password policy allowing previous password

sivaramaraju indukuri
I'm New Here
I'm New Here
Those new to the Atlassian Community have posted less than three times. Give them a warm welcome!
March 31, 2021

I dont want the users to reset password with the current password or previous passwords.

 

so I used the password policy in jira by setting the 

Similarity checks for 'Custom' password settings to Strict, However I am still able to set my current password when I try to reset the password. Any help is appreciated.

1 answer

0 votes
Andy Heinzer
Atlassian Team
Atlassian Team members are employees working across the company in a wide variety of roles.
April 12, 2021

Hi,

If I understand the concern here, it's that when using Jira Server and enabling a custom password policy that users can still reset their password to use the same value despite the settings in the policy.

I tried to recreate this problem in 8.16.0, but so far I have not been able to do so.  Here were my settings:

Screen Shot 2021-04-12 at 1.40.14 PM.png

In my example user, I logged into Jira as that user, then went into my profile and used the changed password option.  From there I attempted reuse the exact same password, in my case this was "helloworld".  But when I tried this I got this error:

Screen Shot 2021-04-12 at 1.38.16 PM.png

I would like to learn more about your environment, such as

  1. Which version of Jira are you using here?,
  2. Is this a user account in the Internal Jira user directory? Or is this account in an LDAP/Crowd external user directory?
  3. Any information you can share with us about the password itself. 

I understand that you might not want to share the password publicly here in Community, but if we can understand if there is anything unique about that password such as use of a particular special character, I would be interested to try to recreate this problem so that we can better help troubleshoot this.

Andy

Suggest an answer

Log in or Sign up to answer