Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...Require Question/Anser problemsRequire Question/Anser problems
Previous
 
Next
New Post
3/5/2009 5:08 PM
 

Alright, based on your comments, I ran down another rabbit trail.  I have a 3rd party administrative module that 'enhances' the functionality of the various user account security functions.  I tested the same scenario as listed previously and get the same results.  Apparently this 3rd party module plays along the same party lines as the core code.  Screens are virtually identical, and operates similarly.

But, the interesting tidbit I discovered during my testing, on my 4.9.x environment, if an admin account attempts to change their password, they have to enter the current password, the new password, and the new password as confirmation.  When they click to change button, the same error occurs BUT the password is actually changed to the new password. This occurs in the core code as well as my 3rd party security module.

I don't see this happening in a clean install of 5.00.01 (Didn't test in upgraded 5 environment- already deleted).

-Travis

 
New Post
3/5/2009 6:03 PM
 

Hi Travis,

Since both 4.9.x and 5.0.x rely on the same underlying ASP.NET membership architecture, I am very surprised to hear of this behavior.  I will try to reproduce on a 4.x install when I get a few moments.

Although I mentioned third-party module in the issue discussion, I am not aware of any modules with this functionality (others may be able to help here).  Your best solution is a custom provider that multiplexes an out-of-band second SQLMembershipProvider with QA disabled.  This would be a moderate development task, but has potential security implications.

Part of the reason for the QA subsystem is to prevent anyone -- administrators included -- from accessing a user's credentials.  Password retrieval and reset violate this presumption, and that is why you are working against the grain here.

Brandon


Brandon Haynes
BrandonHaynes.org
 
New Post
5/11/2009 4:48 PM
 

I ended up building my own challenge/response system that parallels the built-in one..  Mine allows the custosmer to enter up to three challege questions and responses.  They will be presented with a random selection from their list of challenges and will have to supply their response.  I can also re-initialize the challenges and responses and force the user to enter new ones the next time they login.

 

-Travis

 
Previous
 
Next
HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...Require Question/Anser problemsRequire Question/Anser problems


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out