This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org
Talk:Allowing password aging
The title and description appear to be slightly misleading.
"Allowing password aging to occur unchecked can result in the possibility of diminished password integrity"
Allowing password aging is not necessarily an issue, be it checked or unchecked. Missing mechanisms or the ability to set password aging would be the issue. I would recommend changing the article name to "Password Aging not enforceable" or something along those lines.
D
I made some changes, and undid them as I noticed there is an article "Not allowing password aging". I really don't understand the point is this article.