-
Type:
Enhancement
-
Status: New Request
-
Priority:
High
-
Resolution: Unresolved
-
Component/s: BenAdmin
-
Labels:None
-
Module:BenAdmin - Security
-
Reported by:Harbinger
Step 1: Do not set default password. If set it should be random always and not predictable.
Step 2: Send a onetime valid link to the users mail id .Set a 1 or 2 day expiration time for using that link.
Step 3: When user clicks the link navigate user to change password page/set password page
Step 4: Use a strong password policy like minimum 8 characters, alpha numeric at least 1 special and 1 upper
case character .no sequential characters allowed(11,aa,555)
Step 5:Invalidate the sent link immediately from server.
ST-168 is suggestion for
ST-88