I mentioned this to Fran elsewhere, but it'd be nice to see a password blacklist that would not allow clients to utilize easy passwords to bruteforce.
Things like: root, password, passw0rd, password123, server, etc should not be allowed.
You could even go a bit further to ensure clients use secure passwords by setting up something that would disallow the hostname of their VPS to be a password, or combinations that may be easy to guess like first initial + last name, etc.
And if that annoys the customers, there should be an option to just generate a strong password.
I can see it now:
Fuck, cant use 'password'. WTF?! It won't let me use 'r00t'... Hmm... 'server1'. WHAT?? UHG! I'll use the generate password feature... 'fcOFW7*a1VDDdZ#E1Qg1ZeCbxfZiio1j' what the fuck is this?!