Silly Password Policy
Each test can be enabled or disabled in the configuration. See configuration properties to learn more about the specific tests.
detectEmptyPassword) A password is considered to be empty, if it only consists of whitespace.
detectSequences) A password is considered to consist of a sequence, if - after converting it to lowercase characters - the ASCII-code-difference between any two adjacent characters is either 1 or -1. The sign of the difference is ignored, i.e. the sequence "abcdefedce" is also considered such a sequence.
detectSingleCharacterPasswords) A password matches, if - after converting it to lowercase characters - the ASCII-code of all characters is the same.
Example: "aaaaaaa" or "AaaAa"
detectKeyboardLayoutBasedPasswords) A password is considered to be based on the keyboard-layout if it can be typed by pressing keys on a computer keyboard from left to right or from right to left.
Case of characters is not considered.
Example on a Swiss-German keyboard, starting with the letter "k" and going left is: "kjhgfd".
The plugin supports the following keyboard layouts: QWERTY, QWERTZ, AZERTY, QZERTY. For these layouts several subvariants regarding special characters such as umlauts and other special characters are implemented.
type: PwdPolicySillyCheck
id: PwdPolicySillyCheck-xxxxxx
displayName:
comment:
properties:
detectEmptyPassword: true
detectKeyboardLayoutBasedPasswords: true
detectSequences: true
detectSingleCharacterPasswords: true