Zimbra offers Open Source email server software and shared calendar for Linux and the Mac
Go Back   Zimbra :: Forums > Zimbra Collaboration Suite > Users

Welcome to the Zimbra :: Forums!
Welcome, if you would like to post a comment please register. We also encourage you to explore all things Zimbra with our team and members of the community.

Reply
 
LinkBack Thread Tools Search this Thread Display Modes
  #1 (permalink)  
Old 11-14-2008, 07:32 AM
Junior Member
 
Posts: 9
Default Show zimbra password policy when entering a new password

Hi everyone,

I was asking myself :

Is it possible to show the password policy when a user is asked to change his password ?

For example I have set a CoS in which I make my users change their password every 60 days, and each new password require an upper case, a lower case, a numeric, and 7 letters min.

As my users easily forget thier minds, when they're asked to change, they never remember the policy...

Is it possible to show it on the "Change your password / login" page ?

Thanks

Thibaut
Reply With Quote
  #2 (permalink)  
Old 11-17-2008, 01:21 AM
Moderator
 
Posts: 7,911
Default

Please vote for Bug 27194 - Bad error message when password too short and add that it would be useful if the password policy was shown to the user.
__________________
Reply With Quote
  #3 (permalink)  
Old 11-17-2008, 04:47 AM
Junior Member
 
Posts: 9
Default

Hi

Thanks for your guidance !

Regards,

Thibaut
Reply With Quote
  #4 (permalink)  
Old 11-17-2008, 04:58 AM
Moderator
 
Posts: 927
Default

I've thought about this one a number of times in the past, mainly when I'm frustrated by having to explain to the staff for the umpteenth time that their password needs upper and lower case and at least one number.

The problem though, is that if that information is displayed on the logon page, then it makes brute forcing the passwords a lot simpler.

If the login screen tells you that the password needs to be at least 8 chars long, then you know you dont need to brute force anything below this.

Of course, that's all moot if you have account lockout policies set, which pretty much removes the ability to brute force an account.

I dont know the answer to this one, but I think the client currently gives no information about the policy for security reasons.
Reply With Quote
  #5 (permalink)  
Old 11-17-2008, 05:03 AM
Moderator
 
Posts: 7,911
Default

How about when you set a expiration within a CoS it would email the user a predetermined number of days before explaining that the password will expire and what the policy for it is ? Most of this information should be available via zmprov/SOAP so could be performed outside of the Admin GUI aswell.
__________________
Reply With Quote
  #6 (permalink)  
Old 11-28-2008, 09:26 AM
Junior Member
 
Posts: 9
Default

Maybe you should add this suggestion in the bugzilla ?
Reply With Quote
Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes


Similar Threads

Why Join?

Registering let's you ask questions, makes it easier to search, displays any files attached to posts, and notifies you about replies.

blog.zimbra.com




 

SEO by vBSEO ©2011, Crawlability, Inc.