<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Forced password reset? in Off Topic</title>
    <link>https://community.checkpoint.com/t5/Off-Topic/Forced-password-reset/m-p/262358#M528</link>
    <description>&lt;P&gt;I could be mistaken, but I believe&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;confirmed previously it forces you now every 6 months to reset the password. If that is the case, as far as Im concerned, thats totally fine.&lt;/P&gt;</description>
    <pubDate>Mon, 10 Nov 2025 17:08:12 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2025-11-10T17:08:12Z</dc:date>
    <item>
      <title>Forced password reset?</title>
      <link>https://community.checkpoint.com/t5/Off-Topic/Forced-password-reset/m-p/100204#M40</link>
      <description>&lt;P&gt;I tried to log in to the forum earlier and was told my password had expired and needed to be reset. I don't think I've ever seen that before. The only sane reason I know of to force users to reset passwords is a suspected breach of an authentication database. &lt;A href="https://pages.nist.gov/800-63-3/sp800-63b.html#sec5" target="_self"&gt;NIST SP 800-63B 5.1.1.2&lt;/A&gt;: "&lt;SPAN&gt;Verifiers SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically). However, verifiers SHALL force a change if there is evidence of compromise of the authenticator.&lt;/SPAN&gt;"&lt;/P&gt;
&lt;P&gt;I use a randomly-generated password for my User Center account, not shared with anything else, and I don't see it in HaveIBeenPwned, so why the forced reset?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Oct 2020 03:11:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Off-Topic/Forced-password-reset/m-p/100204#M40</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2020-10-27T03:11:13Z</dc:date>
    </item>
    <item>
      <title>Re: Forced password reset?</title>
      <link>https://community.checkpoint.com/t5/Off-Topic/Forced-password-reset/m-p/100521#M41</link>
      <description>&lt;P&gt;We are not aware of any forced reset. Passwords in UserCenter have validity for one year, AFAIK. Also, make sure you are using 2FA.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2020 09:18:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Off-Topic/Forced-password-reset/m-p/100521#M41</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-10-29T09:18:21Z</dc:date>
    </item>
    <item>
      <title>Re: Forced password reset?</title>
      <link>https://community.checkpoint.com/t5/Off-Topic/Forced-password-reset/m-p/100584#M42</link>
      <description>&lt;P&gt;The CheckMates team doesn't have visibility into UserCenter accounts beyond the minimum information required to associate it with a community account.&lt;BR /&gt;That includes things like password resets.&lt;BR /&gt;Account Services would have to be consulted.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2020 17:33:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Off-Topic/Forced-password-reset/m-p/100584#M42</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-10-29T17:33:11Z</dc:date>
    </item>
    <item>
      <title>Re: Forced password reset?</title>
      <link>https://community.checkpoint.com/t5/Off-Topic/Forced-password-reset/m-p/101055#M44</link>
      <description>&lt;P&gt;I have a couple of accounts, with one coming up on ten years old. I don't think I've ever had to reset its password. Definitely not since 2015. Very odd.&lt;/P&gt;</description>
      <pubDate>Tue, 03 Nov 2020 19:26:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Off-Topic/Forced-password-reset/m-p/101055#M44</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2020-11-03T19:26:50Z</dc:date>
    </item>
    <item>
      <title>Re: Forced password reset?</title>
      <link>https://community.checkpoint.com/t5/Off-Topic/Forced-password-reset/m-p/117079#M65</link>
      <description>&lt;P&gt;I just got a forced reset again. One of my other accounts passed the decade mark, and it's still using the same password.&lt;/P&gt;
&lt;P&gt;I'll see what I can find out from Account Services.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Apr 2021 16:30:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Off-Topic/Forced-password-reset/m-p/117079#M65</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2021-04-27T16:30:34Z</dc:date>
    </item>
    <item>
