# What’s cooking for 2022

**URL:** https://community.passbolt.com/t/what-s-cooking-for-2022/4627
**Category:** Announcements
**Created:** [December 16, 2021, 5:50pm UTC](https://community.passbolt.com/t/what-s-cooking-for-2022/4627 "2021-12-16T17:50:01Z")
**Posts on this page:** 20
**Page:** 1

<div class="post-metadata">

### Author: ![kevin](https://yyz1.discourse-cdn.com/flex031/user_avatar/community.passbolt.com/kevin/32/128_2.png) [@kevin](https://community.passbolt.com/u/kevin)
#### Post date: [December 16, 2021, 5:50pm UTC](https://community.passbolt.com/t/what-s-cooking-for-2022/4627/1 "2021-12-16T17:50:01Z")

</div>

Passbolt design team has published a new blog article about what they have been working on lately which includes some of the new upcoming features of 2022. Check it out!

[https://blog.passbolt.com/whats-cooking-for-2022-a2ce136e5c4d](https://blog.passbolt.com/whats-cooking-for-2022-a2ce136e5c4d)

So what do you think? Which one of these should we prioritize first in 2022?

_Poll ([view on site](https://community.passbolt.com/t/what-s-cooking-for-2022/4627/1))_

---

<div class="post-metadata">

### Author: ![mkerz-dcc](https://avatars.discourse-cdn.com/v4/letter/m/96bed5/32.png) [@mkerz-dcc](https://community.passbolt.com/u/mkerz-dcc)
#### Post date: [December 21, 2021, 7:21am UTC](https://community.passbolt.com/t/what-s-cooking-for-2022/4627/2 "2021-12-21T07:21:02Z")

</div>

Safari plugin! 😃

… but whatever you work on: You rock, just keep on rocking!

---

<div class="post-metadata">

### Author: ![jkubik](https://avatars.discourse-cdn.com/v4/letter/j/35a633/32.png) [@jkubik](https://community.passbolt.com/u/jkubik)
#### Post date: [December 21, 2021, 4:22pm UTC](https://community.passbolt.com/t/what-s-cooking-for-2022/4627/3 "2021-12-21T16:22:31Z")

</div>

What about Escrow? Wasn’t that supposed to be released soon as well?

---

<div class="post-metadata">

### Author: ![kevin](https://yyz1.discourse-cdn.com/flex031/user_avatar/community.passbolt.com/kevin/32/128_2.png) [@kevin](https://community.passbolt.com/u/kevin)
#### Post date: [December 22, 2021, 2:11am UTC](https://community.passbolt.com/t/what-s-cooking-for-2022/4627/4 "2021-12-22T02:11:56Z")

</div>

Escrow (Account Recovery) is indeed the current priority and should be available in a few weeks from now. The list above only includes the improvements and features on which the design team has been working on lately and is not meant to be exhaustive roadmap wise.

---

<div class="post-metadata">

### Author: ![jkubik](https://avatars.discourse-cdn.com/v4/letter/j/35a633/32.png) [@jkubik](https://community.passbolt.com/u/jkubik)
#### Post date: [December 22, 2021, 11:03am UTC](https://community.passbolt.com/t/what-s-cooking-for-2022/4627/5 "2021-12-22T11:03:31Z")

</div>

Ah, thanks for clearing that up. Really looking forward to Escrow and Password Expiry!

---

<div class="post-metadata">

### Author: ![farfade](https://avatars.discourse-cdn.com/v4/letter/f/d07c76/32.png) [@farfade](https://community.passbolt.com/u/farfade)
#### Post date: [December 23, 2021, 5:21pm UTC](https://community.passbolt.com/t/what-s-cooking-for-2022/4627/6 "2021-12-23T17:21:50Z")

</div>

Maybe it has already been discussed, sorry if it is the case : with mobile apps release, the private key of an user will become mobile too, so more likely to be _ **compromised** _ (lost, stolen, …). Would it worth it prioritizing the **differenciation of the keys by device** (to be able to disable the one embedded in a compromised device as soon as one realizes its device is lost) ? or at least the way to **let a given user change its key** (i.e. reencrypt all the passwords with the new one and removing the information encrypted with the previous, compromised one) ?

