Table of Contents

How to change your CERGE-EI accounts passwords

Because of security measure, CERGE-EI distinguishes between network (domain) passwords and mailserver passwords.

As a result, there are different passwords for your:

Reset Password Guidelines

for Domain account [D]

Username is usualy in the format nsurname (first letter of name + surname, max. 8 characters. e.g. jdoe, bsprings, …). *

Change password

There are two basic ways how you can change your domain account password:

Reset password

You can also reset forgotten password if necessary. You have to have your mobile phone registered at the portal in advance to be able reset password via SMS. If you do not have mobile registered yet, you may send registration request to helpdesk@cerge-ei.cz

See User Accounts page for more details…

Email Accounts Passwords

for Zimbra email Exchange [X]

There are two basic ways how you can change your Zimbra Mailserver account password:

the second way: Use PWMX - Self-service Portal for Zimbra Mail Exchange:

Go to the address https://portal.cerge-ei.cz/pwmx and log with your Zimbra account.

You can also reset forgotten password at the PWMX Portal if necessary

User name is in short format (e.g. jnovak).

Important! You need to have mobile phone number registered at the portal in advance to be able reset password via SMS (Pager attribute)

for Zimbra Archive [A]

Server: https://mailarch.cerge-ei.cz</font>

PWMA - Self-service Portal Go to the address https://portal.cerge-ei.cz/pwma and log with your Archive Zimbra account.

User name is in short format (e.g. jnovak).

You can also reset forgotten password at the PWMA Portal if necessary

Important! You need to have mobile phone number registered at the portal in advance to be able reset password via SMS. (Pager attribute)


MORE DETAILED INFORMATION

Locking the account and mailbox

Account is temporarily locked after several unsuccessful logon attempts with wrong password to avoid abuse and brute force password breaking.
There are three significant parameters of this feature:

The account is locked if the number of allowed fails is exceeded. Failed attempts are counted during the time window. If logon attempts with wrong password stop, the counter is reset after the time window is over. If the account is locked, after the quarantine time it is unlocked again.

Special warning for smartphone users

Smartphones usually use remembered password repeatedly regardless of its validity. Than you can easily lock the mailbox unintentionally.

Threshold parameters - Active Directory

The Active Directory (shortly AD) serves as authentication authority for local network shares, desktop login, internal web pages, CEIS, CMS, Reporting etc.

Account lockout duration: 3 minutes
Account lockout threshold: 7 invalid logon attempts
Account lockout counter reset: after 3 minutes

Threshold parameters - Zimbra mailer

Number of consecutive failed logons allowed: 10
Time to lockout the account: 30 minutes
Time window in which the failed logons must occur to lock the account: 1 hour

Although the AD account is locked earlier, it is also quickly unlocked. If the attack over the mailer persists, the lock on the mailer is activated for a longer period and produces no new lock of the AD account.

FACTS / HINTS

BE AWARE that SMARTPHONES usually use remembered password repeatedly regardless of its validity which results in the account lockdown.

More complex information is available in the User Accounts and Password usage article.

-.-