Cirrus Password Policy

Rules for Cirrus passwords

R
Escrito por Rubén Mosqueda Herrera
Actualizado hace más de una semana
  1. Initial Password

    For first time users, Cirrus will suggest them to change their password. First time a user logs into Cirrus application, system will prompt to change their current password.

    After the login is completed, system redirects to change the current password (see image) :

  2. Enforce Password History

    Currently, Cirrus does not have any validations that prevent users from setting previous passwords as their new password (history).

  3. Maximum Password Age

    Currently, Cirrus passwords do not have any expiration validations.

  4. Password expiry notification in the login page

    Since Cirrus does not consider password age nor they expire, users are not being notified regarding their password expiration. However, their entire account (username) has an expiration date (User Maintenance configuration), if it's blank then users will expire in two months as a default.

  5. Password Length

    Password is encrypted and it has a minimum length of 8 characters and a maximum length of 20 characters.

  6. Account Disabling

    If the user did not login for successive 6 months, the account is disabled automatically. Currently in Cirrus there is a task that is executed every month and it disables all of the accounts with more than 6 months of inactivity. 

  7. Account Lockout Policy

    Users have a lockout threshold where they can perform 5 login attempts, on the sixth attempt the user will be blocked. 

    To reactivate their account, users must open a support ticket.

    We hope this improves your Cirrus experience. Remember to share this information and ask for help if you need it.

    Date: August 23, 2023.

¿Ha quedado contestada tu pregunta?