You are viewing limited content. For full access, please sign in.

Question

Question

Feature Request: Enable Password Policy by Default for New Repository

asked on June 16 Show version history

In recent Laserfiche Server updates, creating a new repository now requires the admin password to be at least 12 characters long, and the Password Policy options have been updated as well. However, after the repository is created, the Complexity Requirements are not enabled by default. This feels inconsistent with the intent of the security enhancements.

There’s also a mismatch between the initial requirement and the available policy settings. The admin password must be 12 characters during repository creation, but the predefined complexity options don’t align with that standard—Moderate requires 10 characters, while High requires 16.

It would be more consistent if a default complexity requirement were enabled automatically and the admin password requirement matched that default setting. This would help ensure a more unified and predictable security configuration out of the box.

3 0

Replies

replied on June 17 Show version history

We'll look into changing the default behavior for a new repository to enable the Moderate complexity requirement by default.

Re: not matching the predefined levels: Since the administrator has no way to change the password policy before the repository is created, we wanted to strike a balance between ensuring a strong admin password for initial creation and being excessively restrictive, since the latter is makes people more likely to use insecure options. We were also aiming for a balance between updating standards and disrupting existing settings. We may look at increasing the "moderate" complexity to 12. 

0 0
You are not allowed to follow up in this post.

Sign in to reply to this post.