Skip to main content
Released

Enforce password complexity for FME Server users

Related products:FME Form
  • May 19, 2016
  • 5 replies
  • 56 views

gazza
Contributor
Forum|alt.badge.img+6

A security audit of an FME Server application has highlited that users can have simple passwords to login as a problem. It would be nice to be able to set the rules a users password must adhere too.

This post is closed to further activity.
It may be an old question, an answered question, an implemented idea, or a notification-only post.
Please check post dates before relying on any information in a question or answer.
For follow-up or related questions, please post a new question or idea.
If there is a genuine update to be made, please contact us and request that the post is reopened.

5 replies

rylanatsafe
Safer
Forum|alt.badge.img+14
Thanks for contributing, @gazza! Any additional feedback provided (by yourself or others) will be helpful for development on this idea.

 

 

What rules do you think would be most valuable?

 

 

I commonly see the following restrictions:

 

- Minimum of X characters

 

- "Must have" at least one of Uppercase, lowercase, and number (+/- special character)

 

 

Would you envision this applied across all accounts once implemented? Or would you rather have the option to turn this on / off as an FME Server Admin?

 

 

What should happen to accounts that are "grandfathered" in once this setting is enabled? Should the user be forced to generate a new password when they login? Should that be optional for existing accounts – perhaps only a warning displayed?

 


gazza
Contributor
Forum|alt.badge.img+6
  • Author
  • Contributor
  • June 12, 2018

This came from an audit at a council, so I would imagine that similar requirements to passwords in AD would be required. Such as in here:

https://www.networkworld.com/article/2726878/security/configuring-password-complexity-in-windows-and-active-directory.html

I'd definately want it to be an option the admin can toggle on and off. For grandfathered accounts I'd go for a warning rather than forcing new passwords.


rylanatsafe
Safer
Forum|alt.badge.img+14
Thank you very much for the prompt response!

 

 


rylanatsafe
Safer
Forum|alt.badge.img+14
  • Safer
  • August 10, 2018

This feature is now in the FME Server 2019.0 betas! Noting that the downloads are currently not available as of this writing, but stay tuned!

The default rule set is:

 

1. Cannot contain username.

 

2. Minimum 8 characters

 

3. At least 1 lowercase

 

4. At least 1 UPPERCASE

 

5. At least 1 number or special character ~!@#$%^&*_-+=`|(){}[]:;"'<>,.?/

There are plans to make this configurable before official release. It is off by default.

----

 

Please note that this is a beta feature and its functionality and appearance are subject to change as the product continues to evolve before the official release.

Should this feature or its implementation not address your concerns, related to this Idea posting, please let us know by leaving a comment.

As with all beta features and beta versions of our software, they are not considered production-safe and should be incorporated into your workflows with consideration and testing.


rylanatsafe
Safer
Forum|alt.badge.img+14

Note: FME Server 2019.0 was released on April 2 2019. This idea status marked as Released.