Uploaded image for project: 'Project Simple'
  1. Project Simple
  2. ST-88

Strong password policy should be Default for new clients

    Details

    • Type: Enhancement
    • Status: Closed
    • Priority: Medium
    • Resolution: Done
    • Component/s: BenAdmin
    • Labels:
      None
    • Module:
      BenAdmin - Security
    • Reported by:
      Support
    • Item State:
      Production Complete - Closed
    • Sprint:
      ST Sprint 1

      Description

      System should set strong password policy for newly added clients by default.

      Strong password should consider below points-
      1. Password must contain at least one letter
      2. Password must contain at least one numeric digit
      3. Password must contain at least one special character
      4. Password must contain at least one UPPERCASE character
      5. Password must contain at least one lowercase character
      6. Password must be MINIMUM of 10 characters

        Attachments

          Issue Links

            Activity

            vijayendra Vijayendra Shinde (Inactive) created issue -
            vijayendra Vijayendra Shinde (Inactive) made changes -
            Field Original Value New Value
            Assignee Vijayendra Shinde [ ID10506 ]
            vijayendra Vijayendra Shinde (Inactive) made changes -
            Status New Request [ 10029 ] Pending for Approval [ 10002 ]
            vijayendra Vijayendra Shinde (Inactive) made changes -
            Status Pending for Approval [ 10002 ] Approved for Development [ 10003 ]
            vijayendra Vijayendra Shinde (Inactive) made changes -
            Status Approved for Development [ 10003 ] In Development [ 10007 ]
            vijayendra Vijayendra Shinde (Inactive) made changes -
            Description System should set strong password policy for newly added clients.

            Strong password should consider below points-
            1. Password must contain at least one letter
            2. Password must contain at least one numeric digit
            3. Password must contain at least one special character
            4. Password must contain at least one UPPERCASE character
            5. Password must contain at least one lowercase character
            6. Password must be MINIMUM of 8 characters

            System should set strong password policy for newly added clients by default.

            Strong password should consider below points-
            1. Password must contain at least one letter
            2. Password must contain at least one numeric digit
            3. Password must contain at least one special character
            4. Password must contain at least one UPPERCASE character
            5. Password must contain at least one lowercase character
            6. Password must be MINIMUM of 8 characters

            vijayendra Vijayendra Shinde (Inactive) made changes -
            Status In Development [ 10007 ] Mockup Approval [ 10010 ]
            vijayendra Vijayendra Shinde (Inactive) made changes -
            Issue Type Enhancement [ 4 ] Change Request [ 10002 ]
            vijayendra Vijayendra Shinde (Inactive) made changes -
            Status Mockup Approval [ 10010 ] Mockup Approved [ 10012 ]
            vijayendra Vijayendra Shinde (Inactive) made changes -
            Status Mockup Approved [ 10012 ] In Development [ 10007 ]
            vijayendra Vijayendra Shinde (Inactive) made changes -
            Issue Type Change Request [ 10002 ] Enhancement [ 4 ]
            Item State Parent values: Development(10200)Level 1 values: In Progress(10206)
            vijayendra Vijayendra Shinde (Inactive) made changes -
            Attachment Script.sql [ 14223 ]
            Hide
            vijayendra Vijayendra Shinde (Inactive) added a comment -

            Script has been added into JIRA.

            Verified Add scenarios of Partner, Broker and Company Admin. In edit mode we cannot not edit user's own password due to security reason. So not able to verify edit mode.

            For employee role, tried to add new employee on LB with Strong password and Username settings but not able to add employee on LB.

            Show
            vijayendra Vijayendra Shinde (Inactive) added a comment - Script has been added into JIRA. Verified Add scenarios of Partner, Broker and Company Admin. In edit mode we cannot not edit user's own password due to security reason. So not able to verify edit mode. For employee role, tried to add new employee on LB with Strong password and Username settings but not able to add employee on LB.
            vijayendra Vijayendra Shinde (Inactive) made changes -
            Sprint ST Sprint 1 [ 1 ]
            vijayendra Vijayendra Shinde (Inactive) made changes -
            Rank Ranked higher
            vijayendra Vijayendra Shinde (Inactive) made changes -
            Description System should set strong password policy for newly added clients by default.

            Strong password should consider below points-
            1. Password must contain at least one letter
            2. Password must contain at least one numeric digit
            3. Password must contain at least one special character
            4. Password must contain at least one UPPERCASE character
            5. Password must contain at least one lowercase character
            6. Password must be MINIMUM of 8 characters

            System should set strong password policy for newly added clients by default.

