Jump to content

Recommended Posts

Posted

It's nice to know that others are finding this useful, you'll still get some muppets who forget their answers too, but that's inevitable.

But if you can get away with charging for resets (I can't), it'll help with the weekly biscuit (or beer) fund :D

Posted

Thanks for the feedback guys I'm going to put the current version in place during the summer as well after I've rejigged my servers and stuff.

 

@Irazmus: Is it now complete or was there any other bit we were going to add?

 

Cheers,

 

Ben

Posted

I'm pretty sure we'd finalised on v2.0, but I'm planning one more small update during the summer anyway. I'm going to stop storing answers MD5 hashed and simpy store them as plain text. It's less secure, but it's annoying when they not only forget their password, but 1 or 2 of their reset answers too (or at least how they spelled them). And sods law dictates if they can only remember 1 reset answer, it won't be the one you didn't hash >_<

 

But like most other changes I've made, there'll be a switch in the config file so you can have whichever method you prefer.

 

Unless anyone has any other suggestions (or bugs), I think that'll be it.

Posted

Ok cool thanks for all the work you've put into the project mate. I think I hashed them originally because I'd found a security issue where you could dump someones answers and hashing them removed this problem.

 

Ben

  • 2 months later...
  • 3 months later...
Posted

Need a little help. I have installed on my XP machine and tested it locally and worked ok.

 

I tried another user on another machine and I can register details, go in and try and reset password but it fails at the final hurdle when it tries to write changes to AD.

 

I am currently testing being logged in as user rather than the specified resetpassword user.

 

Other than that its brill and once I iron out this one it will be magic.

 

Cheers

 

Tony

Posted

Have you set IIS to use anonymous access for the reset page, specifying a user which has permission to reset passwords in AD?

If not, that's where your problem lies

Posted

cheers for that, its sorted now. I just need to sort out the resetpassword user thing now and its all systems go.

 

This is what I have been waitin for for a long time, the amount password reset we do here is huge!!

 

Cheers

Posted

Hi everyone,

 

Ok its going ok but every now and then it throws an error up when you try and reset a password.

 

Error '80004005' Unexpected Error

 

Its on our 2003 server.

 

Any ideas, other than this its really cool.

 

Cheers

 

Tony

Posted

I have had look but not found a cure yet. It is soo frustrating cus it works for 5 mins then we get an error (which changes from time to time).

 

The message that appears now is

 

 

Microsoft OLE DB Provider for ODBC Drivers error '80004005'

 

[Microsoft][ODBC Microsoft Access Driver]General error Unable to open registry key 'Temporary (volatile) Jet DSN for process 0x1424 Thread 0x13dc DBC 0x15cb054 Jet'.

 

/register/register.asp, line 120

 

 

Cheers

 

Tony

  • 2 weeks later...
Posted

Hi guys this app looks really great, although i'm having problems with an error that my passswords don't meet the complexity rules, ( i have put in Mixed numbers,lettes 30 characters long and all manner of things) i'm sure its something that i'm doing wrong any one shed any light?

cheers as always in advance.

Posted

Hi,

 

What is your domain password policy presumably this is where you've set the complexity.

 

What options have you got for the SSPR pick yuor own password or one of the default lists?

 

Ben

Posted

Hi ben,

ah so its my domain policy thats the problem ok gives me somewhere to look, i tried numbers 1 to 5 in the password settings and still got the same error, i would like ideally to have them given a standard default password (less room for error).

This is a really good system by the way especially as i have managed to get the custom shell bit to work so its very well locked down now, is the admin page only available to admin users? where can i set that so its locked down so only i can get access? i have tested it access from some users and it denys access but i'm a bit paranoid...

Posted
Ben just ran a quick group policy results check and the only password setings being applied are enforce password history enabled and set to three so can't work out why it won't reset the passwords?
Posted

The admin pages are set in the configuration to the groups of users you want to have access.

 

So if it's only you then if you have a group i.e IT support or similar that only you are a member off add that group in the configuration.

 

Ben

Posted

very locked down practically no access (no drive access, start menu, custom shell etc) is there anything in particular that this user will need access to in terms of being able to reset the passwords?

i'll do some trial and error with the ou and user if you think thats whats causing the problem.

Posted

have doen some trial and error with the user (moved him out of the locked ou )and it still thows up the same error mesage

that my passswords don't meet the complexity rules?

Posted

Can you remove the gpo settings that remembers 3 passwords?

 

i.e get back to a default setting then we can build it up from there.

 

Ben

Posted

Hi Uraken,

 

Bit of a conundrum this one as when it was tested following the instructions that were included worked fine.

 

No registration of anything should be required.

 

Bear with us and we'll try our best to solve this.

 

Ben

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...