Skip to content

Add password policy and CSP configuration options - #493

Open
Donien wants to merge 1 commit into
mainfrom
feature/icingaweb-password-policy
Open

Add password policy and CSP configuration options#493
Donien wants to merge 1 commit into
mainfrom
feature/icingaweb-password-policy

Conversation

@Donien

@Donien Donien commented Aug 20, 2026

Copy link
Copy Markdown
Member

Adds new CSP options to the Icinga Web configuration as well as an option for choosing a password policy.

Adds new CSP options to the Icinga Web configuration as well as an
option for choosing a password policy.
@Donien
Donien requested a review from dgoetz August 20, 2026 12:12
@Donien Donien self-assigned this Aug 20, 2026

@dgoetz dgoetz left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

As always I have some change requests.

choices: [ 0, 1 ]
use_custom_csp:
description:
- Set this to 1 to use custom CSP as defined in O(icingaweb2_config.security.use_custom_csp).

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This needs to be icingaweb2_config.security.custom_csp.

required: false
password_policy:
description:
- Sets the global password policy of Icinga Web. You can use the default C(common) password policy. Other choices are available through modules that provide password policies.

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Default is still no password policy and common is checking for length and character classes, so I would change the description a bit. What do you think about?

Sets the global password policy of Icinga Web. The default is no policy at all. The other option provided by Icinga Web is C(common) which checks for password length and character classes. Additional choices are available through modules that provide password policies.

- Set this to 1 to enable strict Content Security Policy (CSP).
type: int
required: false
default: 0

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Why no default anymore? Because it is active (or better inactive) without configuration like it would be with this default? I would be more opinionated here and even enable it by default for more security.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants