Needs review
Project:
Password Policy
Version:
4.0.x-dev
Component:
Code
Priority:
Normal
Category:
Feature request
Assigned:
Unassigned
Reporter:
Created:
21 May 2012 at 11:08 UTC
Updated:
22 Jan 2026 at 20:17 UTC
Jump to comment: Most recent
Comments
Comment #0.0
erikwebb commentedInclude NIST requirements directly in issue
Comment #1
froboyI'm resurrecting this issue based on the new 2025 guidance from NIST.
Comment #3
froboyThis implements a new module that gets as close as possible to the NSIT guidance. I've opened #3568893: Consider including password_policy_pwned in password_policy as I think it would greatly improve the experience, and I've added suggestions to that effect in the README and help text.
cspell isn't happy about
blacklistbut I've removed that from any new additions as much as possible. We should probably remediate the policy to some better verbiage, but that's outside of the scope here.