GUI passwords restrictions and storing





The article describes handling, storing, and restrictions for GUI user passwords.


Product: Flowmon OS

Version: Any

Platform: Any

Question/Problem Description:

How the GUI passwords are stored in FOS?

Steps to Reproduce:  
Error Message:  
Defect Number:  
Enhancement Number:  

User passwords are hashed with the PHP password_hash function ( using the CRYPT_BLOWFISH algorithm.
After the hashing, hashes are stored in the database. 

The only requirement for a user password is 4 characters length, and no restrictions are currently planned. It is possible to use LDAP, Active Directory, or TACACS for the authentication and force the password policy there. 
There is no user lock implemented after failed logins.
The only initial password is for the "admin" user (GUI) and "flowmon" user (SSH). These are recommended to be changed in our hardening guidelines:


