TIBCO Cloud User Account Password Policy

TIBCO Cloud User Account Password Policy

book

Article ID: KB0072048

calendar_today

Updated On:

Products Versions
TIBCO Cloud -

Description

There are two broad types of login credentials that are authenticated by the TIBCO Account.

Credential Types

  • "User Accounts" ie TIBCO Account credentials used by individuals
  • "Service Accounts" ie TIBCO Account credentials used by systems that run on servers.

Credentials not managed by TIBCO Account

Not all login credentials are "stored" within the TIBCO Account.  Some login credentials are stored in systems 'external' to the TIBCO Account.   Hence, TIBCO Account does not manage the password rules for these types of credentials. In fact, the TIBCO Account cannot even 'see' the passwords for these credentials.   These include - 

  1. TIBCO Personnel - TIBCO Personnel's passwords are managed and governed by the TIBCO Corporate Active Directory password policies

  2. Customers who are set up to authenticate using their company's LDAP credentials - These passwords are maintained and managed by the specific customer's corporate LDAP/AD system.

  3. Customers who are set up to authenticate using their company's SSO systems - These passwords are maintained and managed by the specific customer's corporate Single Sign-On system.

  4. Google User - These passwords are maintained and managed by Google's authentication system.

Password rules for TIBCO Account managed user credentials

User Accounts

ConfigurationDescription
Maximum Password HistoryMust not match previous 1 password
Maximum Password AgeNone
Minimum Password Age0 days
Minimum Password Length8 characters
Password complexityMust have at least 3 of the 4 characters - an upper case, a lower case, a number, or a special character 
Maximum Attempts before Account Lockout3 Consecutive unsuccessful login attempts. 
Account Lockout Duration

1 minute 

Note - This 'account lockout timer' only starts after the 'Maximum Attempts before Account Lockout' is met.

Reset account lockout counter after1 minute as defined by account lockout duration
Initial Password ChangePassword set by the user at the time of activating the account
Password DisplayNot displayed by default.  User can user chooses to temporarily override the default.
 

Service Account

ConfigurationDescription
Maximum Password HistoryMust not match previous 1 password
Maximum Password AgeNone
Minimum Password Age0 days
Minimum Password Length8 characters
Password complexityMust have at least 3 of the 4 characters - an upper case, a lower case, a number, or a special character 
Maximum Attempts before Account Lockout3 Consecutive unsuccessful login attempts. 
Account Lockout Duration

1 minute 

Note - This 'account lockout timer' only starts after the 'Maximum Attempts before Account Lockout' is met.

Reset account lockout counter after1 minute as defined by account lockout duration
Initial Password ChangeNot Applicable 
Password DisplayThere is no screen to display the password.  Systems authenticate using a 'Service Account' via API calls.

A note about passwords stored in the TIBCO Account

Passwords are stored using a sha256 hash mechanism with salt. What this basically means is that no person, including the TIBCO Account system administrators, can extract the password stored in the system.

 

Issue/Introduction

This document describes the TIBCO Cloud account password policy for passwords directly managed by TIBCO Account

Environment

TIBCO Cloud