← Back to plugin index

Silly Password Policy

Description
A password policy check that tests for several very specific properties of a password (e.g. sequences, only one letter/digit, empty password, keyboard layout based, etc.).
Each test can be enabled or disabled in the configuration. See configuration properties to learn more about the specific tests.
Type name
PwdPolicySillyCheck
Class
com.airlock.iam.core.misc.impl.authen.PwdPolicySillyCheck
May be used by
Properties
Detect Empty Password (detectEmptyPassword)
Description
Enables (TRUE) or disables (FALSE) the check detecting empty passwords. If such a password is detected, a PasswordTooSillyViolation is returned by this plugin.

A password is considered to be empty, if it only consists of whitespace.

Attributes
Boolean
Optional
Default value
true
Detect Sequences (detectSequences)
Description
Enables (TRUE) or disables (FALSE) the check detecting passwords consisting of an ascending or descending character sequence such as "abcdef", "456789", or "mlkjih". If such a password is detected, a PasswordTooSillyViolation is returned by this plugin.

A password is considered to consist of a sequence, if - after converting it to lowercase characters - the ASCII-code-difference between any two adjacent characters is either 1 or -1. The sign of the difference is ignored, i.e. the sequence "abcdefedce" is also considered such a sequence.

Attributes
Boolean
Optional
Default value
true
Detect Single Character Passwords (detectSingleCharacterPasswords)
Description
Enables (TRUE) or disables (FALSE) the check detecting passwords consisting of only one character. If such a password is detected, a PasswordTooSillyViolation is returned by this plugin.

A password matches, if - after converting it to lowercase characters - the ASCII-code of all characters is the same.

Example: "aaaaaaa" or "AaaAa"

Attributes
Boolean
Optional
Default value
true
Detect Keyboard Layout Based Passwords (detectKeyboardLayoutBasedPasswords)
Description
Enables (TRUE) or disables (FALSE) the check detecting passwords that are "keyboard-layout based". If such a password is detected, a PasswordTooSillyViolation is returned by this plugin.

A password is considered to be based on the keyboard-layout if it can be typed by pressing keys on a computer keyboard from left to right or from right to left.
Case of characters is not considered.

Example on a Swiss-German keyboard, starting with the letter "k" and going left is: "kjhgfd".

The plugin supports the following keyboard layouts: QWERTY, QWERTZ, AZERTY, QZERTY. For these layouts several subvariants regarding special characters such as umlauts and other special characters are implemented.

Attributes
Boolean
Optional
Default value
true
YAML Template (with default values)

type: PwdPolicySillyCheck
id: PwdPolicySillyCheck-xxxxxx
displayName: 
comment: 
properties:
  detectEmptyPassword: true
  detectKeyboardLayoutBasedPasswords: true
  detectSequences: true
  detectSingleCharacterPasswords: true