I now the key is protected by a passphrase, but for me it is sufficient only for letting a short period of time to the user to disable the lost key. Not for just saying “oh, too bad, but let’s forget it”

I also know that I can do it by myself : create another user, share the passwords of the compromised one, delete the former user. But the lambda user does not know… and if it is possible in an error prone manual way, it is possible to do it better programatically 🙂

Thanks for reading… and for the amazing work you’ve already done !

farfade

NB : for me, password expiry is a must **NOT** have : password policies must be enforced by the system to be protected (final application, directory, …), not by the user vault (it would rely on the user to change the password, that is a weak control - worse than no control at all because we might think it is done in the system to be protected, whereas it is not). But… regarding the key protecting the secrets of passbolt… it would be nice to have it expiring, with tools shipped along for renewing it (note that it would use the same feature than the one for compromised password I proposed above 😉 )

---

<div class="post-metadata">

### Author: ![okarenkov](https://avatars.discourse-cdn.com/v4/letter/o/ecae2f/32.png) [@okarenkov](https://community.passbolt.com/u/okarenkov)
#### Post date: [December 29, 2021, 12:57am UTC](https://community.passbolt.com/t/what-s-cooking-for-2022/4627/7 "2021-12-29T00:57:12Z")

</div>

SAML2 SSO would be nice feature to have

---

<div class="post-metadata">

### Author: ![Brichard](https://avatars.discourse-cdn.com/v4/letter/b/ba8739/32.png) [@Brichard](https://community.passbolt.com/u/Brichard)
#### Post date: [January 4, 2022, 12:19pm UTC](https://community.passbolt.com/t/what-s-cooking-for-2022/4627/8 "2022-01-04T12:19:40Z")

</div>

TOTP handling would be neat.

Also I agree with Farfade : password expiration should not occur in the password storage solution

---

<div class="post-metadata">

### Author: ![remy](https://yyz1.discourse-cdn.com/flex031/user_avatar/community.passbolt.com/remy/32/17_2.png) [@remy](https://community.passbolt.com/u/remy)
#### Post date: [January 4, 2022, 12:27pm UTC](https://community.passbolt.com/t/what-s-cooking-for-2022/4627/9 "2022-01-04T12:27:00Z")

</div>

Having password marked as expired, e.g. marked as needed to be changed (but not “automatically deleted” or rotated by passbolt itself), is recommendation from Cure53 audits, so this is something we will implement at some point. This is especially usefull for example when a user is removed from a group, you would want to make sure all the passwords they had access to are rotated, or at least marked as needed to be rotated. To be honest, I’m not following the rationale around this being a security weakness.

---

<div class="post-metadata">

### Author: ![farfade](https://avatars.discourse-cdn.com/v4/letter/f/d07c76/32.png) [@farfade](https://community.passbolt.com/u/farfade)
#### Post date: [January 4, 2022, 4:53pm UTC](https://community.passbolt.com/t/what-s-cooking-for-2022/4627/10 "2022-01-04T16:53:45Z")

</div>

Hi @remy !

> [@remy](#):
>
> To be honest, I’m not following the rationale around this being a security weakness.

I agree, there is no problem with security about implementing a " password expiration" feature.

My message was “if you have limited time for passbolt development, please prioritze tools for managing the compromission of (mobile) keys rather than developing a password expiration feature”. 🙂

---

<div class="post-metadata">

### Author: ![remy](https://yyz1.discourse-cdn.com/flex031/user_avatar/community.passbolt.com/remy/32/17_2.png) [@remy](https://community.passbolt.com/u/remy)
#### Post date: [January 4, 2022, 4:58pm UTC](https://community.passbolt.com/t/what-s-cooking-for-2022/4627/11 "2022-01-04T16:58:41Z")

</div>

Thanks for the precision @farfade. OpenPGP key rotation is something we’re planning to deliver with account recovery for the rotation of the “organization recovery key” (aka the one key to rule them all).  
The implementation will pave the way for doing it with the end user keys as well.

At the moment the workaround for rotating keys is to delete the user account and recreate it which not ideal but can do the job. In the past user key rotation have not been very popular / high demand, i’m glad it’s being flagged as important.

