Skip to content
Vulnotes LogoVulnotes
Local Authentication

Local Authentication

Local authentication is the default method where users log in with an email and password stored in Vulnotes. No external identity provider is required.

Local authentication

Password requirements

Administrators can configure password policies in Administration > Settings > Security. The available options include:

  • Minimum password length
  • Require uppercase and lowercase letters
  • Require numbers
  • Require special characters

The server enforces a minimum length of 12 characters, even if the settings control offers a lower value. Initial setup and invitation enrollment require uppercase and lowercase letters, a number, and a special character as well.

These rules apply when users set a password; changing the policy does not inspect or automatically replace existing passwords. The interface does not offer a password-expiration setting.

Changing or recovering a password

Use Profile > Security > Change Password while signed in. If you cannot sign in, use Forgot your password? on the login page. Password recovery requires working email delivery; see Password recovery for offline installations.