            Strong password should consider below points-
            1. Password must contain at least one letter
            2. Password must contain at least one numeric digit
            3. Password must contain at least one special character
            4. Password must contain at least one UPPERCASE character
            5. Password must contain at least one lowercase character
            6. Password must be MINIMUM of 10 characters

            Hide
            vijayendra Vijayendra Shinde (Inactive) added a comment -

            For employee login, I added new company on Stage by updating master company db. Added new employee with below settings -
            Username Password
            Lastname 4 1
            Firstname 1 2
            SSN 3 3
            DateofBirth 2 2
            EmployeeID 0 2

            All scenarios are working fine.

            Show
            vijayendra Vijayendra Shinde (Inactive) added a comment - For employee login, I added new company on Stage by updating master company db. Added new employee with below settings - Username Password Lastname 4 1 Firstname 1 2 SSN 3 3 DateofBirth 2 2 EmployeeID 0 2 All scenarios are working fine.
            vijayendra Vijayendra Shinde (Inactive) made changes -
            Attachment Script.sql [ 14223 ]
            vijayendra Vijayendra Shinde (Inactive) made changes -
            Attachment Script.sql [ 14279 ]
            vijayendra Vijayendra Shinde (Inactive) made changes -
            Item State Parent values: Development(10200)Level 1 values: In Progress(10206) Parent values: Development(10200)Level 1 values: Ready for Local Testing(10209)
            vijayendra Vijayendra Shinde (Inactive) made changes -
            Item State Parent values: Development(10200)Level 1 values: Ready for Local Testing(10209) Parent values: Local QA(10201)
            vijayendra Vijayendra Shinde (Inactive) made changes -
            Status In Development [ 10007 ] Local Testing [ 10200 ]
            shubhankar Shubhankar Joshi (Inactive) made changes -
            Assignee Vijayendra Shinde [ ID10506 ] Shubhankar Joshi [ shubhankar ]
            shubhankar Shubhankar Joshi (Inactive) made changes -
            Assignee Shubhankar Joshi [ shubhankar ] Zeeshan Chishty [ zeeshan.chishty ]
            Hide
            Zeeshan.Chishty Zeeshan Chishty (Inactive) added a comment -

            Step 1: Do not set default password. If set it should be random always and not predictable.
            Step 2: Send a onetime valid link to the users mail id .Set a 1 or 2 day expiration time for using that link.
            Step 3: When user clicks the link navigate user to change password page/set password page
            Step 4: Use a strong password policy like minimum 8 characters, alpha numeric at least 1 special and 1 upper
            case character .no sequential characters allowed(11,aa,555)
            Step 5:Invalidate the sent link immediately from server.

            Show
            Zeeshan.Chishty Zeeshan Chishty (Inactive) added a comment - Step 1: Do not set default password. If set it should be random always and not predictable. Step 2: Send a onetime valid link to the users mail id .Set a 1 or 2 day expiration time for using that link. Step 3: When user clicks the link navigate user to change password page/set password page Step 4: Use a strong password policy like minimum 8 characters, alpha numeric at least 1 special and 1 upper case character .no sequential characters allowed(11,aa,555) Step 5:Invalidate the sent link immediately from server.
            Zeeshan.Chishty Zeeshan Chishty (Inactive) made changes -
            Status Local Testing [ 10200 ] Reopen in Local [ 10018 ]
            vijayendra Vijayendra Shinde (Inactive) made changes -
            Link This issue relates to ST-168 [ ST-168 ]
            Hide
            vijayendra Vijayendra Shinde (Inactive) added a comment -

            ST 168 is enhancement suggestion to ST-88.

            Show
            vijayendra Vijayendra Shinde (Inactive) added a comment - ST 168 is enhancement suggestion to ST-88 .
            vijayendra Vijayendra Shinde (Inactive) made changes -
            Link This issue relates to ST-168 [ ST-168 ]
            Zeeshan.Chishty Zeeshan Chishty (Inactive) made changes -
            Assignee Zeeshan Chishty [ zeeshan.chishty ] Niteen Surwase [ niteen.surwase ]
            niteen.surwase Niteen Surwase (Inactive) made changes -
            Assignee Niteen Surwase [ niteen.surwase ] Vijayendra Shinde [ ID10506 ]
            Hide
            rakeshr Rakesh Roy (Inactive) added a comment -

            Vijayendra Shinde Is this re-open?

