Monday 24 October 2011

Changing password requirements

I thought I'd already done a post about this but apparently I haven't.

When I did a round of internal testing on the first Moodle site the biggest hitch people had was creating a password.  The Moodle default is to require people to have at least one upper case, one lower case, one number and one non-alpha-numeric character in their passwords.  Nobody knew what a non-alpha-numeric character was.

At first I was just going to change the wording of the text on the sign up page to clarify the password requirements but then I found out how to change them.

As an admin, go to Settings > Site Administration > Advanced Features > Security > Site Policies and scroll down to Password Policy.  You can either uncheck the box so users can have whatever password they want or you can change the requirements in the boxes below.

I just turned the password policy off.  I know having stupidly complicated passwords is supposed to protect us all from the evils of the internet but if that security comes at the expense of users who can't be bothered Googling non-alpha-numeric then it's a bit useless.  Besides, users can still have a stupidly complicated password if they want.

No comments:

Post a Comment

Comment