Help Center> Host Security Service (Old)> FAQs> Alarm and Event Management> Weak Passwords and Unsafe Accounts> Why Are the Weak Password Alarms Still Reported After the Weak Password Policy Is Disabled?
Updated on 2022-08-11 GMT+08:00

Why Are the Weak Password Alarms Still Reported After the Weak Password Policy Is Disabled?

If you have enhanced passwords before disabling the weak password policy, the weak password alarm will not be reported again.

If you do not enhance passwords before disabling the weak password policy, the reported alarm will persist and be retained for 30 days.

  • To enhance server security, you are advised to enhance the passwords of the accounts used for logging in to servers, such as SSH accounts.
  • To protect internal data of your servers, you are advised to enhance the passwords of software accounts, such as MySQL accounts and FTP accounts.

After modifying weak passwords, you are advised to perform manual detection immediately to verify the result. If you do not perform manual verification and do not disable the weak password scan, HSS will automatically check the settings the next day in the early morning.

Weak Passwords and Unsafe Accounts FAQs

more