plesk / whmcs-plugin

Other
16 stars 33 forks source link

Generate more complex passwords to fix autoprovisoning on servers with "Very Strong" security policy #32

Closed jas8522 closed 6 years ago

jas8522 commented 6 years ago

Original pull request: #24

Now repaired to work with PHP5 by falling back to mt_rand() when random_int doesn't exist.

Original text:

I'll admit this may not be the best solution to this problem but until WHMCS itself allows for stronger passwords, this at least solves the problem for Plesk.

I would have preferred to do an API call and find out what the server's Password Strength policy is prior to changing the password (ie: only set a strong password when the server policy is set to "Very Strong") however there appears to be no way to get password strength value via XML API.

It solves these two WHMCS feature requests, but only for the Plesk module: https://requests.whmcs.com/topic/strong-password-for-newly-created-accounts-using-module https://requests.whmcs.com/topic/increase-auto-generated-password-strenght

n8whnp commented 6 years ago

As of WHMCS 7.5.0 the passwords provided to the module are more secure by default:

https://requests.whmcs.com/topic/strong-password-for-newly-created-accounts-using-module

jas8522 commented 6 years ago

Wonderful!