    Password Changes - Are Diffs From Old Tunable?




      My "Global Password Policy" is setup to always check complexity, where complexity, amongst others,  is:

      pwd-strong-check-require-charset   :  any-three


      Password must contain a min of 8 characters, 3 of 4 must be 1 upper, 1 lower, 1 special &/or 1 numeric.



      While I intend to enforce even stricter rules later, I right now want my users to be able to change their password to a new one that is different by just one character only.


      Right now, my users are getting errors when they attempt to change their password, error states that their new password was already used/in history.


      Is this a tunable parameter?  I am at a loss as to why they are getting these errors otherwise.


      Thanks all in advance.