AIX, Security, System Admin↑ Clearing password history

Sometimes when password rules are very strict, a user may have problems creating a new password that is both easy to remember, and still adheres to the password rules. To aid the user, it could be useful to clear the password history for his or her account, so he or she can re-use a certain password that has been used in the past. The password history is stored in /etc/security/pwdhist.pag and /etc/security/pwdhist.dir. The command you can use to disable the password history for a user is:

# chuser histsize=0 username

Actually, this command does not the password history in /etc/security/pwdhist.dir and /etc/security/pwdhist.pag, but only changes the setting of histsize for the account to zero, meaning, that a user is not checked again on re-using old passwords. After the user has changed his or her password, you may want to set it back again to the default value:

# grep -p ^default /etc/security/user | grep histsize
        histsize = 20
# chuser histsize=20 username

In older AIX levels, this functionality (to use chuser histsize=0) would actually have cleared out the password history of the user. In later AIX levels, this functionality has vanished.

So, if you truely wish to delete the password history for a user, here's another way to clear the password history on a system: It is accomplished by zeroing out the pwdhist.pag and pwdhist.dir files. However, this results in the deletion of all password history for all users on the system:

# cp /dev/null /etc/security/pwdhist.pag
# cp /dev/null /etc/security/pwdhist.dir

Please note that his is a temporary measure. Once these files are zeroed out, as soon as a user changes his or her password again, the old password is stored again in these files and it can't be reused (unless the histsize attribute for a user is set to 0).

0 (0)
Article Rating (No Votes)
Rate this article
Attachments
There are no attachments for this article.
Comments
There are no comments for this article. Be the first to post a comment.
Full Name
Email Address
Security Code Security Code
Related Articles RSS Feed
NMON nmon
Viewed 13411 times since Tue, Apr 16, 2019
Getting bosboot errors, don’t reboot just yet
Viewed 3737 times since Tue, Apr 16, 2019
AIX - How to get Memory infomation
Viewed 12875 times since Fri, Jun 8, 2018
AIX, Security, System Admin Difference between sticky bit and SUID/GUID
Viewed 9862 times since Fri, Apr 19, 2019
AIX, user gets “pwd: The file access permissions do not allow the specified action.”
Viewed 13055 times since Tue, Mar 16, 2021
Top 4 Reasons for Node Reboot or Node Eviction in Real Application Cluster (RAC) Environment
Viewed 107816 times since Thu, Jun 21, 2018
Awesome Command to show top 15 processes using memory on AIX
Viewed 24897 times since Thu, Nov 29, 2018
AIX Not all filesets for 6100-07_AIX_ML were found
Viewed 3887 times since Tue, Jul 17, 2018
How to Configure Sendmail not to Look up MX records
Viewed 4706 times since Fri, Apr 19, 2019
Replacing a failed disk (rootvg)
Viewed 3807 times since Mon, May 21, 2018