After you have installed Mahara, you may see a number of warnings when you go to the *Site administration*. They should all be resolved to ensure that your site is secure and has all the necessary settings.
#. |new15| **Session entropy length**: Your PHP session.entropy_length setting is too small. Set it to at least 16 in your php.ini to ensure that generated session IDs are random and unpredictable enough. You can learn more about this advisory on the `OWASP session management cheatsheet <>`_.
#. **Noreply email address**: If the system email address is empty or a malformed email address, you are asked to check and correct it in the `system mail address setting <email_settings>`.
#. **Site-wide password salt**: If you do not have one set, please edit your config.php and set the "passwordsaltmain" parameter to a reasonable secret phrase: ``$cfg->passwordsaltmain = 'your secret phrase here';``
