In this article
As part of the continuous effort to ensure that Forsta complies with the highest standards of security, the following password policy applies for end users (CAPI interviewers, report viewers, Analysts and Designers) and Authoring users (Express/Professional/Translator).
General
System messages are provided (with translations to the usual common languages) for these settings. The appropriate error messages will be displayed when users choose passwords that do not comply with the site settings.
The Authoring (Express and Professional), Reportal and Panel Portal modules all have ‘Forgotten Password’ functionality. This allows end users to trigger an email so they receive an activation link that opens a page where they can reset their password (go to Forgotten Password for more information).
All passwords, including those of panelists in Professional, Standard and Basic Panels, are hashed, and are not transmitted in plain text. Consequently, passwords will not be available in plain text for any system users. Instead, users will be sent an activation link to open a page where they can choose their own password.
Panelists
The changes to the password policy for Panelists are optional, and users must actively enable the restrictions for the Panels. Users may also choose between enabling the site settings, or defining custom settings for a panel. Panelist passwords will be hashed, meaning that passwords will not be available in plain text. When panelists use the “Forgot password” feature, they will be sent an activation link which will open a page where they can reset their password.
SaaS users
The passwords for all areas of Forsta must satisfy the same minimum requirements for complexity. Wherever passwords can be changed or set within the application, they will be validated against these rules before the change is accepted. The passwords will have to comply with these rules from the first time they are changed after the Version 14 release.
- Password history - the new password must be different from the last 12 passwords.
- Minimum age - the user will have to wait 24 hours after changing the password before being allowed to change it again.
- Maximum number of login attempts - after 5 invalid login attempts the account will be locked. The user will not be allowed to login again until the account is reactivated by the system administrator.
- Uppercase characters - the password must contain at least 1 uppercase letter.
- Non-alpha characters - the password must contain at least 1 character that is not a letter (a..z, A..Z).
- Password length - the password must contain at least 8 characters.
- Password expiry days - the password will expire after 60 days. (This will not apply for login to the CAPI console.)
For Authoring users, it is possible to enforce even stricter requirements through certain company settings. Contact Forsta support if you wish to implement a stricter policy.
On-Premise users
The following configurable settings will be enforced for all On-Premise users from the release of Version 14. If the Company Administrator selects to use the settings, users will have to comply with these settings when changing their password:
- Password history - the new password must be different from the last X passwords.
- Minimum age - the user will have to wait X hours after changing the password before being allowed to change it again.
- Maximum number of login attempts - after X invalid login attempts the account will be locked. The user will not be allowed to login again until the account is reactivated by the system administrator.
- Non-alpha-numeric characters - a required minimum number of characters that are not numbers (0..9) or letters (a..z, A..Z).
- Uppercase characters - a required minimum number of uppercase letters.
- Non-alpha characters - a required minimum number of characters that are not letters (a..z, A..Z).
- Password length - a required minimum number of characters in the password.
- Password expiry days - the password will expire after a number of days. (This will not apply for login to the CAPI console.)
- Password strength - in addition to a combination of the above settings, a regular expression may be used to enforce an even stricter policy.
For Authoring users, it is possible to enforce even stricter requirements through certain company settings. The server documentation that will be provided with the release will contain more detail.
Note: It is possible to disable the Force Password Changes functionality for End user lists, such that the end users' passwords never expire. This is done in Forsta Authoring - refer to the Professional Authoring documentation for further details.
2 Step Verification
Forsta Plus supports 2-step verification (2-factor authentication). This can be enabled on a user-by-user basis. 2-factor authentication uses the Google Authenticator™ app, and users will need to download the app to their smartphone to use 2- factor verification with Forsta Plus. When enabled, users will be required to provide an additional authentication code obtained from the app to successfully log into the system. Users have the ability to set certain devices as “trusted devices” for a period of 30 days; trusted devices will not request the additional authentication code from that user when logging in within the trusted device period. Once that period expires the user will be required to re-enter the verification code. Refer to the Professional Authoring documentation for further details.