Merge pull request #5234 from apache/more-secure-defaults

enhance default security of passwords