Is it possible to force a user to make strong password in JIRA 5.1?

Hi,

I would like that user should be forced to keep a strong password for login. These are my finding or loose points in JIRA 5.1 for password.

  1. Weak passwords (complexity-wise) are allowed.
  2. The minimum length of the password is less than 8.
  3. The password cannot be expired.
  4. The user is not forced to change the password during the user's first login.
  5. The password for the new user is set to default.

Any Suggestion that we can have these things in place.

Regards

Preet

2 answers

1 vote

You need to replace the code in Jira that handles passwords, in order to add functions 1, 2, and 4. Function 3 is slightly different as it's a time-based thing, but it needs coding in a slightly different place. I don't understand what the problem with 5 is - "default" passwords are a bad thing in security terms and a random or admin-defined one should always be set.

Your second option is to use external account maintenance, connecting Jira to a system that will do these things for you. This is a better option than coding in the core of Jira in my opinion.

There are other options as well (e.g. use ssl certificates and bypass passwords completely - far more secure in many ways), but they all need coding.

However, you are using OnDemand, which means you can't implement anything different. You'll need to move to your own installation to implement anything better.

Hi Nic,

I have a hosted installation of Jira and have the same issue. How can i change the code like you mentioned on the first paragraph to allow minimun numbers of charaters on the users password?

I just want to make all passwords minimum 8 characters and using at least one number.

Thanks

ES

I'm sorry, I don't know exactly where it is, I've never needed to look for it. I suspect you need to look in the "crowd embedded" stuff, but it might be easier to start from the "changepassword.jsp" and trace it from there.

0 vote

This is not currently possible in OnDemand. We have a feature request logged for it here:

Feel free to keep an eye on that issue for developments.

Suggest an answer

Log in or Sign up to answer
How to earn badges on the Atlassian Community

How to earn badges on the Atlassian Community

Badges are a great way to show off community activity, whether you’re a newbie or a Champion.

Learn more
Community showcase
Published Thursday in Jira Service Desk

How the Telegram Integration for Jira helps Sergey's team take their support efficiency to the bank

...+ reading Fantasy). The same is true for him at the bank he works for: Efficiency is key when time literally equals money. Read on to learn how Sergey makes most of the time he has by...

239 views 0 3
Read article

Atlassian User Groups

Connect with like-minded Atlassian users at free events near you!

Find a group

Connect with like-minded Atlassian users at free events near you!

Find my local user group

Unfortunately there are no AUG chapters near you at the moment.

Start an AUG

You're one step closer to meeting fellow Atlassian users at your local meet up. Learn more about AUGs

Groups near you