Results 1 to 7 of 7

Thread: Changing password strength requirements

  1. #1
    Member
    Join Date
    Sep 2010
    Posts
    10
    cPanel/WHM Access Level

    Root Administrator

    Default Changing password strength requirements

    First the goods: cPanel 11.24.4-R35075 - WHM 11.24.2 - X 3.9 running on FreeBSD 6.2

    We'd like to raise our minimum password strength from it's current level to 80. How will this affect our current users whose password strength is below that threshold?

    I did a search for this, based on "password strength," and found many discussions, but nothing pointing to this particular question.

    Thanks in advance!

  2. #2
    cPanel Staff cPanelTristan's Avatar
    Join Date
    Oct 2010
    Location
    somewhere over the rainbow
    Posts
    7,611
    cPanel/WHM Access Level

    Root Administrator

    Default Re: Changing password strength requirements

    The change should not impact users who have already set passwords below the minimum threshold unless you also have WHM > Configure Security Policies configured for "Password Age" where they will be required to reset the password when it expires for the aging portion.

    Otherwise, you'd simply have users required to use the correct strength password when creating a new password or changing the existing one. Old passwords should still work until the user chooses to change the password in the future and will be bound by the new password strength level.

    Please note that I tested this by increasing the WHM > Password Strength Configuration area to 80 for all options listed there, and I then logged into an account that had a weak password already set. That cPanel user login was still working and I did not have to change the password.

    Even though you appear to be using an older cPanel version, the functionality should still work the same on that version. I would highly suggest updating to the newest 11.28 that is available, which is the following for RELEASE tier:

    11.28.87-RELEASE_51188

    You would be able to see the existing versions at this location:

    http://httpupdate.cpanel.net/

    Simply running "/scripts/upcp --force" on the machine should allow an update to 11.28 for it.
    cPResources: Support Options | More Support Options | Forums Search | cPanel.net Site Search | Mailing Lists(Alt) | Docs
    -- Tristan, Technical Analyst III, Forums Specialist, cPanel Tech Support

    Submit a ticket | Check an existing ticket

  3. #3
    Member
    Join Date
    Sep 2010
    Posts
    10
    cPanel/WHM Access Level

    Root Administrator

    Default Re: Changing password strength requirements

    Thanks, Tristan! I appreciate the information about the password strength requirements.

    Yes, we plan on updating to 11.28 within a month or so. We're going to be updating to FreeBSD 8.1 on the server, to ensure long-time support and that we don't get prematurely EOL'd by your new policy Just hope that y'all continue to support FreeBSD as an OS!

    Thanks again!

  4. #4
    BANNED
    Join Date
    Aug 2009
    Posts
    83

    Default Re: Changing password strength requirements

    Just checking in to make sure that you were able to find our new tables involving EOL for various operating system versions and our applicable EOL policy.

    System Requirements - cPanel Inc.
    Operating System End of Life Policy for cPanel & WHM

  5. #5
    Member
    Join Date
    Jan 2010
    Posts
    15

    Default Re: Changing password strength requirements

    Is it documented anywhere what the details of the password strength requirements will be for varying slider settings? (ie: how many uppercase/numbers/symbols/etc...) ? I want to turn this on but don't know how far to put the slider. I need to improve the assword requirements but don;t want to go to 100 i dont think (or i dont know as i cant even guess what they are)..


    any help on determining this? thanks!

  6. #6
    Registered User
    Join Date
    May 2012
    Posts
    1
    cPanel/WHM Access Level

    Website Owner

    Default Re: Changing password strength requirements

    I do have a problem with reducing the password strength of the email accounts using cpanel. Any help on how to solve this problem cos av been searching everywhere to get a solution and cant seem to find any link to getting a solution ??? Its becoming a nuisance to my colleagues having to get a password with strength of above 70%. they are not I.T saavy at all. I cant seem to find any slider too, cos everyone seems to be talking about a slider. Thanks.
    Last edited by Gochu75; 05-14-2012 at 09:30 AM.

  7. #7
    cPanel Staff cPanelTristan's Avatar
    Join Date
    Oct 2010
    Location
    somewhere over the rainbow
    Posts
    7,611
    cPanel/WHM Access Level

    Root Administrator

    Default Re: Changing password strength requirements

    Those talking about a slider have access to WHM to configure the setting. Have you spoken to your hosting provider about the issue?
    cPResources: Support Options | More Support Options | Forums Search | cPanel.net Site Search | Mailing Lists(Alt) | Docs
    -- Tristan, Technical Analyst III, Forums Specialist, cPanel Tech Support

    Submit a ticket | Check an existing ticket

Similar Threads

  1. Access to password strength algorithm
    By mjqtreble in forum cPanel & WHM Discussions
    Replies: 0
    Last Post: 06-23-2010, 09:28 AM
  2. password strength for email
    By nitaish in forum cPanel & WHM Discussions
    Replies: 4
    Last Post: 12-28-2009, 09:02 AM
  3. Password Strength BUG
    By jandafields in forum cPanel & WHM Discussions
    Replies: 7
    Last Post: 11-21-2009, 10:02 PM
  4. Password Strength
    By gmm6797 in forum cPanel & WHM Discussions
    Replies: 5
    Last Post: 08-20-2009, 10:35 AM
  5. Password Strength
    By cwihost in forum cPanel & WHM Discussions
    Replies: 9
    Last Post: 10-27-2007, 03:30 PM