Expiring Passwords at the Site Level

EFT Server's HS-PCI module provides the option to expire passwords. If you do not activate the HS-PCI module, this feature is disabled after the 30-day trial expires.

On HS-PCI-enabled Sites, users are forced to change their passwords on first use. Each day it also checks whether passwords are <n> days from expiration, and those passwords are flagged for reminders, if reminders are enabled. All reminder e-mail messages are sent immediately after flagging the accounts to be reminded.

You can enable the password reset page while disallowing general access to HTTP or HTTPS. When a new user logs in to EFT Server via the HTTP or HTTPS index page, EFT Server redirects the user to the reset page. After the user creates a new password, they are returned to the index page.

Password initial reset, expiration, and account management features only apply to GlobalSCAPE and ODBC authentication Sites. These options are not available if other authentication types (AD, LDAP, etc.) are used. Password security features all apply at the Server level, not to individual accounts.

There is no way to ask FTP users to change their password prior to logging in. EFT Server allows them to authenticate, but then prevents any further interaction with their session until they change their password.

To configure the Site to expire passwords after a specific number of days

  1. In EFT Administrator, connect to EFT Server and click the Server tab.

  2. In the left pane, click the Site that you want to configure.

  3. In the right pane, click the Site Options tab.

  4. Next to Allow users to reset their passwords, click Advanced. The Reset Password Settings dialog box appears.

  5. Select the Expire passwords in <n> days check box and specify the number of days.

  6. For HS-PCI-enabled Sites, the number of days is set by default to 90 days. If you attempt to change it to fewer than 90 days, or if you clear the check box, a warning message appears.

  7. Click Apply to save the changes on EFT Server.

The text of the password expired message, below, is stored by default in C:\Program Files\GlobalSCAPE\EFT\PasswordResetMsg.html.

%full_name%, The password for account: %username% has expired. Please change your password at your earliest convenience. Instructions for changing your password via FTP, SFTP, and HTTP/S are provided below for your convenience: 1. Please enter the following URL into your browser: %reset_page% 2. Supply your current password when prompted 3. Enter your new password and confirm 4. If approved, exit the browser and login as normal.

The text of the password expiration reminder message, below, is stored by default in C:\Program Files\GlobalSCAPE\EFT\PasswordResetReminderMsg.html .

% full_name%, The password for account: %username% will expire in %days_left% days. Please change your password at your earliest convenience. Instructions for changing your password via FTP, SFTP, and HTTP/S are provided below for your convenience: 1. Please enter the following URL into your browser: %reset_page% 2. Supply your current password when prompted 3. Enter your new password and confirm 4. If approved, exit the browser and login as normal.

You can edit the HTML file for the password messages; however, be sure not to change the variables.

When a password is reset, EFT Server verifies the new password against complexity criteria and password history, if those features are enabled. Users are not allowed to proceed with their session until a password is created and accepted by the system. If the password is not accepted by the system:

For HS-PCI (Multifaceted security standard that includes requirements for security management, policies, procedures, network architecture, software design, and other critical protective measures.)-Enabled Sites:

If a Site (In EFT Administrator, a Site is similar to a virtual FTP server bound to one or more IP addresses.) is running in PCI Compliance mode, the warnings appear in the following situations: