Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeDNN Open Source...DNN Open Source...Provider and Extension ForumsProvider and Extension ForumsAuthenticationAuthenticationAspNetSqlMembershipProvider different rules for password creation and modificationAspNetSqlMembershipProvider different rules for password creation and modification
Previous
 
Next
New Post
4/5/2017 7:59 AM
 

Hi, I'm working with DNN 8.0.4 and after created an user the password used for him is no more accepted on change password for host user management.
Below simple step to reproduce:
- login with host
- go to /Admin/User-Accounts tab
- add new user (user: test password: test.one)
- edit user created and change the password to test.two and exit
- reopen user and try to change to test.one you can see it is no more possible because the provider response to me "Your new password was not accepted for security reasons. Please enter a password that you haven't used before and is long and complex enough to meet the site's password complexity requirements."
At this poin I notice to you that you're still able to create new user with password test.one

Also I've notice that the password have different rules on the user creation from her modification, indedd if you try to change with host an user password to 1234567 you receive a message "The requested password is invalid as it is either the same as the username or uses a term that is on the banned list of passwords."
But at th same time if you try to create a new user with same 1234567 password it is accepted!

Why there are these different rules for password creation from modification? I know how to personalize the password creation rules working around web.config but this not reflect on password modification.

Can I've some explanation about?
Thanks!

 
Previous
 
Next
HomeHomeDNN Open Source...DNN Open Source...Provider and Extension ForumsProvider and Extension ForumsAuthenticationAuthenticationAspNetSqlMembershipProvider different rules for password creation and modificationAspNetSqlMembershipProvider different rules for password creation and modification


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out