Creating a security policy
A security policy sets restrictions on the user accounts that are set up to access iBase. The security policy specifies rules for adding and changing passwords that apply only to user accounts with iBase usernames and passwords.
About this task
New security files do not have a security policy because by default none of the settings on the Security Policy page of the Security Manager are turned on.
The absence of a security policy means that:
- Minimum password length is four-characters.
- No restriction on the characters that are used to make up passwords.
- Passwords never expire.
- No limit to the number of attempts to log on.
- Last used username is displayed at the next logon.
- No password history (although a new password cannot be the same as the current password).
Note: Although a security policy is part of the security file, it is not replicated even if you
choose to replicate the security file. Enabling each site that is involved in iBase Database
Replication to maintain their own security policy. However, the password history is replicated as it
is possible that users might need to log on and change their account details at any of the
sites.
Procedure
To view a security policy or change its settings:
