---
title: "Additional Password validation options"
canonical: "https://kb.myframeworks.com.au/space/FRAM/28405096/Additional%20Password%20validation%20options"
format: markdown
---
# <span style="color: #172b4d">Configuration/Setup</span>

The following System Settings can be configured to apply additional validation rules when creating passwords in Frameworks and ProStix. These are:  
  
1. **System Administration > System Tables > Miscellaneous Table Maintenance - System Settings - General **

(ProStix: Tailoring options > Values Integers)

| **Flag** | **Description** | **Value** |
| --- | --- | --- |
| **PwdAdminGrps** | List of User Groups that require extra password length restrictions as defined by **PwdMinLenAdmin** | values to be entered separated by a comma eg sysadmin, sales |
| **PwdSpecList** | List of special characters that a user must use in their password | ~!@#$%^&*`-_=+<br>These are the default values loaded by the installer but can be changed to suit your needs. |

2. **System Administration > System Tables > Miscellaneous Table Maintenance - System Settings - Numeric **

(ProStix: Tailoring Options > Codes (Characters))

| **Flag** | **Description** |
| --- | --- |
| **PwdExpNot** | Number of days before the user's password expires to notify the user when they log in |
| **PwdMinLen** | Minimum length of password |
| **PwdMinLenAdmin** | Minimum length of password for users with Security Class sysadmin and User Group in **PwdAdminGrps** |
| **PwdMinLow** | Minimum number of lower-case characters |
| **PwdMinNum** | Minimum number of numeric characters |
| **PwdMinSpec** | Minimum number of special characters from **PwdSpecList ** |
| **PwdMinUp** | Minimum number of upper-case characters |
| **PwdRetry** | Number of incorrect password attempts before locking of user account |
| **PwdReuse** | Number of days where a previous password can't be reused |

# Password Validation

In addition to the above flag validations, additional password validation rules include:

- A password cannot be used more than once in a 12-month period, as defined by system flag **PwdReuse** value
- A popup after xx number of invalid password attempts (defined by system setting **PwdRetry**). Once the maximum number of retries has been exceeded, the user is locked out, and their user ID under user maintenance is set to **Account Locked**. Only an administrator can unlock a user by disabling the **Login Locked** flag under user maintenance.

# Password Expiry

To define the password expiry period, there are 2 steps:

1. Navigate to **System Administration > System Tables > System Control File Maintenance. **
  1. Under the **Site **tab, in the **Password Expiry Days** field, enter the number of days a password will be valid for.

> ⚠️ The **Password Expiry Days** field in [System Control File Maintenance](https://sterlandsupport.atlassian.net/wiki/spaces/FRAM/pages/28401568) requires a value for the **Must Change by** field to be visible in [User Maintenance](https://sterlandsupport.atlassian.net/wiki/spaces/FRAM/pages/28378032)

2. Navigate to **System Administration > Users & Security > Users > User Maintenance. **
  1. In the **Must Change by** field, select an expiry date (if it defers from the default time period defined in System Control File Maintenance)

Once these are defined and based on the value defined under flag **PwdExpNot, **when logging in to Frameworks users will receive a warning that the password is due to expire in xxx days. Users will then need to login to Frameworks and reset their password before the expiry date.

> ⚠️ **NOTE**: If **Password will Not Expire **has been defined in [Security Group Maintenance](https://sterlandsupport.atlassian.net/wiki/spaces/FRAM/pages/28401628) on a security group assigned to a user then the above password expiries will be overwritten to NOT expire.

> ✅ Refer to [System Control File Maintenance](https://sterlandsupport.atlassian.net/wiki/spaces/FRAM/pages/28401568) for more information.
> ✅ 
> ✅ Refer to [User Maintenance](https://sterlandsupport.atlassian.net/wiki/spaces/FRAM/pages/28378032) for more information.
> ✅ 
> ✅ Refer to  [Changing your Password or PIN](#) for users to reset their password via existing password functionality.