
iDRAC9 Security Configuration Guide
Password Strength Policy
Using iDRAC interface, you can check the password strength policy and check any errors if the policy is not met. The password policy cannot be applied to previously saved passwords, Server Configuration Profiles (SCP) copied from other servers, and embedded passwords in the profile.
In iDRAC9 releases 4.40.00.00 and later, iDRAC offers two password policy options:
- Simple Policy — Simple Policy is based on LUDS, i.e., lower- and uppercase letters, digits, and symbols.
- Regular Expression — Regular Expression Password Policy Enforcement is a based on the POSIX definition.
To access Password settings, go to .
Following fields are available in this section:
- Minimum Score — Specifies the minimum password strength policy score. The values in this field are:
- 0 — No protection
- 1 — Weak protection
- 2 — Medium protection
- 3 — Strong protection
Scoring is based on zxcvbn's entropy value and map to the following values:- 0 - No Protection; too easy to guess: risky password
- 1 - Weak Protection; very easy to guess: protection from throttled online attacks
- 2 - Moderate Protection; somewhat able to guess: protection from un-throttled online attacks
- 3 - Strong Protection; safely to very not able to guess: moderate protection from offline slow-hash scenario
- Simple Policy — Specifies the required characters in a secure password. It has the following options:
- Upper Case Letters
- Numbers
- Symbols
- Minimum Length
- Regular Expression — The Regular expression along with the Minimum score is used for password enforcement.
Please provide ratings (1-5 stars).
Please provide ratings (1-5 stars).
Please provide ratings (1-5 stars).
Please select whether the article was helpful or not.
Comments cannot contain these special characters: <>()\