Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...How do I configure DNN for hashed passwords?How do I configure DNN for hashed passwords?
Previous
 
Next
New Post
4/22/2010 9:21 AM
 

DNN uses the underlying ASP .Net security provider which has the ability to store passwords as a one-way hash.  The hashing technique is considered a more secure way to store a password.

How do I configure DNN to use the feature?


Best wishes,
- Richard
Agile Development Consultant, Practitioner, and Trainer
www.dynamisys.co.uk
 
New Post
4/22/2010 10:33 AM
 

 Edit web.config and change the password configuration for  AspNetSqlMembershipProvider.




Joe Craig
Patapsco Research Group, Ellicott City, MD
DotNetNuke Development and Services (http://patapscorg.com)
 
New Post
4/22/2010 12:31 PM
 

 

 

.  If you just change the web config then DNN handles it pretty gracefully...
 
        <addname="AspNetSqlMembershipProvider"type="System.Web.Security.SqlMembershipProvider"
             connectionStringName="SiteSqlServer"enablePasswordRetrieval="false"
             enablePasswordReset="true"requiresQuestionAndAnswer="false"
             minRequiredPasswordLength="7"minRequiredNonalphanumericCharacters="0"
             requiresUniqueEmail="false"passwordFormat="Hashed"applicationName="DotNetNuke"
             description="Stores and retrieves membership data from the local Microsoft SQL Server database" />
 
I turned ON hashing and OFF password retrieval from the defaults.  
You can still login with the old passwords (clever!). Membership table stores new a accounts, added under the new regime, as having a different password format.
 
If you try to get a password back then the page tells you  - “This site does not support password retrieval but will email you a new random one.”
 
The only place it really goes wrong is if you return the web config to the original default setting and then try to get a password back, from a new regime account.  At least it didn’t crash but it tells you there was an error recovering your password.  The user would have to ask the admin to reset the account password.

Best wishes,
- Richard
Agile Development Consultant, Practitioner, and Trainer
www.dynamisys.co.uk
 
Previous
 
Next
HomeHomeUsing DNN Platf...Using DNN Platf...Administration ...Administration ...How do I configure DNN for hashed passwords?How do I configure DNN for hashed passwords?


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out