Bug 1002276 - RFE: XKCD style passwords
Summary: RFE: XKCD style passwords
Keywords:
Status: CLOSED WONTFIX
Alias: None
Product: Fedora
Classification: Fedora
Component: freeipa
Version: rawhide
Hardware: All
OS: All
unspecified
low
Target Milestone: ---
Assignee: Rob Crittenden
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2013-08-28 19:01 UTC by sakodak
Modified: 2021-11-01 12:46 UTC (History)
7 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2021-11-01 12:44:32 UTC
Type: Bug
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Issue Tracker FREEIPA-7209 0 None None None 2021-11-01 12:46:53 UTC

Description sakodak 2013-08-28 19:01:46 UTC
I would very much like to have the option for XKCD style passwords as an option in IPA:

https://xkcd.com/936/

With traditional style passwords becoming less and less secure, doing this would be quite helpful.

I know it can be simulated by just doing it, but there's no way to do that and have traditional passwords at the same time (while transitioning.)  An actual password policy that I could apply to just certain groups would be the right way of going about it.

Comment 1 Rob Crittenden 2013-08-28 19:12:08 UTC
Can you be more explicit what you're asking for here. You want a password policy to enforce that the password is made up of 4 discrete words? All lower-case?

Or do you want us to do enforcement based on the entropy math?

Comment 2 sakodak 2013-08-28 19:17:02 UTC
Specifically: four discrete words, preferably with a cracklib-like check to see if they're unrelated (as in, not appearing together, in sequence, in common phrases (or at least a stub that can be extended later.))

I'm not even sure how you'd go about tackling the entropy math.

Comment 3 Rob Crittenden 2013-08-28 19:45:17 UTC
Upstream ticket:
https://fedorahosted.org/freeipa/ticket/3887

Comment 4 Theodoros Apazoglou 2021-11-01 12:44:32 UTC
There is no plan, priority or team capacity now or in the near future to work on this request. Thus, i am closing the ticket as wontfix or upstream (in case there is an upstream ticket that the community can help us solve).

We might revisit this decision according to our product goals. Thank you for reporting this bug/feature.

Theo Apazoglou
Product Owner RHEL IPA


Note You need to log in before you can comment on or make changes to this bug.