Password Policy

 
If you have a password policy in your company, this can also be applied for the Astrow Web application in System - Tab Security. A password policy refers to the obligation users have, firstly, to have a password and then change the password after an interval defined for security reasons (additionally a limitation related to the usage of past passwords can also be set) with minimum password strength.
 
Password policy parameters in Settings - System - Application config. in Astrow Web
 
Use password policy: On YES, this will activate the password policy.
Password expires after X days (0 means never): Here you can set the number of days a password will expire after creation.
Max. number of passwords keep in history: Set here the number of passwords to keep in history for your password policy. If this parameter is set, you are not allowed to use any of the last x passwords kept in history when changing your password in accordance with the policy.
Minimum password strength: The parameter refers to the password strength. If set to Weak, the policy will accept a password with at least 6 digits or letters. If Good, the password should contain at least 7 different letters/digits, 1 special character and 1 capital letter. If Strong, the password must contain at least 9 different letters/digits and a combination of 4 different special characters and capital letters.
 
When the interval set (if > 0) for password expires, the user will get a notification at login to change it and won't be able to enter the application. If a limitation to use old passwords was set (the parameter is > 1), the user won't be able to use for change the last password(s) had in the past until the limitation expires. For example, if the limitation is 2, the user won't be able to set the last password used and the one before; if the limitation is 3, the user won't be able to use the last password used and 2 before.
 
Message for expired credentials in Astrow Web
 
The colored bar will guide you when changing the password:
 
Changing the credentials in Astrow Web
 
When changing the password, the user must set one with the strength defined in the system, otherwise, the new password won't be accepted. This is the first validation made.
 
Tooltip for inadequate strength when changing the credentials in Astrow Web
 
Message for inadequate strength when changing the credentials in Astrow Web
 
The second validation is made against the past passwords limitation. If your password is still in history, you are not allowed to use it.
 
Message for last password(s) limitation when changing the credentials in Astrow Web