|
|||
|
Password strength meets limits but fails
One of my users brought to my attention an interesting item.... I have WHM set to enforce a password strength of 65 across the board for every item.
If the user goes into their cPanel and tries to create an email account using a password in the following pattern: aaaa+aaaa# a = lower case alpha character (same as above example) + = special character "+" # = a number (e.g. "5") So they try to use a password something like this: bnhg+ijyf2 The "Password Strength" indicator will show a strength of 82 / 100 and turns green. However, when the user then tries to create the account it returns an error saying, "Sorry, the password you selected cannot be used because it is too weak and would be too easy to crack. Please select a password with strength rating of 65 or higher." What's up with that? Any ideas? TIA! Tony cPanel / WHM Version: cPanel 11.24.4-S36281 - WHM 11.24.2 - X 3.9 |
|
||||
|
Sounds like you may have uncovered a bug ...
If the code running the password checks doesn't match up to the code used in password generation scoring, they may have an issue. I would think they would call the same functions but maybe not. I have not observed the problem in EDGE which is what we use but I will try to see if I can duplicate the issue. As for you guys on STABLE and RELEASE, I would strongly advise you both moving up to CURRENT. STABLE is often far too old to be of much use and is the most prone to new exploits and attack methods and lacks new features and capabilities and in some respects dangerous. RELEASE is only slightly better but not by much. CURRENT you get the updates for bug fixed reasonably quickly, most of the new features, and security updates. EDGE I don't recommend except for seasoned experts like myself who are capable for handling unexpected issues. This channel will give you all the very latest features and the fastest route for updates and ironically bug fixes but at the same time could have more unexpected issues to deal with too.
__________________
My Server Expert: Server support, security, and management! |
|
||||
|
This is an issue fixed in cPanel 11.25 ( EDGE ). In 11.24 and prior versions the server side checks were not governed by the same algorithm as the client side checks. cPanel 11.25 harmonizes these into a unified system.
__________________
cPanel Kenneth cPanel QA |
|
|||
|
Kenneth - Thanks for the update. Will look forward to that trickling down to the other versions.
Spiral - I reckon we may have to consider switching to the CURRENT release. Many years ago we had some problems when using the newer builds and switched to STABLE simply to help avoid problems. But, as I say, that was years ago so it is probably time to move to try the more recent updates. Thanks! Tony |
|
|||
|
Is there any ETA as to when this will hit the CURRENT builds?
|
![]() |
| Thread Tools | |
| Display Modes | |
|
|
Similar Threads
|
||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| WHM Password Issue: Lenght & Limits | TRPN | cPanel and WHM Discussions | 4 | 07-06-2009 01:59 PM |
| Prevent WHM worrying about pass strength? | trevHCS | cPanel and WHM Discussions | 2 | 07-15-2008 01:12 PM |
| Password Strength | cwihost | cPanel and WHM Discussions | 9 | 10-27-2007 04:30 PM |
| Password Protect Directories limits? .htaccess | tulsabobt | cPanel and WHM Discussions | 0 | 11-11-2004 05:47 PM |
| Username, Password, and Database name limits | any-hoo | cPanel and WHM Discussions | 0 | 02-09-2004 01:02 AM |