We allow them when users set their passwords, and no doubt allowed from LDAP and other external sources. We should allow them to be entered. Closes #229.