If not mistaken, you are asking how strong the server password(s) should be. As said in the comments, you are the only one who can answer that.
Those pages should help you out:
SEC.SE
Wikipedia
Microsoft
Nist
Not in the question range
Your password(s) policies should meet the security requirements you have wisely established after assessed the risks. Here is a basic plain scheme :
0 security security requirements button super secure
<------------------------[]----------------------->
user super friendly Not user friendly at all
Here is the general idea : you have to define the security requirements button position. It's more or less a compromise between the ease of access and the security.