TeamcenterKnowledge

System Administration > Server manager > Teamcenter management console > Administer embedded LDAP for Teamcenter management console

Set password policies for embedded LDAP

If you use embedded lightweight directory access protocol (LDAP) to provide authorization for user access to the Teamcenter management console, use Apache Directory Studio to administer passwords for the embedded LDAP. Procedure Ensure that JETI Management is running. JETI Management must be running to work with embedded LDAP. Run the following command to start JETI Management: Copy TC_ROOT\mgmt_console\container\bin\trun Install and configure Apache Directory Studio. Run Apache Directory Studio. For example, run the installed-location\Apache Directory Studio\Apache Directory Studio.exe file. To view the default password policy settings provided by Apache Directory Studio, choose the following path in the LDAP Browser view: ou=config→ ads-directoryServiceId=default→ ou=interceptors→ ads-interceptorId=authenticationInterceptor→ ou=passwordPolicies→ ads-pwdId=default The default Apache Directory Studio (ads) password policy attributes are displayed. For a description of all Apache Directory Studio password policy entries, see Apache Directory help. Tip Because the ads-pwdmustchange attribute is set to TRUE, LDAP forces users to change their password upon the first logon after a new Teamcenter user is created or after the password is modified for a Teamcenter user by an LDAP administrator. Following the initial password change, users can subsequently change their Teamcenter Management Console user password. The default embedded LDAP is extended with additional Teamcenter password policy features in the authenticationInterceptorTc interceptor. To view these Teamcenter password policy settings, choose the following path in the LDAP Browser view: ou=config→ ads-directoryServiceId=default→ ou=interceptors→ ads-interceptorId=authenticationInterceptorTc→ ou=passwordPolicies→ ads-pwdId=default The Teamcenter password policy settings are displayed. By default, tc-pwdnotifyemailserver is the only Teamcenter-specific password policy attribute shown. To add more Teamcenter policy entries, click the New Attribute button on the view toolbar. In the New Attribute dialog box, click the arrow in the Attribute type box to see a list of available attributes. Following are some of the available Teamcenter attributes: tc-pwdBlacklist (Optional) Specifies a list of blocklisted passwords. tc-pwdLockNotifyEmails (Optional) Specifies a list of email addresses to send notifications to regarding Teamcenter users locked out of their accounts. tc-pwdNotifyEmailServer (Required) Specifies the name of an email server to be used when sending password policy-related email notifications. pc-pwdPatternsBlacklist (Optional) Specifies a list of entries that are not allowed to be part of a password. tc-pwdRegEx (Optional) Specifies a regular expression identifying a required password pattern. Any changes to password policies requires you to restart the Teamcenter management console before the policy can take effect. After changing password policies, you can use the LDAP Browser view to add Teamcenter users to embedded LDAP.

Source: https://docs.sw.siemens.com/documentation/external/PL20251212545240207/en-US/tc_help/AWAdmin/fhs4814155880506/moj1737238607512/yhr1737238607613/jud1737238609739/xid1071868.html · retrieved Fri Jul 31 2026 00:00:00 GMT+0000 (Coordinated Universal Time)