Document toolboxDocument toolbox

Settings - Configuration - Security - Password rules

Password rules for administrators

Minimum password length

Minimum password length for administrators. The length is enforced when setting a new password or changing the existing one. For security reasons this cannot be set lower than 8 characters.

(default: 12)

Password must contain

By checking the required character groups (lowercase and uppercase, digits, symbols) it is possible to increase the complexity of used passwords. The following characters are considered as symbols: ! @ # $ % ^ & *. The character groups are checked when when setting a new password or changing the existing one.

(default: all checked)

Forbid leaked passwords usage

When enabled, ensures any new password must not be a part of a known password data breach. The "Have I Been Pwned (HIBP)" service is used to check this. The password is not sent anywhere for this check. Only a 5 character fragment of the SHA1 password hash is sent. For more information see: https://haveibeenpwned.com/API/v3#PwnedPasswords. This is checked when setting a new password or changing the existing one.

(default: enabled)

Password rules for users

The following rules for user passwords are valid only for local users (created directly in the SOFiE application by an administrator). Remote users (from AD/ADFS) are not affected.

Minimum password length

Minimum password length for users. The length is enforced when setting a new password or changing the existing one. For security reasons this cannot be set lower than 8 characters.

(default: 8)

Password must contain

By checking the required character groups (lowercase and uppercase, digits, symbols) it is possible to increase the complexity of used passwords. The following characters are considered as symbols: ! @ # $ % ^ & *. The character groups are checked when when setting a new password or changing the existing one.

(default: all checked except symbols)

Forbid leaked passwords usage

When enabled, ensures any new password must not be a part of a known password data breach. The "Have I Been Pwned (HIBP)" service is used to check this. The password is not sent anywhere for this check. Only a 5 character fragment of the SHA1 password hash is sent. For more information see: https://haveibeenpwned.com/API/v3#PwnedPasswords . This is checked when setting a new password or changing the existing one.

(default: enabled)

Password rules for packages

Minimum password length

Minimum password length for password protected packages. For security reasons this cannot be set lower than 8 characters.

(default: 8)

Password must contain

By checking the required character groups (lowercase and uppercase, digits, symbols) it is possible to increase the complexity of used passwords. The following characters are considered as symbols: ! @ # $ % ^ & *. The character groups are checked when when setting a new password or changing the existing one.

(default: all unchecked)

Forbid leaked passwords usage

When enabled, ensures any new password must not be a part of a known password data breach. The "Have I Been Pwned (HIBP)" service is used to check this. The password is not sent anywhere for this check. Only a 5 character fragment of the SHA1 password hash is sent. For more information see: https://haveibeenpwned.com/API/v3#PwnedPasswords . This is checked when setting a new password or changing the existing one.

(default: enabled)

Mandatory package password - not logged in user

Enforce a password to be set for package access if it is uploaded by a NOT LOGGED IN user (anonym). If enabled, a package without a password (complying with the rules above) cannot be sent.

(default: disabled)

Mandatory package password - logged in user

Enforce a password to be set for package access if it is uploaded by a LOGGED IN user. If enabled, a package without a password (complying with the rules above) cannot be sent.

(default: disabled)