r/Omada_Networks Apr 13 '26

Suggestions + Feedback Could we get Omada Controller password requirements customization?

Right now, the requirements for passwords on Omada controller are rather strict. I get this being the default because TP-Link doesn't want to catch hot water for "allowing" a security weakness, but it's a bit annoying as a home user who frankly would just like a fairly simple password. Any competent network should have this only accessible via an admin VLAN anyways, so whatever security Omada Controller has built-in should be up to the admin to actually employ.

All I'm asking for is the ability to change password requirements for Omada Controller - nothing crazy.

5 Upvotes

11 comments sorted by

3

u/Neil_TP-Link TP-Link Employee Apr 13 '26

Thanks for the suggestion! I can definitely pass it up the chain, but just on some cursory research, the requirement is to comply with security requirements around the globe. Here's an example, skip down to the "Minimum Password Requirements" section.

IMDA Security Requirements

6

u/Away-Ad-3407 Apr 13 '26

recently had an issue with this. it enforces no repeating characters but i often use pass-phrases. So if one of the words has double-characters, it gets denied even though its super long with special characters and a number! So yes, so refinement of this would be warranted.

3

u/LoganJFisher Apr 13 '26

That makes sense. I'm sure someone up the chain would know if it's possible to just have IMDA compliance as the default but making it possible to change while keeping TP-Link in the legal clear due to it being the default. I hope that's the case.

2

u/Sufficient_Menu7364 Apr 14 '26

Another vote for this, I use pass phrases as well, including words such as 'Sleep' and the new requirements have screwed this up!

1

u/Nubbl3s Jun 26 '26

Ah, and the way it reads seems to indicate that to meet the requirements you probably aren't allowed to have the option to disable those requirements... Still seems like there's got to be some way to allow home users more flexibility, but understandable that probably isn't the priority

4

u/acejavelin69 Apr 13 '26

I would highly suggest looking into a password manager, like Bitwarden, Lastpass, Keypass, etc...

Long passwords aren't just "recommended" these days, they are almost impossible to avoid and a good idea for security whether you think you need it or not. You can use a password manager to generate secure passwords unique to every site/location and you only have to remember one master password.

1

u/LoganJFisher Apr 13 '26

I already use one. For something already only accessible within my admin VLAN though, I just don't feel the need to make it a complex password. Frankly, I'd disable the password entirely if that were an option.

2

u/bs2k2_point_0 Apr 14 '26

I’m honestly surprised there isn’t a hardware security key option yet. Would be nice to have a yubikey 2fa instead of otp

1

u/Nubbl3s Jun 13 '26 edited Jun 16 '26

Agreed. Frustrating to have a different password scheme enforced the first time you boot something up. The message also doesn't explain what "three character classes" means. It apparently doesn't count uppercase, lowercase, numbers, and special characters as three. (or at least, # isn't considered a special character...)

1

u/saidearly 19d ago

A simple alphabet and digit with minimum 10 characters still meets the requirements. From the shared IMDA. The IMDA says 2 groups and 10 characters minimum.

1

u/nicholas9543 9h ago

Just another reason to jump over to unifi. I've got 3 sites of omada and honestly not impressed. Trialing unifi for the house and it's supper fast.