cool; just to expand - since hashed passwords are all the same length in a db, there's no benefit for max length requirements, and providing character limitations gives attackers a blueprint for brute force attacks since they now know what characters they
don't need to try. When your requirements are too strict, this can make hashes orders of magnitude faster to reverse.
my personal stance is: if they can type it, it can be in a password