            Show
            rakeshr Rakesh Roy (Inactive) added a comment - Vijayendra Shinde Is this re-open?
            Hide
            vijayendra Vijayendra Shinde (Inactive) added a comment - - edited

            Hi Rakesh,

            Zeeshan has some suggestion over existing password generation. He has added new JIRA ST-168 for this suggestion.

            Changes which we did for this ticket are working fine.

            We can move this to Stage.

            Thanks.

            Show
            vijayendra Vijayendra Shinde (Inactive) added a comment - - edited Hi Rakesh, Zeeshan has some suggestion over existing password generation. He has added new JIRA ST-168 for this suggestion. Changes which we did for this ticket are working fine. We can move this to Stage. Thanks.
            rakeshr Rakesh Roy (Inactive) made changes -
            Item State Parent values: LB QA(10201) Parent values: LB QA(10201)Level 1 values: Ready for Stage(10213)
            rakeshr Rakesh Roy (Inactive) made changes -
            Status Reopen in Local [ 10018 ] In Development [ 10007 ]
            rakeshr Rakesh Roy (Inactive) made changes -
            Status In Development [ 10007 ] Local Testing [ 10200 ]
            rakeshr Rakesh Roy (Inactive) made changes -
            Developer Vijayendra Shinde [ ID10506 ]
            gokul.sonawane Gokul Sonawane (Inactive) made changes -
            Item State Parent values: LB QA(10201)Level 1 values: Ready for Stage(10213) Parent values: Stage QA(10202)Level 1 values: Stage Deployed(11602)
            vijayendra Vijayendra Shinde (Inactive) made changes -
            Assignee Vijayendra Shinde [ ID10506 ] Deepali Tidke [ deepalit ]
            gokul.sonawane Gokul Sonawane (Inactive) made changes -
            Item State Parent values: Stage QA(10202)Level 1 values: Stage Deployed(11602) Parent values: LB QA(10201)Level 1 values: LB Deployed(11600)
            deepalit Deepali Tidke (Inactive) made changes -
            Link This issue is blocked by WT-3585 [ WT-3585 ]
            Hide
            deepalit Deepali Tidke (Inactive) added a comment -

            Once WT-3585 is fixed , can proceed with this patch

            Show
            deepalit Deepali Tidke (Inactive) added a comment - Once WT-3585 is fixed , can proceed with this patch
            deepalit Deepali Tidke (Inactive) made changes -
            Item State Parent values: LB QA(10201)Level 1 values: LB Deployed(11600) Parent values: LB QA(10201)Level 1 values: In Testing(10210)
            gokul.sonawane Gokul Sonawane (Inactive) made changes -
            Item State Parent values: LB QA(10201)Level 1 values: In Testing(10210) Parent values: LB QA(10201)Level 1 values: LB Deployed(11600)
            deepalit Deepali Tidke (Inactive) made changes -
            Item State Parent values: LB QA(10201)Level 1 values: LB Deployed(11600) Parent values: LB QA(10201)Level 1 values: On Hold(10211)
            Hide
            deepalit Deepali Tidke (Inactive) added a comment -

            verified on lb , all the passwords combinations on security pages are working fine.

            Show
            deepalit Deepali Tidke (Inactive) added a comment - verified on lb , all the passwords combinations on security pages are working fine.
            deepalit Deepali Tidke (Inactive) made changes -
            Item State Parent values: LB QA(10201)Level 1 values: On Hold(10211) Parent values: LB QA(10201)Level 1 values: Ready for Stage(10213)
            rakeshr Rakesh Roy (Inactive) made changes -
            Item State Parent values: LB QA(10201)Level 1 values: Ready for Stage(10213) Parent values: Stage QA(10202)Level 1 values: Stage Deployed(11602)
            rakeshr Rakesh Roy (Inactive) made changes -
            Status Local Testing [ 10200 ] Pending for Stage Approval [ 10300 ]
            rakeshr Rakesh Roy (Inactive) made changes -
            Status Pending for Stage Approval [ 10300 ] Approved for Stage [ 10030 ]
            rakeshr Rakesh Roy (Inactive) made changes -
            Status Approved for Stage [ 10030 ] Stage Testing [ 10201 ]
            Hide
            deepalit Deepali Tidke (Inactive) added a comment -

            verified on stage , all the passwords combinations on security pages are working fine.