---

<div class="post-metadata">

### Author: ![Speatzle](https://avatars.discourse-cdn.com/v4/letter/s/76d3ee/32.png) [@Speatzle](https://community.passbolt.com/u/Speatzle)
#### Post date: [January 7, 2022, 10:56am UTC](https://community.passbolt.com/t/what-s-cooking-for-2022/4627/12 "2022-01-07T10:56:52Z")

</div>

Those are all very cool features but i would rather have a general usability feature/fix for using folders as not being able to search for passwords that are in folders and their sub folders is making my and my coworkers daily life hard.

> [@As a user I want to be able to search for passwords that are know are within a given folder](https://community.passbolt.com/t/as-a-user-i-want-to-be-able-to-search-for-passwords-that-are-know-are-within-a-given-folder/3607):
>
> Q1. What is the problem that you are trying to solve? Organizing Passwords using Folders becomes Useless with many folders as Users are unable to find Passwords by Folder Names. Example: Hundreds of Folders (One for Each Customer) Storing Customer Passwords (You cannot find Passwords by Customer Names as the Name is only in the Folder Name and not in the Resource Name). Q2 - Who is impacted? Everyone using the PRO Version That Organizes using lots of Folders. Q3 - Why is it important and/or …

---

<div class="post-metadata">

### Author: ![remy](https://yyz1.discourse-cdn.com/flex031/user_avatar/community.passbolt.com/remy/32/17_2.png) [@remy](https://community.passbolt.com/u/remy)
#### Post date: [January 7, 2022, 11:41am UTC](https://community.passbolt.com/t/what-s-cooking-for-2022/4627/13 "2022-01-07T11:41:47Z")

</div>

@Speatzle “advanced search”, e.g. allowing to search with more parameters, like inside a given folder, was not mentioned in the article but it is something on our radar for 2022. Thanks for your feedback.

 ![Screenshot 2022-01-07 at 12.34.19](https://canada1.discourse-cdn.com/flex031/uploads/passbolt/original/2X/c/c28f31101ff2219e1f0ccfb27db580ac4cca077f.png)

[https://docs.google.com/document/d/1t4Y1QixcT4Q3I5vCLXcCZli5ezIHCrhmnEx\_Bte9HOM/edit?usp=sharing](https://docs.google.com/document/d/1t4Y1QixcT4Q3I5vCLXcCZli5ezIHCrhmnEx_Bte9HOM/edit?usp=sharing)

---

<div class="post-metadata">

### Author: ![Speatzle](https://avatars.discourse-cdn.com/v4/letter/s/76d3ee/32.png) [@Speatzle](https://community.passbolt.com/u/Speatzle)
#### Post date: [January 7, 2022, 5:45pm UTC](https://community.passbolt.com/t/what-s-cooking-for-2022/4627/14 "2022-01-07T17:45:00Z")

</div>

Hi @remy

i have looked over the Passbolt Advanced Search Specification.  
It looks good to me but i have a few suggestions:

1. A checkbox to also recursively include passwords from sub folders in the results
2. A column in the result grid that shows the location/path of the resource (/Root/org1/folder1)
3. When right clicking a folder in the left overview to have a button to add it as a search filter

It would also be very helpful if the folder/password detail panel on the right would show the entire path in the location field instead of just the parent folder (/Root/org1/folder1).

---

<div class="post-metadata">

### Author: ![zebastiane](https://yyz1.discourse-cdn.com/flex031/user_avatar/community.passbolt.com/zebastiane/32/1123_2.png) [@zebastiane](https://community.passbolt.com/u/zebastiane)
#### Post date: [January 24, 2022, 12:16pm UTC](https://community.passbolt.com/t/what-s-cooking-for-2022/4627/15 "2022-01-24T12:16:27Z")

</div>

Hi,

I’m really looking for the ability to enforce the complexity of generated passwords for an organization. It is a recommendation I saw in many audits.

There is already a feature request regarding users’ passphrases, but I think it should be extended to generated passwords/passphrases.

