Skip to content

Change of password expiration policy defaults #7503

@DavidePrincipi

Description

@DavidePrincipi

An expiring password policy has become obsolete through the years because it generates some of the problems it tries to solve:

Proposed solution

  • Default password expiration policy: disabled enabled
  • If expiry is enabled, Default password age is 0-180
  • In UI, when admin sets a password (also in the user creation workflow) add an option "must-change-at-next-login"
  • Implement "password-does-not-expire" flag in UI

Additional context

Current password policy settings

Image

Currently Password-does-not-expire is displayed, but not modifiable

Image

See also

Discussion https://mattermost.nethesis.it/nethesis/pl/m93w1ifhgtbqdy8qmmmt7ep3wy


Thanks to @nrauso @charliewhiting @digre82

Metadata

Metadata

Assignees

No one assigned

    Labels

    verifiedAll test cases were verified successfully

    Projects

    Status

    Done

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions