Menu

#2336 Update Keepass to change the default MasterKey force password change values

KeePass
closed
nobody
None
5
2018-02-22
2018-02-21
No

I am deploying Keepass 2 to Associated British foods Corporation.
They have requested when a new database is created that the:
Recommend changing the Master Key is set to 80 days
Force Changing the master Key is set to 90 days.

There is a XML value MasterkeyexpireRec which I have set to below following support documentation.
<masterkeyexpiryrec>P90D</masterkeyexpiryrec>
However this throughs up an error that P90D is not valid field.

I have done some investigation and it appears the recommended and the Force Master key values are stored in the Database and no configuration can set this.

If you set the <uiflags>8</uiflags> then when a database is created the recommended time is set to 182 and the force is set to 365.

I would like to request that a configuration change is made to Keepass so these values can be set to a determined value.

Discussion

  • Dominik Reichl

    Dominik Reichl - 2018-02-21
    • status: open --> closed
     
  • Dominik Reichl

    Dominik Reichl - 2018-02-21

    Specifying database settings via a configuration file is inconvenient and not a good solution. Instead of this, I'd suggest to create a template database file that has all the settings configured as you wish and distribute this template database file to your users.

    The MasterKeyExpiryRec configuration setting must be set to an XSD date (see [1]), not a duration. For periodic change recommendations, use the template database file approach.

    Best regards,
    Dominik

    [1] https://keepass.info/help/base/keys.html#pwmin

     

Log in to post a comment.

MongoDB Logo MongoDB