Uploaded image for project: 'ZABBIX FEATURE REQUESTS'
  1. ZABBIX FEATURE REQUESTS
  2. ZBXNEXT-8858

Password check against Have I Been Pwned db

XMLWordPrintable

    • Icon: Change Request Change Request
    • Resolution: Unresolved
    • Icon: Trivial Trivial
    • None
    • None
    • None
    • None

      Hello,
      I would be nice if we could level up our password checking process and check user passwords against https://haveibeenpwned.com/API/v3#PwnedPasswordsDownload

      This is one of the largest leaked password database, much larger than /data/top_passwords.txt file in Zabbix.

      This implementation should support offline options as well. No live external API calls.

      The check should happen while creating password for new user or changing passwords for existing users.

            Unassigned Unassigned
            akplenkovs Aldis Kesans-Plenkovs
            Votes:
            0 Vote for this issue
            Watchers:
            4 Start watching this issue

              Created:
              Updated: