Skip to main content

Hi all,

Hoping to confirm how these two values in Password Safe global policy (“Minimum (days) retention for old password” and “Number of old passwords to retain”) operate when one value has been reached but not the other.

Eg, if "Number of old passwords to retain" is set to 5 and minimum retention in days is set to 30:-

Observation and some doco suggests that if a password is only changed once a month, password history will be kept for 150 days (despite the 30 day retention period) - assumedly delaying purging to allow the minimum of 5 old passwords to be retained.

Does this apply in the reverse? Ie, with the same settings, if a password is changed daily, will Password Safe retain 30 old passwords so as to satisfy the 30 day minimum retention?

Can anyone confirm?

Thanks!

Be the first to reply!

Reply