions, it is locked:
- The account is not marked invalid
- The account is not locked
- A password change is enforced
- The generation date of the password is not null and older than the
initial-password-validity-period (as specified by the configuration of this plugin.
Note: This task determines whether a password is an initial password based only on the facts that the password change flag is set and that there is a password generation date/time. Thus, setting the password change flag to true and not changing an "old" generation date may result in the account being locked by this task.
May be used by
Properties
User Persister (
userPersister) Description
User persister plugin used to read user account data and lock it if necessary.
Attributes
Plugin-Link
Mandatory
Assignable plugins
User Iterator (
userIterator) Description
The user iterator plugin used to iterate over all users.
Usually this is the same as the "User Persister".
Usually this is the same as the "User Persister".
Attributes
Plugin-Link
Mandatory
Assignable plugins
Password Validity Days (
passwordValidityDays) Description
Number of days an initial password is considered valid before it is locked.
Attributes
Long
Mandatory
Delete Password (
deletePassword) Description
If enabled, the password is deleted if the account is locked.
Attributes
Boolean
Optional
Default value
true
YAML Template (with default values)
type: LockExpiredInitialPasswordsTask
id: LockExpiredInitialPasswordsTask-xxxxxx
displayName:
comment:
properties:
deletePassword: true
passwordValidityDays:
userIterator:
userPersister: