Login Management
Introduction
To further secure the login in Relution, a variety of settings can be configured under Home → Settings → Login Data Management. Here, the settings for password complexity, multi-factor authentication (MFA), and fail2ban are described.
Password Policy
- Allow simple passwords
A simple password may match the username, e.g., username test and password test.
- Minimum password length
- Maximum password age in days
- Minimum number of digits
- Minimum number of lowercase letters
- Minimum number of uppercase letters
- Minimum number of special characters
- Disable Forgot Password functionality
Disabling Password Reset
The “Forgot Password” functionality can be disabled under Login Management settings. If disabled, password reset without administrator intervention is no longer possible. Local accounts that lose their password require an administrator to reset it directly.
Ensure at least one administrator account with a known, recoverable password exists before disabling this option.
Multi-Factor Authentication
- Email Authentication
- Expiration time for one-time codes
- Authenticator Apps (TOTP)
Failed Login Attempts
- Lock user account after consecutive failed login attempts
- Maximum number of failed login attempts