Skip to content
  • Solutions
    By Role
    • For Developers
    • For Content Managers
    • For Agencies
    • For IT Admins
    • For Web Hosters
    • For Developers
    • For Content Managers
    • For Agencies
    • For IT Admins
    • For Web Hosters
    By Infrastructure
    • Overview
    • AWS
    • Microsoft Azure
    • Alibaba Cloud
    • Google Cloud Platform
    • Vultr
    • Overview
    • AWS
    • Microsoft Azure
    • Alibaba Cloud
    • Google Cloud Platform
    • Vultr
    • Digital Ocean
    • Linode
    • Upcloud
    • Oracle
    • OVH
    • Digital Ocean
    • Linode
    • Upcloud
    • Oracle
    • OVH
  • Product
    • Plesk Features
    • Plesk Editions
    • What’s new
    • Pricing
    • Roadmap
    • Lifecycle Policy
    • Extensions Catalogue
  • Pricing
  • Extensions
    Featured Extensions
    • SocialBee
    • WP Toolkit
    • Sitejet Builder for Plesk
    • SEO Toolkit
    • Joomla! Toolkit
    • Premium Email
    • Email Security
    • SocialBee
    • WP Toolkit
    • Sitejet Builder for Plesk
    • SEO Toolkit
    • Joomla! Toolkit
    • Premium Email
    • Email Security
    Bundles and packs:
    • Business and Collaboration Edition
    • WP pack
    • Hosting pack
    • Power pack
    • Language pack
    • Business and Collaboration Edition
    • WP pack
    • Hosting pack
    • Power pack
    • Language pack

    See all Extensions

  • For Partners
    • Plesk Contributor Program
    • Plesk Partner Program
    • Affiliate program
    • Plesk University
  • Help Center
    • Documentation
    • Professional Services
    • Support
    • Contact Us
    • Wiki
    • Forum
  • Plesk 360 login
  • Free Trial
  • Pricing
  • Solutions
    • By Role
      • For Developers
      • For Content Managers
      • For Agencies
      • For IT Admins
      • For Web Hosters
    • By Infrastructure
      • Overview
      • Plesk on Amazon Web Services (AWS & Lightsail)
      • Microsoft Azure
      • Alibaba Cloud
      • Google Cloud Platform
      • Vultr
      • DigitalOcean
      • Linode
      • UpCloud
      • Oracle
      • OVH
  • Products
  • Pricing
  • Extensions
    • Featured Extensions
      • SocialBee
      • WP Toolkit
      • Sitejet Builder for Plesk
      • SEO Toolkit
      • Joomla! Toolkit
      • Premium Email
      • Email Security
    • Bundles and packs:
      • Business and Collaboration Edition
      • WP pack
      • Hosting pack
      • Power pack
      • Language pack
      • See all Extensions
  • For Partners
    • Plesk Contributor Program
    • Plesk Partner Program
    • Affiliate Program
    • Plesk University
  • Help Center
    • Documentation
    • Professional Services
    • Support
    • Contact Us
    • Wiki
    • Forum
  • Plesk 360 login
  • Free Trial
  • Pricing
  • Solutions
    • By Role
      • For Developers
      • For Content Managers
      • For Agencies
      • For IT Admins
      • For Web Hosters
    • By Infrastructure
      • Overview
      • Plesk on Amazon Web Services (AWS & Lightsail)
      • Microsoft Azure
      • Alibaba Cloud
      • Google Cloud Platform
      • Vultr
      • DigitalOcean
      • Linode
      • UpCloud
      • Oracle
      • OVH
  • Products
  • Pricing
  • Extensions
    • Featured Extensions
      • SocialBee
      • WP Toolkit
      • Sitejet Builder for Plesk
      • SEO Toolkit
      • Joomla! Toolkit
      • Premium Email
      • Email Security
    • Bundles and packs:
      • Business and Collaboration Edition
      • WP pack
      • Hosting pack
      • Power pack
      • Language pack
      • See all Extensions
  • For Partners
    • Plesk Contributor Program
    • Plesk Partner Program
    • Affiliate Program
    • Plesk University
  • Help Center
    • Documentation
    • Professional Services
    • Support
    • Contact Us
    • Wiki
    • Forum
  • Plesk 360 login
  • Free Trial
Plesk 360 login
Free Trial

Knowledge Base

Plesk Obsidian Default Password Strength Policy changes starting from February 18th, 2020

 
cliinstall pleskobsidianobsidian releasepasswords

General Information

The Plesk default password strength policy under Tools & Setting > Security Policy  will be changed to Strong starting from Plesk Obsidian 18.0.25.
This policy requires passwords to be at least 8 characters long and to have at least one occurrence of upper and lower-case characters, digits, and special characters, for example: P@ssw0rd12. 

Note: Uppercase/lowercase chars along with special digits requirement is only applied to short passwords(less than 14 digits). Meanwhile, the long ones(with the exception for long passwords where the same letters/digits repeat, for example "thisssisssssssss") are considered Very strong by default, even if they do not contain upper-case, digit or special symbol.

Why are we doing this?

Before the Plesk Obsidian release, the default password strength policy was set to "Very Weak".
Such passwords in Plesk satisfy only the minimum required strength and could be brute-forced in 0-7 minutes. Change in password strength policy provides strong protection from brute-force attacks.

For what Plesk servers password strength policy will be changed

Plesk default password strength policy will be changed:

    • For all new Plesk Obsidian installations the "Strong" password strength policy will be applied by default.
    • For Plesk servers updated to Plesk Obsidian:
      • If the password strength policy is "Very weak", the default value will be set to "Strong" during the next two months.
        Plesk will use the smooth rollout mechanism to change the policy.

        Note: existing passwords for users will not be changed.

      • If the password strength policy differs from "Very weak" then the used policy will be kept intact till March 2020. 
        We want everyone to have the same level of security, so after strengthening passwords for new Plesk installations, we’ll roll out the
        same for existing Plesk Obsidian installations starting from March 2020.

For Plesk Onyx and below password strength policy will not be changed.

Possible effects

Changing the default password strength policy can have an impact on automatic initialization scripts that are used during Plesk installation. If you use automatic scripts with CLI or API calls to install Plesk, adjust the password generator to meet the new policy requirements.

Tweet
Share
Share
Email
0 Shares
Read the full article
Related Posts

Plesk Obsidian 18.0.62 is now available

Read More »

Plesk Obsidian 18.0.61 Release

Read More »

Recommended OSs for Plesk

Read More »
Knowledge Base

How to enable/disable notifications about SSL It!/Let’s Encrypt certificate renewal?

Read More »

Upcoming changes in the Plesk Password Strength Policy

Read More »

Plesk available editions and difference between them

Read More »

 How to change the default content for newly created domains in Plesk?

Read More »

Hosting Wiki

  • Content Security Policy ( CSP )
  • CLI
  • Linux
  • Plesk
  • Email Virus Protection
X-twitter Linkedin Youtube Reddit Github
  • Product
  • Login
  • Pricing
  • Editions
  • For Partners
  • Partner Program
  • Contributor Program
  • Affiliate Program
  • Plesk University
  • Company
  • Blog
  • Careers
  • Events
  • About Plesk
  • Our Brand
  • Resources
  • User and Admin guides
  • Help Center
  • Migrate to Plesk
  • Contact Us
  • Hosting Wiki
  • Forum
  • Legal
  • Legal
  • Privacy Policy
  • Imprint

© 2025 WebPros International GmbH

Part of the WebPros®  Family