<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <title>Passwords longer than 128 characters should be rejected</title>
  <link rel="self" href="https://liferay.dev/c/message_boards/find_thread?p_l_id=119785294&amp;threadId=122336595" />
  <subtitle>Passwords longer than 128 characters should be rejected</subtitle>
  <id>https://liferay.dev/c/message_boards/find_thread?p_l_id=119785294&amp;threadId=122336595</id>
  <updated>2026-05-13T06:56:52Z</updated>
  <dc:date>2026-05-13T06:56:52Z</dc:date>
  <entry>
    <title>RE: RE: Passwords longer than 128 characters should be rejected</title>
    <link rel="alternate" href="https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=122359349" />
    <author>
      <name>Václav Suchánek</name>
    </author>
    <id>https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=122359349</id>
    <updated>2024-01-26T10:43:22Z</updated>
    <published>2024-01-26T10:43:21Z</published>
    <summary type="html">&lt;p&gt;Thank you, Zsigmond.&lt;/p&gt;</summary>
    <dc:creator>Václav Suchánek</dc:creator>
    <dc:date>2024-01-26T10:43:21Z</dc:date>
  </entry>
  <entry>
    <title>RE: RE: Passwords longer than 128 characters should be rejected</title>
    <link rel="alternate" href="https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=122354143" />
    <author>
      <name>Zsigmond Rab</name>
    </author>
    <id>https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=122354143</id>
    <updated>2024-01-23T10:38:58Z</updated>
    <published>2024-01-23T10:38:57Z</published>
    <summary type="html">&lt;p&gt;Hi Václav,&lt;/p&gt;
&lt;p&gt;Watch &lt;a href="https://liferay.atlassian.net/browse/LPD-15194"&gt;https://liferay.atlassian.net/browse/LPD-15194&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Regards,&lt;br&gt; Zsigmond&lt;/p&gt;</summary>
    <dc:creator>Zsigmond Rab</dc:creator>
    <dc:date>2024-01-23T10:38:57Z</dc:date>
  </entry>
  <entry>
    <title>RE: RE: Passwords longer than 128 characters should be rejected</title>
    <link rel="alternate" href="https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=122346108" />
    <author>
      <name>Václav Suchánek</name>
    </author>
    <id>https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=122346108</id>
    <updated>2024-01-18T11:02:55Z</updated>
    <published>2024-01-18T11:02:55Z</published>
    <summary type="html">&lt;p&gt;Hello Zsigmond,&lt;/p&gt;
&lt;p&gt;Yes, you are right. For sure we can limit the length of the password
  with regex (portal properties). But what if we don't want to use a
  regex because of the following issue:&lt;br&gt;
  &lt;a href="https://liferay.atlassian.net/browse/LPS-152747"&gt;https://liferay.atlassian.net/browse/LPS-152747&lt;/a&gt;
  &lt;br&gt; In the end, we have to establish a very complex regex pattern
  that follows all our password policies.&lt;/p&gt;
&lt;p&gt;Regards,&lt;br&gt; Václav&lt;/p&gt;</summary>
    <dc:creator>Václav Suchánek</dc:creator>
    <dc:date>2024-01-18T11:02:55Z</dc:date>
  </entry>
  <entry>
    <title>RE: Passwords longer than 128 characters should be rejected</title>
    <link rel="alternate" href="https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=122341524" />
    <author>
      <name>Zsigmond Rab</name>
    </author>
    <id>https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=122341524</id>
    <updated>2024-01-16T08:17:58Z</updated>
    <published>2024-01-16T08:17:57Z</published>
    <summary type="html">&lt;p&gt;Hi Václav,&lt;/p&gt;
&lt;p&gt;I believe this can be done with password policies. There you can set
  a Minimum Length and you can even define a Regular Expression to
  validate the passwords.&lt;/p&gt;
&lt;p&gt;Regards,&lt;br&gt; Zsigmond&lt;/p&gt;</summary>
    <dc:creator>Zsigmond Rab</dc:creator>
    <dc:date>2024-01-16T08:17:57Z</dc:date>
  </entry>
  <entry>
    <title>Passwords longer than 128 characters should be rejected</title>
    <link rel="alternate" href="https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=122336594" />
    <author>
      <name>Václav Suchánek</name>
    </author>
    <id>https://liferay.dev/c/message_boards/find_message?p_l_id=119785294&amp;messageId=122336594</id>
    <updated>2024-01-12T08:22:11Z</updated>
    <published>2024-01-12T08:22:09Z</published>
    <summary type="html">&lt;p&gt;See ASVS v4.0.3, section 2.1.2:&lt;/p&gt;
&lt;p&gt;Verify that passwords of at least 64 characters are permitted, and
  that passwords of more than 128 characters are denied.&lt;/p&gt;</summary>
    <dc:creator>Václav Suchánek</dc:creator>
    <dc:date>2024-01-12T08:22:09Z</dc:date>
  </entry>
</feed>
