Upgrade Notes Week 49
Password complexity update in compliance with PCI DSS 4.0
Who is affected | All users managing passwords for Administrator, Person, User Account, Company, Merchant, and Merchant Staff entities. |
What will be changed | To align with PCI DSS 4.0 standards, the requirements for password creation will be updated. Passwords must now have a minimum length of 12 characters (or 8 characters if the system does not support 12) and include both numeric and alphabetic characters. These changes aim to enhance the security of user accounts and administrative access across the platform. |
Expected release | 10.12.2024 |
Instructions | Ensure that all users update their passwords to meet the new standards once the changes are implemented. Passwords with a minimum length of 8 symbols will still be supported; however, we strongly encourage users to create stronger passwords with at least 12 characters to enhance protection and security. |
Consequences | Any existing passwords that do not meet the new standards may need to be updated to ensure compliance. While passwords with a minimum of 8 symbols will still be supported, accounts with simpler passwords are encouraged to update to stronger passwords to avoid potential security vulnerabilities. |