JBEAP-1094 brings in the change in the add-user utility behaviour, weak passwords are no longer rejected, warning is given instead (see $EAP_HOME/bin/add-user.properties). This behaviour can be reverted back by changing the value of password.restriction=WARN to password.restriction=REJECT.
I believe the Installer should mirror the behaviour of EAP utilities.
This would require change of Error dialogues to Warning if password doesn't pass the validation. Screen description and password fields tool-tips for "Create an administrative user" screen (and console dialogue) have to be updated as well. I'll handle the documentation in separate Jira.
- is related to
-
JBEAP-2859 Document that EAP installer no longer reject weak passwords
-
- Closed
-