Project

General

Profile

Actions

Feature #4370

closed

Expire passwords on accounts created by administrators

Added by Colan Schwartz over 14 years ago. Updated over 9 years ago.

Status:
Closed
Priority:
Normal
Assignee:
-
Category:
Accounts / authentication
Target version:
-
Start date:
2009-12-09
Due date:
% Done:

0%

Estimated time:
Resolution:
Duplicate

Description

When a user account is created by an administrator, a plain-text password is sent over the network. Users should be forced to change their passwords in this situation, but there is currently no means by which to enforce this.

The standard way to enforce this is to expire user passwords when they first log into the system so that they must change their passwords. This way, if anyone else digs up a user's initial password later and tries to use it, it will be useless.

Actions

Also available in: Atom PDF