EXPERT RESPONSE
I think I would set values for just about all the profile parameters if your
company and application will tolerate them. I'd start with these:
failed_login_attempts 3
password_life_time 60
password_reuse_time 250
password_reuse_max unlimited
password_lock_time unlimited
password_grace_time 7
password_verify_function your_custom_func_here
|