• Please be aware: Kaspersky Anti-Virus has been deprecated
    With the upgrade to Plesk Obsidian 18.0.64, "Kaspersky Anti-Virus for Servers" will be automatically removed from the servers it is installed on. We recommend that you migrate to Sophos Anti-Virus for Servers.
  • The Horde webmail has been deprecated. Its complete removal is scheduled for April 2025. For details and recommended actions, see the Feature and Deprecation Plan.
  • We’re working on enhancing the Monitoring feature in Plesk, and we could really use your expertise! If you’re open to sharing your experiences with server and website monitoring or providing feedback, we’d love to have a one-hour online meeting with you.

Question Password Generate button in template "ch_pass_by_secret.php" (reset login password screen)

Hey

Plesk 17.5.3

By default, when an user wants to reset its panel user's password, it will be redirected to https://domain.tld:8443/ch_pass_by_secret.php?secret=abCxyZ at one point.

Since I've set the password security to very strong I found many users being unable to deal with the error message given in case the entered new password is not strong enough:
Error: Your password is not complex enough. According to the server policy, the minimal password strength is Very strong. To improve the password strength, use numbers, upper and lower-case characters, and special characters like !,@,#,$,%,^,&,*,?,_,~

The problems here are the facts that there is no mention of the minimum length of the password and also there is no "Generate" button present as it can be found in many other forms that require a password input by the user.

Even though the support page How does password strength policy work in Plesk? gives a good hint about how a password should be build in my eyes it is not suitable to required users to first of all read some docs about how the password policy in plesk works before they can login.

So I though about modifying ch_pass_by_secret.php (/opt/psa/admin/htdocs/ch_pass_by_secret.php) on my own, however this file is encoded - also I can not find any information about how to make a template change update-proof (not 100% sure this is the correct file but at least that's the one that gets called).

Giving an user voice/request certainly is an option but since I haven't found any related topic so far I'm afraid that the request will become on of these single-voice-requests. So, how could I achieve a "Generate" password button and a more meaningful error description?


Expected result may look somewhat like this:
2018-10-19_1606.png
 
OR I wonder if it’s possible to change the reset password link and implement our own script via API, or maybe integrate a Plesk password reset option inside of WHMCS or whatever billing model you’re using. Just throwing out ideas....

Edit to throw this out there; a certain host I work with only sends out credentials for WHMCS when a customer orders. They refer to it as the “main account login”, they then use API calls to login users to other services like Plesk. VERY few people actually noticed the reset password option on the Plesk login page as very few people actually would logout and see it.
 
Last edited:
There are two possible ways to resolve the issue:

  1. Specify more complex password by using the Generate button near the password field:
There are two possible ways to resolve the issue:

2.Reduce the password complexity:

  • via GUI (Graphical User Interface):

    Go to Plesk > Tools & Settings > Security Policy > Password strength and change the Minimum password strength value:

  • via CLI (Command Line Interface):
    1. Connect to the server via RDP.

    2. Open Command Prompt.

    3. Execute the following command:
 
from Change Log for Plesk:
23 October 2018
Plesk Onyx 17.9 Preview 7
* Improved the “Change Your Password” screen: password strength is now checked on the fly, plus users can now create a strong password with one click using the “Generate” button.


... is this what I think it is? :) any chance to get this update in earlier versions too as I'm stuck (yes, I know I'm saying that every time) with my multi server setup on v17.5.3


@zeeshan786, thanks but
1) that's the point, this button does not exist ;)
2) I don't want to reduce the password security - I just want users to be able more easily to reset their password by generating one
 
Back
Top