      <title>Re: Forced password reset?</title>
      <link>https://community.checkpoint.com/t5/Off-Topic/Forced-password-reset/m-p/198868#M295</link>
      <description>&lt;P&gt;Just got it again.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-11-24 at 08.45.10.png" style="width: 892px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23418i1DF0CA9C8FCFA7C0/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2023-11-24 at 08.45.10.png" alt="Screenshot 2023-11-24 at 08.45.10.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Passwords are not milk. They do not expire. The fact this is still behaving this way is ridiculous.&lt;/P&gt;
&lt;P&gt;I've talked with Account Services. They had no idea what I was talking about and said they have no control over any password expiration. My other User Center accounts still have never had to reset their passwords.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Nov 2023 15:18:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Off-Topic/Forced-password-reset/m-p/198868#M295</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2023-11-24T15:18:19Z</dc:date>
    </item>
    <item>
      <title>Re: Forced password reset?</title>
      <link>https://community.checkpoint.com/t5/Off-Topic/Forced-password-reset/m-p/199010#M296</link>
      <description>&lt;P&gt;I'm checking, but I suspect it occurs only with "non-business" emails (Gmail and similar).&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 13:39:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Off-Topic/Forced-password-reset/m-p/199010#M296</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-11-27T13:39:30Z</dc:date>
    </item>
    <item>
      <title>Re: Forced password reset?</title>
      <link>https://community.checkpoint.com/t5/Off-Topic/Forced-password-reset/m-p/216952#M318</link>
      <description>&lt;P&gt;Happened again. Passwords don't expire, and every authority agrees that changes should only be required after a breach, so that must mean the forum is getting breached repeatedly over the span of years.&lt;/P&gt;
&lt;P&gt;Or it could mean User Center authentication isn't following the recommendations of every single authority on security, and that this failure to meet minimum standards isn't documented anywhere.&lt;/P&gt;
&lt;P&gt;Either possibility ought to be awfully embarrassing.&lt;/P&gt;</description>
      <pubDate>Sun, 09 Jun 2024 17:56:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Off-Topic/Forced-password-reset/m-p/216952#M318</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2024-06-09T17:56:44Z</dc:date>
    </item>
    <item>
      <title>Re: Forced password reset?</title>
      <link>https://community.checkpoint.com/t5/Off-Topic/Forced-password-reset/m-p/216955#M319</link>
      <description>&lt;P&gt;Gonna buy me a tin foil hat. Was just doing some searching regarding the issue you have and wanted to read a SK that I had to login.&lt;/P&gt;
&lt;P&gt;When I wanted to login:&amp;nbsp;&lt;SPAN&gt;Our records indicate that your password has expired.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 09 Jun 2024 18:34:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Off-Topic/Forced-password-reset/m-p/216955#M319</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-06-09T18:34:23Z</dc:date>
    </item>
    <item>
      <title>Re: Forced password reset?</title>
      <link>https://community.checkpoint.com/t5/Off-Topic/Forced-password-reset/m-p/216958#M320</link>
      <description>&lt;P&gt;I got the same, but assumed it was the time, as I did not have to change it in how knows how long. Not sure, but maybe someone from CP can confirm if this is indeed expected, ie happens every 6 months, 1 year?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 09 Jun 2024 20:22:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Off-Topic/Forced-password-reset/m-p/216958#M320</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-09T20:22:55Z</dc:date>
    </item>
    <item>
      <title>Re: Forced password reset?</title>
      <link>https://community.checkpoint.com/t5/Off-Topic/Forced-password-reset/m-p/217025#M322</link>
      <description>&lt;P&gt;We now require all UserCenter/PartnerMap accounts to have their password changed periodically.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jun 2024 15:06:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Off-Topic/Forced-password-reset/m-p/217025#M322</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-06-10T15:06:47Z</dc:date>