> [@As an administrator I can enforce the minimum passphrase complexity in my organization settings](https://community.passbolt.com/t/as-an-administrator-i-can-enforce-the-minimum-passphrase-complexity-in-my-organization-settings/2146):
>
> Q1. What is the problem that you are trying to solve? When a user creates its passphrase the only requirement is to use 8 o more length, but they still can use passphrase like ‘12345678’. There is an advertise saying its weak but can be ingonerd by the user. Q2 - Who is impacted? Everybody. Q3 - Why is it important and/or urgent? The passphrase is the weakiest point of security in the system and as an admin I can´t control how complex/weaky is. Q4 - What is your proposed solution? (optiona…

---

<div class="post-metadata">

### Author: ![mammoth78](https://avatars.discourse-cdn.com/v4/letter/m/ad7895/32.png) [@mammoth78](https://community.passbolt.com/u/mammoth78)
#### Post date: [February 3, 2022, 1:26pm UTC](https://community.passbolt.com/t/what-s-cooking-for-2022/4627/16 "2022-02-03T13:26:46Z")

</div>

> [@farfade](#):
>
> be it has already been discussed, sorry if it is the case : with mobile apps release, the private key of an user will become mobile too, so more likely to be _ **compromised** _ (lost, stolen, …). Would it worth it prioritizing the **differenciation of the keys by device** (to be able to disable the one embedded in a compromised device as soon as one realizes its device is lost) ? or at least the way to **let a given user change its key** (i.e. reencrypt all the passwords with the new one and removing the information encrypted with the previous, compromised one) ?
> 
> I now the key is pr

Being able to **attach files to credentials** is a must have for us.  
In our use case it’s essential being able to distribute VPN certificates along with user credentials and at the moment Passbolt does not support it.  
Without this we are back to the old days: that is a big spreadsheet for credentials and a folder for secret files.

---

<div class="post-metadata">

### Author: ![gahkri](https://avatars.discourse-cdn.com/v4/letter/g/8491ac/32.png) [@gahkri](https://community.passbolt.com/u/gahkri)
#### Post date: [March 11, 2022, 10:15am UTC](https://community.passbolt.com/t/what-s-cooking-for-2022/4627/17 "2022-03-11T10:15:22Z")

</div>

What is your plan about custom fields?

We are using passbolt pro for store ssh, snmp, san switches, etc. passwords. The current solution for password storing is not the best for custom protocol (not web), custom port, etc.

A new dropdown field for resource type with custom value would be cool too, example:  
Resource type: SSH, WEB, SNMP, ILO, MYSQL etc.

---

<div class="post-metadata">

### Author: ![kevin](https://yyz1.discourse-cdn.com/flex031/user_avatar/community.passbolt.com/kevin/32/128_2.png) [@kevin](https://community.passbolt.com/u/kevin)
#### Post date: [March 11, 2022, 6:08pm UTC](https://community.passbolt.com/t/what-s-cooking-for-2022/4627/18 "2022-03-11T18:08:16Z")

</div>

@gahkri note that the “what’s cooking” blog post was only about some of the work done in the past few months by the design team, not about the product roadmap.

Good news: custom fields is indeed on the roadmap for 2022. It will allow to store various types of credentials, similarly to the use case you described.

---

<div class="post-metadata">

### Author: ![Duffman](https://yyz1.discourse-cdn.com/flex031/user_avatar/community.passbolt.com/duffman/32/3667_2.png) [@Duffman](https://community.passbolt.com/u/Duffman)
#### Post date: [July 24, 2022, 1:12am UTC](https://community.passbolt.com/t/what-s-cooking-for-2022/4627/20 "2022-07-24T01:12:28Z")

</div>

Hi Passbolt  
I am a CE user.  
This road map will be a fun ride. Adding website icons and tags to the grid is a great idea! Looks great! Accessing websites will be easier and faster.

 ![passboltnew](https://canada1.discourse-cdn.com/flex031/uploads/passbolt/original/2X/f/fb0a1c0f48bf68280233b6b1c8cddd767c077f6a.png)

---

<div class="post-metadata">

### Author: ![farfade](https://avatars.discourse-cdn.com/v4/letter/f/d07c76/32.png) [@farfade](https://community.passbolt.com/u/farfade)
#### Post date: [April 12, 2025, 7:39am UTC](https://community.passbolt.com/t/what-s-cooking-for-2022/4627/21 "2025-04-12T07:39:15Z")

</div>

Hello @remy and the wonderful passbolt team !

Any update on rotation features for end user keys ?  
It’s still not clear to me how to easily manage it, especially now it is replicated on many mobile devices.

Thanks for your attention !

[Next page](https://community.passbolt.com/t/what-s-cooking-for-2022/4627.md?page=2)
