Simple Password Policy
Description
Password policy that allows to configure the most common password policy checks.
May be used by
Password Reset Step Basic Auth Request Authentication Pattern-based Random String Generator Password-only Authentication Step Mandatory Password Change Step Administrators Configuration Username Password Authentication Step Voluntary Password Change Step Password Change Self-Service Step Password Settings Username Password with FIDO Authentication Step Set Password Step HTTP Basic Authentication Step Password User Item
Properties
Required Characters (
requiredCharacters) Description
Assure that a password contains at least one character from every configured character class.
For example, "Characters and digits" assures that at least one character and one digit is used.
In addition, the following character classes include:- "Normal characters" include a-z (case insensitive)
- "Special characters" include
. , ; : - _ ! $ ( ) { } [ ] < > = ? + * & % \ / | @ # ^ ` ~
Attributes
Enum
Optional
Default value
CHARS_AND_DIGITS
Min Required Length (
minRequiredLength) Description
The minimum required number of characters of a password. Shorter passwords are rejected.
Attributes
Integer
Optional
Default value
8
Max Allowed Length (
maxAllowedLength) Description
The maximum allowed number of characters of a password. Longer passwords are rejected.
Attributes
Integer
Optional
Default value
100
No Silly Passwords (
noSillyPasswords) Description
Rejects passwords that are easy to guess, such as:
- Character sequences such as "abcde" or "1234321"
- Passwords consisting of a single character such as "AaAaaaaAa"
- Passwords constructed by typing a sequence on keyboard such as "asdfgh". A variety of keyboard layouts are supported.
Attributes
Boolean
Optional
Default value
true
No Previously Used Passwords (
noPreviouslyUsedPasswords) Description
Check that new password is the same as one in the password history (i.e. a previously used password).
The number of "forbidden" used passwords (= the password history length) is defined by the password hash plugin passed to this plugin when performing the check.
The number of "forbidden" used passwords (= the password history length) is defined by the password hash plugin passed to this plugin when performing the check.
Note: The check requires that the used password hash function supports password histories (i.e. implements "PasswordHashWithHistory"). If not, an error occurs.
Attributes
Boolean
Optional
Default value
false
Allowed Characters (
allowedCharacters) Description
A regular expression pattern defining the set of allowed characters.
Every character of the password is matched against this pattern and must match or the password is not allowed.
Attributes
RegEx
Optional
Forbidden Characters (
forbiddenCharacters) Description
A regular expression pattern defining the set of forbidden characters.
If the pattern matches the whole password or only a part of it, the password is rejected.
Attributes
RegEx
Optional
YAML Template (with default values)
type: SimplePasswordPolicy
id: SimplePasswordPolicy-xxxxxx
displayName:
comment:
properties:
allowedCharacters:
forbiddenCharacters:
maxAllowedLength: 100
minRequiredLength: 8
noPreviouslyUsedPasswords: false
noSillyPasswords: true
requiredCharacters: CHARS_AND_DIGITS