    </item>
    <item>
      <title>Re: Forced password reset?</title>
      <link>https://community.checkpoint.com/t5/Off-Topic/Forced-password-reset/m-p/217026#M323</link>
      <description>&lt;P&gt;Any idea how often? Every 3, 6 months? 1 year? Something else?&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jun 2024 15:09:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Off-Topic/Forced-password-reset/m-p/217026#M323</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-10T15:09:04Z</dc:date>
    </item>
    <item>
      <title>Re: Forced password reset?</title>
      <link>https://community.checkpoint.com/t5/Off-Topic/Forced-password-reset/m-p/217042#M324</link>
      <description>&lt;P&gt;6 months.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jun 2024 18:32:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Off-Topic/Forced-password-reset/m-p/217042#M324</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-06-10T18:32:15Z</dc:date>
    </item>
    <item>
      <title>Re: Forced password reset?</title>
      <link>https://community.checkpoint.com/t5/Off-Topic/Forced-password-reset/m-p/217043#M325</link>
      <description>&lt;P&gt;Thanks for confirming.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jun 2024 18:36:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Off-Topic/Forced-password-reset/m-p/217043#M325</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-06-10T18:36:47Z</dc:date>
    </item>
    <item>
      <title>Re: Forced password reset?</title>
      <link>https://community.checkpoint.com/t5/Off-Topic/Forced-password-reset/m-p/224982#M343</link>
      <description>&lt;P&gt;The User Center is becoming shockingly bad.&lt;/P&gt;
&lt;P&gt;First, password expiration (which, again, every authority agrees should never be done) with no announcement and no warning. No way to turn it off.&lt;/P&gt;
&lt;P&gt;Then you have to set up a TOTP token, &lt;STRONG&gt;again&lt;/STRONG&gt; with no announcement. No way to turn it off, and you have to set it up right when you're trying to log in to actually&amp;nbsp;&lt;STRONG&gt;&lt;EM&gt;do something&lt;/EM&gt;&lt;/STRONG&gt;. Like, say, when you're trying to view an SK to deal with an outage.&lt;/P&gt;
&lt;P&gt;Then random CAPTCHAs, &lt;STRONG&gt;&lt;EM&gt;again&lt;/EM&gt;&lt;/STRONG&gt; with no announcement. And &lt;STRONG&gt;again&lt;/STRONG&gt;, no way to turn off this garbage.&lt;/P&gt;
&lt;P&gt;And now business email addresses are rolled into the password expiration,&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;AGAIN&lt;/STRONG&gt;&lt;/EM&gt; with no announcement, and &lt;EM&gt;&lt;STRONG&gt;AGAIN&lt;/STRONG&gt;&lt;/EM&gt; with no way to configure it.&lt;/P&gt;
&lt;P&gt;Who is in charge of this mess and why are they in charge of anything? You can't just go changing requirements&amp;nbsp;&lt;EM&gt;&lt;STRONG&gt;without any notice&lt;/STRONG&gt;&lt;/EM&gt;!&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 15:36:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Off-Topic/Forced-password-reset/m-p/224982#M343</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2024-08-29T15:36:48Z</dc:date>
    </item>
    <item>
      <title>Re: Forced password reset?</title>
      <link>https://community.checkpoint.com/t5/Off-Topic/Forced-password-reset/m-p/224985#M344</link>
      <description>&lt;P&gt;I have not had to reset password in few months now, but lets see next time I do, if there are any issues. As far as CAPTCHAs, have not seen those in almost a year now, maybe just luck, no clue : - )&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 16:08:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Off-Topic/Forced-password-reset/m-p/224985#M344</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-08-29T16:08:45Z</dc:date>
    </item>
    <item>
      <title>Re: Forced password reset?</title>
      <link>https://community.checkpoint.com/t5/Off-Topic/Forced-password-reset/m-p/225022#M345</link>
