Horde/IMP, by default, does not seem to enforce strict passwords. This can cause a lot of issues due to the number of brute force scans going on out there in internetland. If you (or a client you are representing) want to set horde to do the typical “strict password” enforcement, look for the file:


And read the bit about password policy. An example policy that can be set in this file that would require 1 capital, 1 lowercase, 1 special character and 1 number, with a minimum password size of 8, would look like:

‘password policy’ => array(
‘minLength’ => 8,
‘maxLength’ => 64,
‘maxSpace’ => 0,
‘minUpper’ => 1,
‘minLower’ => 1,
‘minNumeric’ => 1,
‘minSymbols’ => 1

Took me a bit to find this, so I figured I’d pass it along to other linux folks working with Horde/IMP.

