Postponed (maintainer needs more info)
Project:
Password Policy
Version:
7.x-2.x-dev
Component:
Code
Priority:
Normal
Category:
Feature request
Assigned:
Unassigned
Reporter:
Created:
2 Jul 2012 at 19:53 UTC
Updated:
6 Apr 2015 at 09:21 UTC
Jump to comment: Most recent
Comments
Comment #1
erikwebb commentedJust to be clear, once they pass this first threshold they would then be subject to the normal time limits?
Comment #2
shrop commentedYes, that sounds right. This would just a be an expiration for new users. If the user changes their temp password before the expiration, they can continue on, but are subject to all other aspects of their assigned password policy.
Comment #3
erikwebb commentedHow do you see this working differently for uses with a generated password versus those that pick their initial password? Should this apply to both or only to the generated ones?
Comment #4
shrop commentedGood questions Erik. My first thought is that if a user picks their initial password and it follows the rest of the policy, it shouldn't expire. With that said, if I as an admin user set a password for the user, that password should probably expire. For that scenario, I would have a requirement to have the user change their password at login. Between that and the expiration, it creates a nice policy.
Does that help?
Comment #5
erikwebb commentedCould this be covered by adding a threshold to #1596960: Force password change on first-time login requires password to change?
Comment #6
aohrvetpv commented