Skip to main content

Feature Requests and Issues Regarding Password Strength Policies in cPanel Webmail

Comments

8 comments

  • cPRex Jurassic Moderator

    Hey there!  For issues 1-4, we don't currently have them in place and don't have plans for them.  If you'd like I can submit a feature request for them, but you're always welcome to do that over at features.cpanel.net as I am also the admin that handles the features site.

    For #5 I tested this just now and I wasn't able to reproduce.  If you can outline the necessary steps to take so I can make this problem happen I'd be happy to try again, or you could always submit a ticket from a system that is experiencing this problem.

    For #6, I don't have a good explanation for that.  Do you see the email getting handled at all in the main Exim log at /var/log/exim_mainlog?

    0
  • Netgate Unknown

    Hi cPRex,

    Thank you for your quick response.

    Regarding issues 1–4, I understand they are not currently implemented. Yes, please go ahead and submit the feature requests on our behalf. We will also consider posting them directly on features.cpanel.net to provide more context and track any progress.

    As for issue #5, I’ll prepare a detailed set of steps to reproduce the problem.

    - Password Strength Configuration is set to 90 for Webmail.

    - After that I apply in Configure Security Policies and Password Strength to validate the strength when entering the webmail

    - Then I try to enter a box which has less than 90 score in the strength

    - I place a key with less than the established score and the error is reproduced

    I understand this error is because a key was placed that does not meet the 90 score but it should not be allowed to update it and we see that if it is updated, only then this has to be repeated until the correct score can be entered and entered

    That is to say, if I want to enter the webmail again, it is not with the original password, but rather I update it to the one with the lowest score, even though it then asks me again and does not let me enter.

    Thanks again for your assistance.

    Best regards,

    0
  • cPRex Jurassic Moderator

    Thanks for the excellent description.  I was able to reproduce this perfectly and I've created case CPANEL-48566 with our team so they can look into this.  If you ever want to check the status on that just ask!

    Did you want me to get those other items submitted on the features site for you?

    0
  • Netgate Unknown

    Hello again,

    Thank you for confirming the creation of the case CPANEL-48566. I would like to know how I can check the status of this case in the future or contribute additional information if necessary.

    Additionally, I would like to provide more details related to Issue #6, as we are still facing the following situation:

    • The server is correctly configured to send outgoing emails from its main domain (tested and working).

    • However, WHM/cPanel is not sending system notifications, such as login alerts or password reset emails.

    • We have already verified that the corresponding contact email addresses were added correctly in "Contact Manager" and "Basic WebHost Manager® Setup".

    • We also checked /var/log/exim_mainlog, but no entries appear related to those system notification emails.

    • The server can send emails using the domain configured, but apparently not from WHM directly, which suggests the issue is limited to internal system notifications.

    Is there any other log or test we can perform to verify whether WHM is attempting to send these emails?
    Are there any debugging methods or known issues with this behavior?

    We appreciate your guidance on how to continue testing or debugging this issue.

    Best regards,

    0
  • cPRex Jurassic Moderator

    The only way to get details on the case would be the ask me directly, as we don't have anything public facing for the development system.

    It sounds like a ticket would be best to see what's happening with issue #6 as that's one of those "it should just work" - we'd likely end up stracing a cPanel process and seeing if there is anything happening there.

    0
  • Netgate Unknown

    Hello again,

    After testing, I don't know what changed but I see that the error also extends to users who entering a key with the correct score takes them to the same error screen. I just adjusted it on a production server, thinking that it would only be reflected in lower-scoring passwords, but no. This is confusing for the end user. Has anything changed since this Monday that I tested and it behaved differently than today?

    Best regards,

    0
  • cPRex Jurassic Moderator

    We haven't pushed any updates this week - you can always check the changelogs here: https://docs.cpanel.net/changelogs/130-change-log/

    0
  • Netgate Unknown

    Additional details for case CPANEL-48566

     

    After more testing, I’ve noticed that the behavior is slightly different now:

    • When logging into Webmail with a password below the configured strength requirement, the user is prompted to change it (expected).

    • If they enter a new password with a lower score, it accepts and channge shows an error message saying there was a problem (bug)

    • If they enter a new password that meets the required strength, the system still shows an error message saying there was a problem, but the password is actually updated. (bug) 

    • After reloading the Webmail login page and using the new valid password, the login works correctly.

    The issue is not preventing login, but the error message is misleading and could confuse users into thinking the password was not updated when in fact it was.

    No updates have been applied this week (confirmed via changelog), so the behavior change happened without a cPanel version change.

     

    I tried this on Monday, and it only failed for passwords that didn't reach the minimum score requested. Now, it happens for all of them. Could you try to reproduce the error? I have applied a stregth of 100 only to the mailboxes.

    I await a response

     

    0

Please sign in to leave a comment.