aaa authentication password local history compare

Prev Next

Use this command to set the number of passwords that are required to be used before a previous password can be reused.

When the local password history feature is enabled, the history of a specified number of passwords is maintained. For example, if 5 is the specified number, users can reuse a password after they change it to something else five times. If the configured number is changed to a lower number, the oldest excess passwords are removed from the history.

The password history is cleared in the following cases:

  • The feature is disabled using the no aaa authentication password local history command.

  • An administrator clears the history using the aaa authentication password local history clear command.

A password can be reused immediately after the password history is cleared, or after the feature is disabled. In both cases, information about the current password, such as the date and time it was set, is retained. For more information, see the Trellix System Security Guide.

Syntax

[no] aaa authentication password local history compare <number>

Parameters

<term>

no

</term>

Removes any constraints about reusing a password (the default behavior).

<term>

number

</term>

The number of times a password must change before it can be reused.

Range: 0–50. Specifying 0 has the same result as using the no parameter.

Example

In this example, all users are required to provide 3 new passwords before repeating a previous password.

hostname (config) # aaa authentication password local history compare 3

User role

Admin

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Central Management System: Release 7.6

  • Email Security — Server: Release 7.6

  • Network Security: Release 7.6

  • Malware Analysis: Release 7.7

  • File Protect: Release 7.7