Skip to main content

Local password management

Local passwords support bcrypt and Argon2id in caddy-security v1.3.0 / go-authcrunch v1.3.8. A federated user changes their password at their identity provider; signing into the portal does not grant control of a local account.

Manually​

Use the released executable's password utility. It prompts without terminal echo:

authcrunch security local generate password hash
authcrunch security local generate password hash --algorithm argon2

Bcrypt is the default, cost 10. Argon2 selects Argon2id; defaults are 65536 KiB, three iterations and four lanes. The output is a quoted Caddyfile password directive, ready for static-user provisioning. Review resource use before changing cost parameters; --cost is bcrypt-only.

For automation, --password-file /private/password.txt requires an owner-only file, or --password-file - reads stdin. One final LF/CRLF is removed; other whitespace is preserved. --db-path reads the existing password policy without modifying the database. Do not put a production password on a command line.

A compatible standalone CLI can be installed at the matching version:

go install github.com/greenpau/go-authcrunch/cmd/authdbctl@v1.3.8

Its released command guide explains server configuration and updates. Do not assume installing @latest changes the library inside a previously built Caddy server.

Prefer a supported account mutation over replacing a JSON hash by hand. Manual file repair requires a stopped writer and coherent backup; it must preserve algorithm and security metadata. A password change invalidates prior credential evidence, so verify a fresh login and old refresh/OIDC credential rejection.

Settings Page​

For a local account with authp/user or authp/admin, sign in and open /auth/profile/, then choose password management. A live completed portal session is required. The old /auth/settings route is not available in this release.

  1. Confirm the selected local account and enter the current password.
  2. Enter and confirm a new password that satisfies the store's policy.
  3. Submit the change and sign in again with the new credential.
  4. Verify that the old password fails and required MFA still applies.

The released recovery endpoint does not provide a complete forgotten-password service. Establish an administrator-assisted recovery process rather than promising reset links that the implementation cannot complete.