            Show
            deepalit Deepali Tidke (Inactive) added a comment - verified on stage , all the passwords combinations on security pages are working fine.
            deepalit Deepali Tidke (Inactive) made changes -
            Item State Parent values: Stage QA(10202)Level 1 values: Stage Deployed(11602) Parent values: Stage QA(10202)Level 1 values: Ready for Production(10217)
            satyap Satya made changes -
            Item State Parent values: Stage QA(10202)Level 1 values: Ready for Production(10217) Parent values: Production QA(10203)Level 1 values: Production Deployed(10221)
            hrishikesh.deshpande Hrishikesh Deshpande (Inactive) made changes -
            Assignee Deepali Tidke [ deepalit ] Rashmita Dudhe [ rashmita.dudhe ]
            rashmita.dudhe Rashmita Dudhe (Inactive) made changes -
            Status Stage Testing [ 10201 ] Pending for Production Approval [ 10301 ]
            rashmita.dudhe Rashmita Dudhe (Inactive) made changes -
            Status Pending for Production Approval [ 10301 ] Approved for production [ 10034 ]
            rashmita.dudhe Rashmita Dudhe (Inactive) made changes -
            Status Approved for production [ 10034 ] Production Testing [ 10202 ]
            rashmita.dudhe Rashmita Dudhe (Inactive) made changes -
            Item State Parent values: Production QA(10203)Level 1 values: Production Deployed(10221) Parent values: Production QA(10203)Level 1 values: In Testing(10218)
            Hide
            rashmita.dudhe Rashmita Dudhe (Inactive) added a comment -

            We can not add new Company on Production.
            for existing company all the passwords combinations on security pages are working fine.

            Show
            rashmita.dudhe Rashmita Dudhe (Inactive) added a comment - We can not add new Company on Production. for existing company all the passwords combinations on security pages are working fine.
            rashmita.dudhe Rashmita Dudhe (Inactive) made changes -
            Item State Parent values: Production QA(10203)Level 1 values: In Testing(10218) Parent values: Production Complete(10222)Level 1 values: Closed(10223)
            rashmita.dudhe Rashmita Dudhe (Inactive) made changes -
            Resolution Fixed [ 1 ]
            Status Production Testing [ 10202 ] Production Complete [ 10028 ]
            rashmita.dudhe Rashmita Dudhe (Inactive) made changes -
            Status Production Complete [ 10028 ] Closed [ 6 ]
            Transition Time In Source Status Execution Times
            Vijayendra Shinde (Inactive) made transition -
            New Request Pending for Approval
            36s 1
            Vijayendra Shinde (Inactive) made transition -
            Pending for Approval Approved for Development
            4s 1
            Vijayendra Shinde (Inactive) made transition -
            Approved for Development In Development
            2s 1
            Vijayendra Shinde (Inactive) made transition -
            In Development Mockup Approval
            20h 5m 1
            Vijayendra Shinde (Inactive) made transition -
            Mockup Approval Mockup Approved
            3m 1s 1
            Vijayendra Shinde (Inactive) made transition -
            Mockup Approved In Development
            4s 1
            Zeeshan Chishty (Inactive) made transition -
            In LB Testing Reopen in Local
            30d 23h 7m 1
            Rakesh Roy (Inactive) made transition -
            Reopen in Local In Development
            80d 1h 44m 1
            Rakesh Roy (Inactive) made transition -
            In Development In LB Testing
            6d 7h 18m 2
            Rakesh Roy (Inactive) made transition -
            In LB Testing Pending for Stage Approval
            41d 22h 9m 1
            Rakesh Roy (Inactive) made transition -
            Pending for Stage Approval Approved for Stage
            2s 1
            Rakesh Roy (Inactive) made transition -
            Approved for Stage Stage Testing
            6s 1
            Rashmita Dudhe (Inactive) made transition -
            Stage Testing Pending for Production Approval
            16d 18h 17m 1
            Rashmita Dudhe (Inactive) made transition -
            Pending for Production Approval Approved for production
            3s 1
            Rashmita Dudhe (Inactive) made transition -
            Approved for production In Production Testing
            7s 1
            Rashmita Dudhe (Inactive) made transition -
            In Production Testing Production Complete
            5h 44m 1
            Rashmita Dudhe (Inactive) made transition -
            Production Complete Closed
            196d 17h 34m 1

              People

              Assignee:
              rashmita.dudhe Rashmita Dudhe (Inactive)
              Reporter:
              vijayendra Vijayendra Shinde (Inactive)
              Developer:
              Vijayendra Shinde (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              5 Start watching this issue

                Dates

                Created:
                Updated:
                Resolved: