Password

You can select the following settings for passwords in Neptune DXP - Open Edition:

  • Minimum Password Length

  • Minimum Number of Uppercase Characters

  • Minimum Number of Special Characters

  • Minimum Number of Numbers

  • Minimum Number of Lowercase Characters

  • Password Validity Period (Days - If set to 0 passwords will never expire)

    If you set the password validity period to 0, the password does not expire.
  • Size of Password History

  • Password must not contain the username or email address

Password validation script

To add custom password rules, select a server script as the password validation script. For example, you can check passwords against a dictionary, block simple sequences, or require a longer minimum length for administrators.

The script runs in the server process after the built-in rules, on every password change: when a user is created, when an administrator sets a password, when a user changes their own password, and when a forgotten password is reset.

The script receives the following objects:

password

The new password.

user

The user whose password changes, with id, username, email, name, and roles.

result

The validation result. To reject the password, add a message to result.errors. The user sees the message.

if (/0123|1234|2345|3456|4567|5678|6789|abcd/i.test(password)) {
    result.errors.push("The password must not contain simple sequences.");
}
If the script fails or cannot be found, every password change is rejected. Test the script before you select it in a production system.

Password Lock

To prevent brute-force log-in attacks, select the following autolock settings:

  • Number of Tries before Autolock

    If you set the number of tries before autolock to 0, no autolock is applied. A user can enter an incorrect password an unlimited number of times without login autolocking.
  • Remove Autolock After No. Minutes

  • Waiting Time Before Removing Autolock (Minutes)

    The default waiting time before removing the autolock is 30 minutes.

  • Message when user tries to access a locked account

    The following messages can be selected:

    • Neutral - "Wrong username/password combination"

    • Specific - "Locked account"

  • Send a notification email to the user when their account is locked due to too many login attempts

    The checkbox is selected by default.

Password setting interplay

If the number of login attempts exceeds the number set in Number of Tries before Autolock, the message set in Message when user tries to access a locked account is displayed to the user. If you select Send a notification email to the user when their account is locked due to too many login attempts, a notification email is sent to the email address of the user that is set in the User tool.