-
Notifications
You must be signed in to change notification settings - Fork 19
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Allow to force password changes after the next UI login #14
Comments
Moved to 11 |
Hi there. Sorry for my stupid question. This is available @ Nextcloud 11.0. There is no patch for now, right? |
That's odd. But no, this is not implemented yet. |
No - this is Germany ;) |
Use LDAP login and policies from the LDAP are used. Also as a company you may consider a Support Subscription from https://nextcloud.com/enterprise. This gives you direct access to Engineers and influence on our roadmap. |
This is an option for our company, for sure. I did take note of this a few weeks ago and planed to ask for such an invest after the Cloud is productional. For LDPA-User it is no Problem. But for Partner Companies we need to create databased Accounts. And the workflow does not have an opportunity to force new database-user to change the PW we created when adding the account. |
Awesome. Reach out and we'd likely be very happy to help with a proof of concept. Just link to this discussion :-) So the requirement is actually that after registration users have to change their password is that correct? Would it also be an option that if you have created an user a mail with password reset link is send to the user? The user would then have to reset their password there. Also is there any kind of requirement for changing passwords after X days? That would again be kinda harder to implement and not sure if at the moment desired since it clutters the UI and is not compatible with all backends. (i.e. confusing behaviour) |
This would be an acceptable workaround. Because this would ensure, that no one of us (expecting us admins with database knowledge) knows the PW of the external Partner. No need to force changing PW after X days.
I will do this. But we are a relative big Company (about 1000 Employes) and it takes a while since all the processes being past. But I'll come back to you soon with this. |
This comment was marked as off-topic.
This comment was marked as off-topic.
Are thery any news about this feature? |
This comment was marked as abuse.
This comment was marked as abuse.
Yes, I'm also interested to know if this feature is already available. |
This comment was marked as abuse.
This comment was marked as abuse.
This comment was marked as spam.
This comment was marked as spam.
This comment was marked as abuse.
This comment was marked as abuse.
Feel free to find someone in https://help.nextcloud.com/c/nextcloud-freelancing/48 to get this feature in.
While I agree that the community is responsible for the success of Nextcloud, I don't think this issue is offending someone or the community which (as you said yourself before) should be able to fix the issue. Especially since the NIST changed its recommendation and removed password expiration (ref https://blog.24by7security.com/unpacking-the-nist-password-requirements-in-2019) and now says it's not recommmended to expire passwords.
This pays our salaries, that's just how it is and why you can use Nextcloud for free.
See https://github.com/nextcloud/server/blob/master/.github/CONTRIBUTING.md#contributing-to-source-code |
This comment was marked as duplicate.
This comment was marked as duplicate.
There are 2 topics |
Is there no one with premium-subscription, who is interested to support/push this security(!)feature? |
is there any word on being able to force a password change? I know people use resetting your password via email, and while that is a work around that is ok for some it really is a work around making you depend on a external account to be already setup a user properly . Alternatively It would be nice to have nextcloud be the first / only account for the user which then set an easy password that must change at first login with a good password policy it will allow you to put all other accounts (including email) in a password database thus keeping all accounts secured |
This comment was marked as off-topic.
This comment was marked as off-topic.
Just bumping in 2023 because there was an incident with one leaked password here. |
Same here, would be glad to have this feature! |
I appreciate the work of the devs. thx in advanced. |
https://help.nextcloud.com/t/force-password-change-at-user-logon/1664/1
I think it's a nice idea and also fit's in the context of this app.
The text was updated successfully, but these errors were encountered: