Add password policy and CSP configuration options - #493
Open
Donien wants to merge 1 commit into
Open
Conversation
Adds new CSP options to the Icinga Web configuration as well as an option for choosing a password policy.
dgoetz
suggested changes
Aug 26, 2026
dgoetz
left a comment
Member
There was a problem hiding this comment.
As always I have some change requests.
| choices: [ 0, 1 ] | ||
| use_custom_csp: | ||
| description: | ||
| - Set this to 1 to use custom CSP as defined in O(icingaweb2_config.security.use_custom_csp). |
Member
There was a problem hiding this comment.
This needs to be icingaweb2_config.security.custom_csp.
| required: false | ||
| password_policy: | ||
| description: | ||
| - Sets the global password policy of Icinga Web. You can use the default C(common) password policy. Other choices are available through modules that provide password policies. |
Member
There was a problem hiding this comment.
Default is still no password policy and common is checking for length and character classes, so I would change the description a bit. What do you think about?
Sets the global password policy of Icinga Web. The default is no policy at all. The other option provided by Icinga Web is C(common) which checks for password length and character classes. Additional choices are available through modules that provide password policies.
| - Set this to 1 to enable strict Content Security Policy (CSP). | ||
| type: int | ||
| required: false | ||
| default: 0 |
Member
There was a problem hiding this comment.
Why no default anymore? Because it is active (or better inactive) without configuration like it would be with this default? I would be more opinionated here and even enable it by default for more security.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Adds new CSP options to the Icinga Web configuration as well as an option for choosing a password policy.