BILLmanager 6
en En
es Es

Password settings

The article describes how a provider works with passwords in BILLmanager:

  • setting required password changes and complexity rules;
  • generating secure combinations;
  • password recovery by users;
  • protection against brute-force attacks.

To configure the password policy, go to Provider Password settings.

Required password changes

You can configure mandatory password changes:

  • for all employees and users in BILLmanager;
  • for a specific employee or user.

You can also configure the platform to check that when a user attempts to change their password, it matches:

  • the user's login or email address;
  • previous passwords.

With this configuration, users and employees see a notification about the need to change the password at the time of authorization.

To configure password change upon the next employee authorization:

  1. Go to the ProviderStaff menu.
  2. Select an employee.
  3. Click Change password.
  4. Click Ok.

To configure password change upon the next user authorization:

  1. Go to the Clients Users menu.
  2. Select the employee.
  3. Click Change password.
  4. Click Ok.

To configure changing passwords for all employees or users:

  1. Go to the ProviderPassword settings menu.
  2. In Main settings block:
    1. Set the Password complexity level:
      • do not check;
      • weak;
      • good;
      • strong.
      Read more about password strength levels in Configuration file.
    2. Enable the Consider restricted passwords option if you want to prevent specific passwords from being used. Click on the List of restricted passwords to open the editing menu. You can create, edit, or delete passwords from the list.
      Examples of restricted passwords
    3. Specify what the Minimum password length should be. For example, 10 characters.
    4. Select which characters the password should consist of. In the Password must contain field, the following options are available:
      • Digits;
      • Lowercase Latin characters — select this option if you want the password to include characters from a to z;
      • Uppercase Latin characters — select this option if you want the password to include characters from A to Z;
      • Special characters — select this option if you want the password to include characters from the list: +-*/^()[]{}=<>"''$,;:%!&?_#@.
  3. In the Password change block:
    1. Enable the Require employees to change password option. When enabled, fill in the fields:
      1. Warn after — the time in days after which BILLmanager issues a warning to the employee about the need to change the password.
      2. Block after — the time in days after which the employee must change the password to continue working in the system.
      3. Exclude employees — specify separated by spaces the IDs of employees who will not need to change the password upon the next authorization.
    2. Enable the Require users to change password option. When enabled, fill in the fields:
      1. Warn after — the time in days after which BILLmanager issues a warning to the user about the need to change the password.
      2. Block after — the time in days after which the user must change the password to continue working in the system.
      3. Exclude users — specify separated by spaces the IDs of users who will not need to change the password upon the next authorization.
    3. Set the date in the Do not block till field. This is the date until which the access of employees and users will not be blocked if they have not changed the password.

      Example
    4. Compare password with login/email — enable this option to prevent users from setting a password that matches their login or email.
    5. Compare the new password with the previous ones — enable this option to compare the new password with previous passwords when changing a password. If this option is enabled, in the Password history depth field, specify the number of recent passwords to compare the new password with.
  4. Click Ok to save the changes.

Password recovery

If a user has forgotten the password for a BILLmanager account, they can go through the password recovery process. To recover the password, the user needs to specify the email address that serves as the login for the account.

By default, BILLmanager sends a recovery code to the user's email. For BILLmanager to be able to send emails, configure the outgoing mail server.

Configure the number of password reset attempts by email:

  1. Go to ProviderPassword settings.
  2. In the Password recovery block, specify:
    1. Recovery request limit — the maximum number of password recovery emails that can be sent during the period specified in the Recovery request period field.
    2. Recovery request period — the time before the request limit is reset, in seconds.
  3. Click Ok to save the changes.

To make the platform send a confirmation code to a verified phone number:

  1. Enable and configure Fraud protection.
  2. Go to ProviderProviders  → select a provider → click Clients verification → create a phone verification rule. For more information, see the article Phone verification gateways.
  3. Go to ProviderGlobal settingsMain block → enable the Password recovery via SMS option to turn on sending a confirmation code to a verified phone number.
    If the user does not have a verified number, the confirmation code will be sent by email.
    1. Attempts to send a code — the limit on attempts to receive a password reset code by SMS. Once the limit is exceeded, password recovery will be available only by email. 
    2. Code receiving timeout, in seconds — the minimum interval between repeated password reset code sends.
    3. How to receive a code — this option lets the user choose how to receive the code: by SMS or email.

Password generation

You can configure password generation for all staff members or users. The parameters will be used for all cases where a password needs to be set. For example, for the login password or the password when ordering a virtual server.

To configure password generation:

  1. Go to ProviderPassword settings.
  2. In the Password generation block:
    1. Specify the Password length. The length of the generated password:
      • must meet the specified password complexity level;
      • cannot be less than the minimum password length specified in the Main block.
    2. Specify the Allowed symbols that will be used when generating the password. For example, 0123456789ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz
  3. Click Ok to save the changes.

Authorization settings

You can limit the number and frequency of failed login attempts and lock users who try to guess a password. These restrictions help protect the platform from network attacks that use automated password guessing (brute force).

To configure authorization settings:

  1. Go to ProviderPassword settings.
  2. In the Authorization settings block:
    1. Specify the Limit of failed password entries — the maximum number of incorrect password attempts during login. After the limit is exceeded, the system will block the user for the time specified in the settings. Default value: 3. The setting does not apply to the root user.
    2.  Specify the Attempt accounting interval — the period in minutes during which failed password attempts are counted. For example, 5 incorrect entries in 15 minutes. You can enter only an integer number of minutes. Default value: 15 attempts.
    3. Select the User lock type:

      1. Temporary lock — the user is blocked for a period and unblocked automatically. When this option is selected, specify the Delay after failed password entry, seconds. You can enter only an integer number of seconds. Default value: 20 seconds.
      2. Permanent lock — the user must reset the password using:

      Default value: Temporary lock.
  3. Click Ok to save the changes.

Changing the password by an administrator

To change an employee's password:

  1. Go to ProviderStaff members.
  2. Select a staff member → Edit.
  3. Specify a new password. To:
    • show the entered password, click the icon;
    • generate a password, click the icon.
  4. In the Confirmation field, enter the password again.
  5. Click Ok to save the changes.

To change a user's password:

  1. Go to Clients Users.
  2. Select a user → Edit.
  3. Specify a new password. To:
    • show the entered password, click the icon;
    • generate a password, click the icon.
  4. In the Confirmation field, enter the password again.
  5. Click Ok to save the changes.
Useful tips

Related topics: