In recent Laserfiche Server updates, creating a new repository now requires the admin password to be at least 12 characters long, and the Password Policy options have been updated as well. However, after the repository is created, the Complexity Requirements are not enabled by default. This feels inconsistent with the intent of the security enhancements.
There’s also a mismatch between the initial requirement and the available policy settings. The admin password must be 12 characters during repository creation, but the predefined complexity options don’t align with that standard—Moderate requires 10 characters, while High requires 16.
It would be more consistent if a default complexity requirement were enabled automatically and the admin password requirement matched that default setting. This would help ensure a more unified and predictable security configuration out of the box.