CSSCurrent en:Password Policy
Security Requirements for passwords
Passwords must contain numbers
Enable this setting to force digits within the password.
Passwords must contain alphabetical characters
Enable this setting to force alphabetical characters within the password.
Passwords must contain special characters
Enable this setting to force special characters within the password.
Passwords must be upper and lower case
Enable this setting to force upper- and lowercase letters within the password
Passwords may not be common words
Enable this setting to countercheck the password, or parts of the password with the dictionary to force users not to use common words in the password. The dictionary consists of English and German words and is applied independently from the language selected in the User Interface.
Character repetitions or character sequences are not allowed
Enable this setting to deny the use of character repetitions or sequences within the password. This applies to the following patterns:
Sequence Type |
Examples |
---|---|
Keyboard Sequences | qwert, asdfg, etc. |
Alphabetical Sequences | abc, xyz. etc. |
Numeric Sequences | 123 etc. |
Character Repetitions | aaa, zzz, 111 etc. |
The patterns mentioned above are recognized as such beginning with a length of three characters.
Minimum/Maximum Password Length
Forces users to use a minimum/maximum number of characters for the password.
Whitespaces within passwords
This setting generally applies and is not visible in the Administration Interface. It forces the users not to use whitespaces within the password, such as 'tab', 'blank space' etc.
Blacklist Characters/Invalid Characters
Characters in this field will not be allowed independently of what has been configured above. If a user enters a password containing one of these characters, the password will not be accepted.
Only for automatically generated passwords
If this option is enabled the blacklist character list will not be taken into consideration for passwords entered manually. Only passwords generated automatically will be affected. This means, that automatically generated passwords won't contain any of the specified characters.