Password Strength Logic (Advanced Security)

File -> System Configuration -> Password Strength

Special Note - Existing Passwords From Ostendo Versions Prior to Continuum Edition:


For sites migrating from a previous version of Ostendo where this new Password functionality did not exist, they can choose to implement advanced security or simply continue using their present password structure. Advanced Password options are either activate or inactive for a site in total



Enforced Changed of Initial Password:


In previous versions of Ostendo when the default password of 'pass' was initially set, users were never be forced to change this password which could leave sensitive areas of Ostendo exposed to users who should not have access.


If NO Password strength rules are defined, Ostendo will behave the same way it has in previous versions. ie: allow any existing user to log on with their current password.(lowercase is allowed)



If 'ANY' Password Strength rule is defined, then existing users must type their existing password in UPPERCASE. If that current password does not meet the defined Password Strength rules, they will be forced immediately to change their password to one that meets the current criteria defined in the Password Strength. When advanced security is defined, passwords are case sensitive



Password Strength:


Ostendo has the concept of setting and using a global password strength. This ensures that when a user sets their password, it is of enough strength the organisation requires.


This screen allows Administrators to define their organisations default password strength attributes.


The password strength attributes can be defined as follows:


    • Minimum Password Length: Minimum Password character Length (NB: The maximum length is 20 characters)
    • Requires Both Alpha and Numeric Characters: Select to force an Alpha Numeric password required
    • Requires Both Upper and Lowercase Characters: Select to force Upper and Lower case characters
    • At Least 1 Symbol Character: Select force at lease 1 Symbol character eg: !,@,%,$ etc.....
    • Default New User Password: This an override Default password to the standard password of 'pass' that is used when resetting a users password or when a new user is created. If you have Password Strength rules defined, ensure this default password 'Does Not' meet these rules. This will ensure the user must change their password.


 If turning on 'ANY' Password Strength rules for the first time, ensure existing users initially log on with their existing password in UPPERCASE. They will then be prompted to change their current password if it does not meet the current Password Strength criteria.