Password Policy
Enforce strong password requirements and security system-wide
Overview
The auth_password_policy module allows configuring password strength, expiration and history requirements.
Helps comply with security regulations and reduce account breach risk.
Key Features
Key points
• Minimum length - Require passwords of 8-16 characters minimum
• Complexity - Enforce uppercase, lowercase, numbers, special characters
• Password expiration - Force password change after 30-90 days
• Password history - Prevent reuse of last 5-10 passwords
• Weak password check - Reject common passwords (123456, password)
• Expiration notifications - Email reminders before password expires
Configure Password Policy
Steps
1. Go to Settings → General Settings → Security
2. Password Policy section, configure parameters
3. Minimum password length: 8-16 characters (recommend 12)
4. Password must contain: Uppercase, lowercase, numbers, special chars
5. Password expiration: 30-90 days (recommend 60)
6. Password history: 5-10 passwords (recommend 5)
7. Click Save
Recommended Configuration
By Security Level
| Level | Length | Complexity | Expiration | History |
|---|---|---|---|---|
| Basic | 8 chars | Letters + numbers | 90 days | 3 passwords |
| Medium | 10 chars | Upper + lower + numbers | 60 days | 5 passwords |
| High | 12 chars | Upper + lower + numbers + special | 30 days | 10 passwords |
Change Password
Steps
1. Go to My Profile → Account Security
2. Password tab, click Change Password
3. Enter current password
4. Enter new password (must meet policy)
5. Confirm new password
6. Click Save