blueprints: add default Password policy (cherry-pick #11793) #11993
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Cherry-picked blueprints: add default Password policy (#11793)
This change complies with the minimal compositional requirements by
NIST SP 800-63 Digital Identity Guidelines. See
https://pages.nist.gov/800-63-4/sp800-63b.html#password
More work is needed to comply with other parts of the Guidelines,
specifically
and
add docs for default Password policy
remove HIBP from default Password policy
add zxcvbn to default Password policy
add fallback password error message to password policy, fix validation policy
Signed-off-by: Jens Langhammer jens@goauthentik.io
Co-authored-by: Tana M Berry tanamarieberry@yahoo.com
Signed-off-by: Simonyi Gergő 28359278+gergosimonyi@users.noreply.github.com
Co-authored-by: Jens L. jens@goauthentik.io
Signed-off-by: Simonyi Gergő 28359278+gergosimonyi@users.noreply.github.com
Signed-off-by: Jens Langhammer jens@goauthentik.io
Signed-off-by: Jens Langhammer jens@goauthentik.io
Signed-off-by: Jens Langhammer jens@goauthentik.io
Signed-off-by: Jens Langhammer jens@goauthentik.io
Signed-off-by: Simonyi Gergő 28359278+gergosimonyi@users.noreply.github.com
Co-authored-by: Jens Langhammer jens@goauthentik.io
Co-authored-by: Tana M Berry tanamarieberry@yahoo.com