Products

Solutions

Resources

Partners

Community

Blog

About

QA

Ideas Test

New Community Website

Ordinarily, you'd be at the right spot, but we've recently launched a brand new community website... For the community, by the community.

Yay... Take Me to the Community!

Welcome to the DNN Community Forums, your preferred source of online community support for all things related to DNN.
In order to participate you must be a registered DNNizen

HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...Plain-Text PasswordsPlain-Text Passwords
Previous
 
Next
New Post
10/19/2008 6:34 PM
 

Even beyond that how can someone implement this correctly using the DNN software?  If you go onto Gemini and forgot your password, it sends you and email, which you then click a link, and are allowed to type in a new password. I dont think DNN has that ability.  Maybe someone knows how to configure this way?

JK wrote
 

 cathal connolly wrote

 

If you take a look at your web.config you'll see that the dotnetnuke supports 3 modes for password storage - clear, encrypted and hashed. By default dotnetnuke uses encryption and stores the passwords via triple-des (with a SALT value to protect against repeated values). This is basically for historical reasons, as ibuyspy portal (which dotnetnuke was originally based on) supported the recall of passwords. We added some additional security (superuser passwords cannot be retrieved via email). You can change the storage method to hashed and then dotnetnuke will store the password using SHA-1 to generate a 1 way hash, which disables the email password functionality.

Finally, dotnetnuke supports ssl, both across the site and at the page level so it's easy to force SSL for user logins.

Cathal

 



As I understand it, the complaint is about dotnetnuke.com itself sending passwords via email in plain text, which is not a terribly good idea.  Yes DNN has various password features, but that wasnt the complaint. The complaint is that dotnetnuke.com is using a far from perfect setting.

JK.

 
New Post
7/6/2009 9:11 AM
 

I was just about to enter this same problem. This happens in DNN 5.0 and 5.1. Will there be a fix for this?

 
New Post
8/19/2009 12:19 AM
 

Hello,

My name is David Hubbard. I am the President/CEO of Hubbard Genesis Corporation. As a Compliance Officer for third-party credit/debit card processors I understand the security issue brought to DNN's attention. What the community failed to do was provide a solution to your original concern.

I googled "We are pleased to advise that you have been added as a Registered User" and came across this link:

http://books.google.com/books?id=L4C7cm5N9YkC&pg=PA267&lpg=PA267&dq=%22We+are+pleased+to+advise+that+you+have+been+added+as+a+Registered+User%22&source=bl&ots=zVlBeS7fO2&sig=OfkGxWOPkb7eAlWeKmalHUIwrnk&hl=en&ei=unOLSt2sE4_aNtDNuckP&sa=X&oi=book_result&ct=result&resnum=2#v=onepage&q=%22We%20are%20pleased%20to%20advise%20that%20you%20have%20been%20added%20as%20a%20Registered%20User%22&f=false

This link provide access to an online version of 'DotNetNuke for Dummies'. It explains how you can navigate to Admin>Languages>Language Editor> in order to gain access to various response templates, including the email notifications. You can edit the templates to remove elements or "mask" them, like replacing the password [Membership:Password] command with "********". This way you can send the notification to your user and make them responsible for saving their password. I also editied the password notification so it does not include the User ID.

The file you want to edit is \App_GlobalResources\GlobalResources.resx in case you wanted to manually edit the file.

It is amazing that no one at DNN was able to address this issue in a timely manner. Perhaps they did not understand the question. It may help to be more concise in the future.

 
Previous
 
Next
HomeHomeOur CommunityOur CommunityGeneral Discuss...General Discuss...Plain-Text PasswordsPlain-Text Passwords


These Forums are dedicated to discussion of DNN Platform and Evoq Solutions.

For the benefit of the community and to protect the integrity of the ecosystem, please observe the following posting guidelines:

  1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DNN.
  2. No vendor trolling / poaching. If someone posts about a vendor issue, allow the vendor or other customers to respond. Any post that looks like trolling / poaching will be removed.
  3. Discussion or promotion of DNN Platform product releases under a different brand name are strictly prohibited.
  4. No Flaming or Trolling.
  5. No Profanity, Racism, or Prejudice.
  6. Site Moderators have the final word on approving / removing a thread or post or comment.
  7. English language posting only, please.
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out
What is Liquid Content?
Find Out