Bug 1002276

Summary: RFE: XKCD style passwords
Product: [Fedora] Fedora Reporter: sakodak
Component: freeipaAssignee: Rob Crittenden <rcritten>
Status: CLOSED WONTFIX QA Contact: Fedora Extras Quality Assurance <extras-qa>
Severity: low Docs Contact:
Priority: unspecified    
Version: rawhideCC: abokovoy, mkosek, pviktori, rcritten, sakodak, ssorce, tapazogl
Target Milestone: ---Keywords: Triaged
Target Release: ---   
Hardware: All   
OS: All   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2021-11-01 12:44:32 UTC Type: Bug
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description sakodak 2013-08-28 19:01:46 UTC
I would very much like to have the option for XKCD style passwords as an option in IPA:

https://xkcd.com/936/

With traditional style passwords becoming less and less secure, doing this would be quite helpful.

I know it can be simulated by just doing it, but there's no way to do that and have traditional passwords at the same time (while transitioning.)  An actual password policy that I could apply to just certain groups would be the right way of going about it.

Comment 1 Rob Crittenden 2013-08-28 19:12:08 UTC
Can you be more explicit what you're asking for here. You want a password policy to enforce that the password is made up of 4 discrete words? All lower-case?

Or do you want us to do enforcement based on the entropy math?

Comment 2 sakodak 2013-08-28 19:17:02 UTC
Specifically: four discrete words, preferably with a cracklib-like check to see if they're unrelated (as in, not appearing together, in sequence, in common phrases (or at least a stub that can be extended later.))

I'm not even sure how you'd go about tackling the entropy math.

Comment 3 Rob Crittenden 2013-08-28 19:45:17 UTC
Upstream ticket:
https://fedorahosted.org/freeipa/ticket/3887

Comment 4 Theodoros Apazoglou 2021-11-01 12:44:32 UTC
There is no plan, priority or team capacity now or in the near future to work on this request. Thus, i am closing the ticket as wontfix or upstream (in case there is an upstream ticket that the community can help us solve).

We might revisit this decision according to our product goals. Thank you for reporting this bug/feature.

Theo Apazoglou
Product Owner RHEL IPA