We have updated the Admin UI password requirements to align with current industry security standards (RHEL8 compliant). These changes are designed to better protect your account and the administrative functions you manage.
Please review the new rules and procedures below, which will take effect in Release 25.1.
New Password Requirements
To create a strong and secure password, it must meet the following criteria:
Minimum Length: At least 8 characters long.
Complexity: Must include characters from at least three of the following four categories:
1 Uppercase Letter (A-Z)
1 Lowercase Letter (a-z)
1 Number (0-9)
1 Symbol or Special Character (!, @, #, $, %, etc.)
Password Update Procedures & Changes
Here's how these security enhancements will affect your Admin UI login and password management:
1. First-Time Login for New Admin ?
Previous Behavior: After logging in with your Employee ID (the default password), the system did not require you to update your password.
New Behavior: You will now be forced to update your password upon your first login using your Employee ID. The new password you choose must comply with the New Password Requirements detailed above.
2. Password Expiration for Existing Admin ?️
Previous Behavior: Existing users were never prompted or required to update their passwords.
New Behavior: To maintain security, you will now be prompted to update your password every 3 months.
If your password has expired, a pop-up window will appear upon login, asking you to set a new password.
Your new password must comply with the New Password Requirements and cannot be the same as your previous three passwords.
3. Resetting a Forgotten Password (Forgot Password)
Previous Behavior: A new temporary password was emailed to you, and you could use it indefinitely without being forced to change it.
New Behavior: This process now includes an extra mandatory security step:
You will receive a new temporary password via email that meets the new complexity rules.
When you use this temporary password to log in, the system will immediately force you to set a new permanent password.
Your new permanent password must comply with the New Password Requirements and cannot be the same as your previous three passwords.
4. Admin Changing a Crew Member's Password
Previous Behavior: Schedulers (for certain ALCs) could modify a crew member's password, and the new password did not have to meet any specific complexity rules.
New Behavior: When using the "Change Password" function for a crew member in the Crew tab, the new password you set must comply with the New Password Requirements.
The system will ensure the new password is not the same as the crew member's previous password.
The crew member will not be forced to change this password upon their next login.
These updates are essential to strengthening the security of your account and the entire Admin UI platform. Thank you for helping us keep your information secure!