Welcome Guest. Please Login or Register  


You are here: Index > Softaculous Auto Installer > Suggestions > Topic : Password security options



Threaded Mode | Print  

 Password security options, Let admins AND end users set their pw security preferences. (4 Replies, Read 2904 times)
Leeteq
Group: Member
Post Group: Newbie
Posts: 5
Status:
The default email notifications include the database password and the application username password by default - both in clear text - through open, insecure emails.

I suggest implementing the following customizeable options:
a) Let the Softaculous admin determine if such passwords should be sent at all (one option for each type of password), and if they should be sent, whether to let the user override this in their email settings or not.

b) Let the user specify if they want passwords in the notification emails at all (in case the admin setting is to send them, otherwise this is not relevant and this option should be hidden), or if they want to include for example only partial passwords, but not the whole password. (This can make life easier for admins that have many sites and a "password scheme" to follow, which can be hard to remember sometimes, especially in periods when default passwords are updated for security reasons).

c) Further on b).., let users specify how many characters of the password(s)(one setting for the db pw, and another for the application pw) to include, and from which side (from the left or from the right).

See also:"Default password and email template"http://www.softaculous.com/board/index.php?tid=697&tpg=1#p10268
IP: --   

Password security options
Brijesh
Group: Softaculous Team
Post Group: Super Member
Posts: 2246
Status:
Hi,

Thanks for the suggestions. We will discuss this with our team.

-----------------------
Facebook
Twitter
Vote for us
IP: --   

Password security options
alons
Group: Administrator
Post Group: Super Member
Posts: 2188
Status:
Hi,

Sir, its also possible to do this right now if you want.
We have email templates and you can modify that and remove the password option.

Adding it to the FORM will complicate the usage of the script installation. It will be more of a FEATURE creep.
I have still added this to the REVIEW by developers.
But personally I feel this is going to be a feature creep if we add options to the installation forms.

But we can add it to the USER SETTINGS form if you confirm the same. So a user can specify it in the user settings if he want to. But this will not be shown in the Installation Forms.

-----------------------
For immediate support please email us at our Support email address. PMs sent to any Softaculous Team member or posting in the forums is not the official way to get support.

Remote Installer - AEFER
Softaculous Webuzo - It is Softaculous Standalone for Enterprises, SMB, Developers. Deploy it on Dedicated Servers, VPS, Virtual Appliances or the Cloud
Softaculous Virtualizor - The Next Generation VPS Panel
IP: --   

Password security options
Leeteq
Group: Member
Post Group: Newbie
Posts: 5
Status:
Quote From : alons May 15, 2012, 8:46 am
But we can add it to the USER SETTINGS form if you confirm the same. So a user can specify it in the user settings if he want to. But this will not be shown in the Installation Forms.
ok, well it is better to have it as an option in the user settings in addition to altering the templates, so that would be an improvement in itself.
I hope it will become possible to also let the admins set a default from the CP, though.
Regards,Leeteq
IP: --   

Password security options
Brijesh
Group: Softaculous Team
Post Group: Super Member
Posts: 2246
Status:
Hi,

We will try to add it in the future versions of Softaculous.

-----------------------
Facebook
Twitter
Vote for us
IP: --   

« Previous    Next »

Threaded Mode | Print  



Jump To :


Users viewing this topic
1 guests, 0 users.


All times are GMT. The time now is October 25, 2014, 12:48 pm.

  Powered By AEF 1.0.8 © 2007-2008 Electron Inc.Queries: 11  |  Page Created In:0.247