Note: You are currently viewing documentation for Moodle 3.6. Up-to-date documentation for the latest stable version of Moodle is likely available here: Password policy.

Password policy: Difference between revisions

From MoodleDocs
(content moved from Site policies)
Line 1: Line 1:
{{stub}}
{{Moodle 1.9}}It is highly recommended that a password policy is set in ''Administration > Security > [[Site policies]]'' to force users to use stronger passwords that are less susceptible to being cracked by a intruder.


It is recommended that a password policy is set in ''Administration > Security > [[Site policies]]'', since password guessing is very often the easiest way to gain unauthorised access.
In Moodle 1.9.7 onwards the password policy is enabled by default.
 
The password policy includes option to set the minimum length of the password, the minimum number of digits, the minimum number of lowercase characters, the minimum number of uppercase characters and the minimum number of non alphanumeric characters.
 
If a user enters a password that does not meet the requirements, they are given an error message indicating the nature of the problem with the entered password.
 
Enabling the password policy does not affect existing users until they decide to or are required to change their password. In Moodle 1.9.7 onwards, an admin can force all users to change their password using the force password change option in [[Bulk user actions]].
 
''Tip'': In Moodle 1.9.4 onwards, the password policy may also be applied to [[Enrolment key|enrolment keys]] by setting ''enrol_manual_usepasswordpolicy'' to Yes in the [[Internal enrolment]] settings.


==See also==
==See also==


* Using Moodle [http://moodle.org/mod/forum/view.php?id=7301 Security and Privacy forum]
* Using Moodle [http://moodle.org/mod/forum/view.php?id=7301 Security and Privacy forum]
* Using Moodle [http://moodle.org/mod/forum/discuss.php?d=103211 Retrospective password policy] forum discussion
* [http://www.passwordmeter.com/ Password strength checker]


[[Category:Security]]
[[Category:Security]]

Revision as of 12:32, 17 November 2009

Template:Moodle 1.9It is highly recommended that a password policy is set in Administration > Security > Site policies to force users to use stronger passwords that are less susceptible to being cracked by a intruder.

In Moodle 1.9.7 onwards the password policy is enabled by default.

The password policy includes option to set the minimum length of the password, the minimum number of digits, the minimum number of lowercase characters, the minimum number of uppercase characters and the minimum number of non alphanumeric characters.

If a user enters a password that does not meet the requirements, they are given an error message indicating the nature of the problem with the entered password.

Enabling the password policy does not affect existing users until they decide to or are required to change their password. In Moodle 1.9.7 onwards, an admin can force all users to change their password using the force password change option in Bulk user actions.

Tip: In Moodle 1.9.4 onwards, the password policy may also be applied to enrolment keys by setting enrol_manual_usepasswordpolicy to Yes in the Internal enrolment settings.

See also