Bug 45772 - Display password quality interactively
Display password quality interactively
Status: REOPENED
Product: UCS
Classification: Unclassified
Component: Self Service
UCS 4.4
Other Linux
: P5 normal (vote)
: ---
Assigned To: UMC maintainers
UMC maintainers
:
Depends on:
Blocks: 45773 45774 45775
  Show dependency treegraph
 
Reported: 2017-11-27 10:54 CET by Jan Christoph Ebersbach
Modified: 2020-12-22 11:42 CET (History)
2 users (show)

See Also:
What kind of report is it?: Feature Request
What type of bug is this?: ---
Who will be affected by this bug?: ---
How will those affected feel about the bug?: ---
User Pain:
Enterprise Customer affected?:
School Customer affected?:
ISV affected?:
Waiting Support:
Flags outvoted (downgraded) after PO Review:
Ticket number:
Bug group (optional): Security
Max CVSS v3 score:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Jan Christoph Ebersbach univentionstaff 2017-11-27 10:54:41 CET
The BSI recommendations on passwords suggest to display the password quality interactively while the user is typing it: https://www.bsi.bund.de/DE/Themen/ITGrundschutz/ITGrundschutzKataloge/Inhalt/_content/m/m02/m02011.html

This would enhance the security in key scenarios greatly because school districts often suffer from hacked user accounts.
Comment 1 Ingo Steuwer univentionstaff 2020-07-03 20:52:30 CEST
This issue has been filed against UCS 4.2.

UCS 4.2 is out of maintenance and many UCS components have changed in later releases. Thus, this issue is now being closed.

If this issue still occurs in newer UCS versions, please use "Clone this bug" or reopen it and update the UCS version. In this case please provide detailed information on how this issue is affecting you.
Comment 2 Florian Best univentionstaff 2020-07-13 20:01:23 CEST
Still a feature request.
Comment 3 Dirk Ahrnke univentionstaff 2020-12-22 11:42:03 CET
This feature will partially solve a customer request. 
Although this particular request asked to display the current password complexity criteria during the "change password" dialog the feature will solve the problem when the interactive display will act based on the rules for the particular account.