Uploaded image for project: 'Project Simple'
  1. Project Simple
  2. ST-88

Strong password policy should be Default for new clients

    Details

    • Type: Enhancement
    • Status: Closed
    • Priority: Medium
    • Resolution: Done
    • Component/s: BenAdmin
    • Labels:
      None
    • Module:
      BenAdmin - Security
    • Reported by:
      Support
    • Item State:
      Production Complete - Closed
    • Sprint:
      ST Sprint 1

      Description

      System should set strong password policy for newly added clients by default.

      Strong password should consider below points-
      1. Password must contain at least one letter
      2. Password must contain at least one numeric digit
      3. Password must contain at least one special character
      4. Password must contain at least one UPPERCASE character
      5. Password must contain at least one lowercase character
      6. Password must be MINIMUM of 10 characters

        Attachments

          Issue Links

            Activity

            Hide
            vijayendra Vijayendra Shinde (Inactive) added a comment -

            Script has been added into JIRA.

            Verified Add scenarios of Partner, Broker and Company Admin. In edit mode we cannot not edit user's own password due to security reason. So not able to verify edit mode.

            For employee role, tried to add new employee on LB with Strong password and Username settings but not able to add employee on LB.

            Show
            vijayendra Vijayendra Shinde (Inactive) added a comment - Script has been added into JIRA. Verified Add scenarios of Partner, Broker and Company Admin. In edit mode we cannot not edit user's own password due to security reason. So not able to verify edit mode. For employee role, tried to add new employee on LB with Strong password and Username settings but not able to add employee on LB.
            Hide
            vijayendra Vijayendra Shinde (Inactive) added a comment -

            For employee login, I added new company on Stage by updating master company db. Added new employee with below settings -
            Username Password
            Lastname 4 1
            Firstname 1 2
            SSN 3 3
            DateofBirth 2 2
            EmployeeID 0 2

            All scenarios are working fine.

            Show
            vijayendra Vijayendra Shinde (Inactive) added a comment - For employee login, I added new company on Stage by updating master company db. Added new employee with below settings - Username Password Lastname 4 1 Firstname 1 2 SSN 3 3 DateofBirth 2 2 EmployeeID 0 2 All scenarios are working fine.
            Hide
            Zeeshan.Chishty Zeeshan Chishty (Inactive) added a comment -

            Step 1: Do not set default password. If set it should be random always and not predictable.
            Step 2: Send a onetime valid link to the users mail id .Set a 1 or 2 day expiration time for using that link.
            Step 3: When user clicks the link navigate user to change password page/set password page
            Step 4: Use a strong password policy like minimum 8 characters, alpha numeric at least 1 special and 1 upper
            case character .no sequential characters allowed(11,aa,555)
            Step 5:Invalidate the sent link immediately from server.

            Show
            Zeeshan.Chishty Zeeshan Chishty (Inactive) added a comment - Step 1: Do not set default password. If set it should be random always and not predictable. Step 2: Send a onetime valid link to the users mail id .Set a 1 or 2 day expiration time for using that link. Step 3: When user clicks the link navigate user to change password page/set password page Step 4: Use a strong password policy like minimum 8 characters, alpha numeric at least 1 special and 1 upper case character .no sequential characters allowed(11,aa,555) Step 5:Invalidate the sent link immediately from server.
            Hide
            vijayendra Vijayendra Shinde (Inactive) added a comment -

            ST 168 is enhancement suggestion to ST-88.

            Show
            vijayendra Vijayendra Shinde (Inactive) added a comment - ST 168 is enhancement suggestion to ST-88 .
            Hide
            rakeshr Rakesh Roy (Inactive) added a comment -

            Vijayendra Shinde Is this re-open?

            Show
            rakeshr Rakesh Roy (Inactive) added a comment - Vijayendra Shinde Is this re-open?
            Hide
            vijayendra Vijayendra Shinde (Inactive) added a comment - - edited

            Hi Rakesh,

            Zeeshan has some suggestion over existing password generation. He has added new JIRA ST-168 for this suggestion.

            Changes which we did for this ticket are working fine.

            We can move this to Stage.

            Thanks.

            Show
            vijayendra Vijayendra Shinde (Inactive) added a comment - - edited Hi Rakesh, Zeeshan has some suggestion over existing password generation. He has added new JIRA ST-168 for this suggestion. Changes which we did for this ticket are working fine. We can move this to Stage. Thanks.
            Hide
            deepalit Deepali Tidke (Inactive) added a comment -

            Once WT-3585 is fixed , can proceed with this patch

            Show
            deepalit Deepali Tidke (Inactive) added a comment - Once WT-3585 is fixed , can proceed with this patch
            Hide
            deepalit Deepali Tidke (Inactive) added a comment -

            verified on lb , all the passwords combinations on security pages are working fine.

            Show
            deepalit Deepali Tidke (Inactive) added a comment - verified on lb , all the passwords combinations on security pages are working fine.
            Hide
            deepalit Deepali Tidke (Inactive) added a comment -

            verified on stage , all the passwords combinations on security pages are working fine.

            Show
            deepalit Deepali Tidke (Inactive) added a comment - verified on stage , all the passwords combinations on security pages are working fine.
            Hide
            rashmita.dudhe Rashmita Dudhe (Inactive) added a comment -

            We can not add new Company on Production.
            for existing company all the passwords combinations on security pages are working fine.

            Show
            rashmita.dudhe Rashmita Dudhe (Inactive) added a comment - We can not add new Company on Production. for existing company all the passwords combinations on security pages are working fine.

              People

              Assignee:
              rashmita.dudhe Rashmita Dudhe (Inactive)
              Reporter:
              vijayendra Vijayendra Shinde (Inactive)
              Developer:
              Vijayendra Shinde (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

                Dates

                Created:
                Updated:
                Resolved: