Explore the latest product updates and best practices at our hybrid Checkmk Conference #12 from June 16-18, 2026 – Register here

Werk #15187: Enforce password policy in REST API and user management

Component Setup
Title Enforce password policy in REST API and user management
Date Feb 3, 2023
Level Trivial Change
Class Bug Fix
Compatibility Compatible - no manual interaction needed
Checkmk versions & editions
2.2.0b1 Checkmk Community, Checkmk Pro, Checkmk Ultimate, Checkmk Ultimate MT
2.1.0p21 Checkmk Community, Checkmk Pro, Checkmk Ultimate MT
2.0.0p34 Checkmk Community, Checkmk Pro, Checkmk Ultimate MT

Prior to this Werk both the REST API and the user management UI (Setup > Users) did not correctly enforce the password policy for local accounts.

As a result, administrators with the "User management" permission could set passwords that don't comply with the policy for their own or other users' accounts.

Note that the "Change password" option in the user profile menu was not affected by the issue and correctly checked the password policy.

To the list of all Werks