Configure Password Strength Validation and Password Expiration

This page describes how to configure password strength validation and password expiration in Bloomreach Content. By default, password validation rules and expiration policies are disabled. You can enable and customize these settings to enforce minimum password strength and require regular password updates.

Password Strength Validation

Bloomreach Content can validate passwords whenever a user changes their password through the CMS. This occurs either via Setup > System or the Change password shortcut from the Home screen. The password validation service manages this process and is configured at:

/hippo:configuration/hippo:frontend/cms/cms-services/passwordValidationService

Each subnode under this path represents an implementation of the org.hippoecm.frontend.plugins.cms.admin.password.validation.IPasswordValidator interface. Each validator node must include the validator.class property, which specifies the implementation class. Implementations must provide a constructor that accepts a single org.hippoecm.frontend.plugin.config.IPluginConfig argument.

The password validation service supports a single configuration property: password.strength. This property determines how many optional validators must pass for a password to be considered valid.

Optional Validators

A validator is considered optional if its isOptional() method returns true. The password.strength property sets the minimum number of optional validators that must pass. If you set password.strength higher than the number of configured optional validators, the service logs an error message.

Available Password Validators

The following password validators are available:

  • org.hippoecm.frontend.plugins.cms.admin.password.validation.ContainsCapitalPasswordValidator
    Requires at least one uppercase letter (A-Z).
    Optional: Yes

  • org.hippoecm.frontend.plugins.cms.admin.password.validation.ContainsDigitPasswordValidator
    Requires at least one digit (0-9).
    Optional: Yes

  • org.hippoecm.frontend.plugins.cms.admin.password.validation.ContainsLowercasePasswordValidator
    Requires at least one lowercase letter (a-z).
    Optional: Yes

  • org.hippoecm.frontend.plugins.cms.admin.password.validation.ContainsSpecialCharacterPasswordValidator
    Requires at least one of the following characters: !, $, #, or %.
    Optional: Yes

  • org.hippoecm.frontend.plugins.cms.admin.password.validation.ContainsNoNamePasswordValidator
    Password must not contain the login name, first name, or last name.
    Optional: No

  • org.hippoecm.frontend.plugins.cms.admin.password.validation.IsNoPreviousPasswordValidator
    Password must not match any of the previous N passwords.
    Optional: No
    Properties:

    • numberOfPreviousPasswords (Long)
  • org.hippoecm.frontend.plugins.cms.admin.password.validation.MinimalLengthPasswordValidator
    Password must be at least N characters long.
    Optional: No
    Properties:

    • minimallength (Long)

Password Expiration

You can require users to update their passwords regularly by configuring password expiration notifications and automatic account disabling.

Password Expiration Notification

To notify users that their password will expire soon, configure the change password shortcut plugin at:

/hippo:configuration/hippo:frontend/cms/cms-dashshortcuts/changePasswordShortcut

Set the passwordexpirationnotificationdays property to define how many days in advance users are notified before their password expires. The default value is 3 days. During this period, a message appears on the dashboard indicating the remaining time.

Automatic Account Disabling

To automatically disable user accounts when passwords expire, set the hipposys:passwordmaxagedays property on the following node:

/hippo:configuration/hippo:security

When a user changes their password through the CMS, the corresponding hipposys:user node receives a passwordlastmodified property. From that point, the system checks the password expiration date at each login. If the password is expired, the user account is inactivated and login is prevented.

Note: Password expiration does not apply to system users. If system users are locked out due to password expiration, critical site functionality may be disrupted. System users can still access the repository programmatically (for example, via RMI) even if their password is expired.

Share Feedback
Page: /about/security/core-security/configure-password-safety-validation-and-password-expiration
Section: About
Category *
Configure Password Strength Validation and Password Expiration | Bloomreach Content Documentation