Enforcing a password policy introduction
BMC Remedy AR System ensures that passwords are always encrypted. An SHA-256 hash of passwords is stored in the database, ensuring that the system (and so the reader of the database) cannot retrieve passwords. In addition, you can enforce a password policy with the User Password Management Configuration form.
User Password Management Configuration form
(Click the image to expand it.)
The password management feature is preconfigured when you install BMC Remedy Encryption Security, but it is not enabled. This section describes how to enable and use the feature.
With a password policy, you can:
- Force all users or individual users to change their passwords when they use a browser
- Enforce restrictions on passwords [Health Insurance Portability and Accountability Act (HIPAA) standards are shipped as the default restrictions.]
- Set up password expiration with scheduled warnings
- Disable an account after the expiration period
- Enable users to change their passwords at will
Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*