      <description>&lt;P&gt;I actually posted an announcement of this back in May:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/General-Topics/UserCenter-PartnerMap-Accounts-to-Require-MFA-5-May-2024/m-p/212845" target="_blank"&gt;https://community.checkpoint.com/t5/General-Topics/UserCenter-PartnerMap-Accounts-to-Require-MFA-5-May-2024/m-p/212845&lt;/A&gt;&lt;BR /&gt;Granted, this doesn't help folks who didn't see it in CheckMates.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 18:51:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Off-Topic/Forced-password-reset/m-p/225022#M345</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-08-29T18:51:39Z</dc:date>
    </item>
    <item>
      <title>Re: Forced password reset?</title>
      <link>https://community.checkpoint.com/t5/Off-Topic/Forced-password-reset/m-p/262356#M527</link>
      <description>&lt;P&gt;Just happened again. For a security-focused company to still be following worst practices like this after five years should be &lt;EM&gt;&lt;STRONG&gt;deeply embarrassing&lt;/STRONG&gt;&lt;/EM&gt;.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Nov 2025 17:03:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Off-Topic/Forced-password-reset/m-p/262356#M527</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2025-11-10T17:03:46Z</dc:date>
    </item>
    <item>
      <title>Re: Forced password reset?</title>
      <link>https://community.checkpoint.com/t5/Off-Topic/Forced-password-reset/m-p/262358#M528</link>
      <description>&lt;P&gt;I could be mistaken, but I believe&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;confirmed previously it forces you now every 6 months to reset the password. If that is the case, as far as Im concerned, thats totally fine.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Nov 2025 17:08:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Off-Topic/Forced-password-reset/m-p/262358#M528</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-11-10T17:08:12Z</dc:date>
    </item>
    <item>
      <title>Re: Forced password reset?</title>
      <link>https://community.checkpoint.com/t5/Off-Topic/Forced-password-reset/m-p/262359#M529</link>
      <description>&lt;P&gt;&lt;A href="https://pages.nist.gov/800-63-4/sp800-63b.html#AAL_SEC5" target="_self"&gt;NIST SP 800-63B version 4&lt;/A&gt;, section 3.1.1.2 (emphasis mine):&lt;/P&gt;
&lt;BLOCKQUOTE&gt;&lt;HR /&gt;
&lt;P&gt;The following requirements apply to passwords.&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Verifiers and CSPs SHALL require passwords that are used as a single-factor authentication mechanism to be a minimum of 15 characters in length. Verifiers and CSPs MAY allow passwords that are only used as part of multi-factor authentication processes to be shorter but SHALL require them to be a minimum of eight characters in length.&lt;/LI&gt;
&lt;LI&gt;Verifiers and CSPs SHOULD permit a maximum password length of at least 64 characters.&lt;/LI&gt;
&lt;LI&gt;Verifiers and CSPs SHOULD accept all printing ASCII [RFC20] characters and the space character in passwords.&lt;/LI&gt;
&lt;LI&gt;Verifiers and CSPs SHOULD accept Unicode [ISO/ISC 10646] characters in passwords. Each Unicode code point SHALL be counted as a single character when evaluating password length.&lt;/LI&gt;
&lt;LI&gt;Verifiers and CSPs SHALL NOT impose other composition rules (e.g., requiring mixtures of different character types) for passwords.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Verifiers and CSPs SHALL NOT require subscribers to change passwords periodically.&lt;/STRONG&gt; However, verifiers SHALL force a change if there is evidence that the authenticator has been compromised.&lt;/LI&gt;
&lt;LI&gt;Verifiers and CSPs SHALL NOT permit the subscriber to store a hint (e.g., a reminder of how the password was created) that is accessible to an unauthenticated claimant.&lt;/LI&gt;
&lt;LI&gt;Verifiers and CSPs SHALL NOT prompt subscribers to use knowledge-based authentication (KBA) (e.g., “What was the name of your first pet?”) or security questions when choosing passwords.&lt;/LI&gt;
&lt;LI&gt;Verifiers SHALL request the password to be provided in full (not a subset of it) and SHALL verify the entire submitted password (e.g., not truncate it).&lt;/LI&gt;
&lt;/OL&gt;
&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Mon, 10 Nov 2025 17:16:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Off-Topic/Forced-password-reset/m-p/262359#M529</guid>
      <dc:creator>Bob_Zimmerman</dc:creator>
      <dc:date>2025-11-10T17:16:18Z</dc:date>
    </item>
  </channel>
</rss>

