Is it possible to force a user to make strong password in JIRA 5.1?


I would like that user should be forced to keep a strong password for login. These are my finding or loose points in JIRA 5.1 for password.

  1. Weak passwords (complexity-wise) are allowed.
  2. The minimum length of the password is less than 8.
  3. The password cannot be expired.
  4. The user is not forced to change the password during the user's first login.
  5. The password for the new user is set to default.

Any Suggestion that we can have these things in place.



2 answers

1 vote

You need to replace the code in Jira that handles passwords, in order to add functions 1, 2, and 4. Function 3 is slightly different as it's a time-based thing, but it needs coding in a slightly different place. I don't understand what the problem with 5 is - "default" passwords are a bad thing in security terms and a random or admin-defined one should always be set.

Your second option is to use external account maintenance, connecting Jira to a system that will do these things for you. This is a better option than coding in the core of Jira in my opinion.

There are other options as well (e.g. use ssl certificates and bypass passwords completely - far more secure in many ways), but they all need coding.

However, you are using OnDemand, which means you can't implement anything different. You'll need to move to your own installation to implement anything better.

Hi Nic,

I have a hosted installation of Jira and have the same issue. How can i change the code like you mentioned on the first paragraph to allow minimun numbers of charaters on the users password?

I just want to make all passwords minimum 8 characters and using at least one number.



I'm sorry, I don't know exactly where it is, I've never needed to look for it. I suspect you need to look in the "crowd embedded" stuff, but it might be easier to start from the "changepassword.jsp" and trace it from there.

0 votes

This is not currently possible in OnDemand. We have a feature request logged for it here:

Feel free to keep an eye on that issue for developments.

Suggest an answer

Log in or Sign up to answer
Community showcase
Published Nov 27, 2018 in Portfolio for Jira

Introducing a new planning experience in Portfolio for Jira (Server/DC)

In the past, Portfolio for Jira required a high degree of detail–foresight that was unrealistic for many businesses to   have–in   order to produce a reliable long-term roadmap. We're tur...

2,740 views 17 21
Read article

Atlassian User Groups

Connect with like-minded Atlassian users at free events near you!

Find a group

Connect with like-minded Atlassian users at free events near you!

Find my local user group

Unfortunately there are no AUG chapters near you at the moment.

Start an AUG

You're one step closer to meeting fellow Atlassian users at your local meet up. Learn more about AUGs

Groups near you