Jump to content

Recommended Posts

Posted (edited)

Had several reports of issues logging in to iampearson since they enforced more complex passwords and mfa.

The user account credentials immediate error and repeated tries results in lockout.

Following the password reset portal is flawed as no matter what password I try it thinks the password is common and doesn’t proceed any further.

Pearson claim that this is firewall issue and have given me endpoints to whitelisted however all these attempts have been on my home network with no firewall in place.

They have escalated the issue but has been going on for a number of weeks without resolve.

Anyone have any experiences or words of wisdom?

Thanks

Edited by dapaulio
  • Thanks 1
Posted

Yes, been having the same issues for the past few days..and yes, their support tried to blame our firewall etc.

 

However, same issue when using non-school internet (e.g. mobile or home internet etc)

 

Feed this info back, still waiting for them to fix.

  • Thanks 2
Posted
Yes we've had this too with the 2FA and their authentication app. Hasn't worked for two members of staff, code doesn't show up in the app but their account on the pearson portal thinks 2FA is enabled and working and so asks for a verification code. Only way to fix it was for the teachers to raise a ticket with pearson support where they then phoned them both to confirm their identities. Worked the second time round for both of them after they reset it. Pearson's instructions for setting it up are pants, they show a QR code during setup but you're meant to skip the first one they show? Well why show it in the first place?
  • Thanks 2
Posted

I've been getting this too and have been digging into it as deeply as I can.

 

When a user reset password, they start typing and the second they get past 8 characters, they instantly get a message saying that it's a common password or discovered in a databreach (I know it's not - Keepass password generated....).

 

Developer tools point to a call to an API - here: https://springboot-prod.priv.pearsonprd.tech:8443/v1/identity/password/checkDictionary

 

Which fails with ERR_TUNNEL_CONNECTION_FAILED in Chrome, other browsers show their equivalent messages.

 

I've tried everything I can do to allow that URL. No dice.

 

I've got a ticket open with pearson who just sent me this link: https://support.pearson.com/uk/s/article/Edexcel-Online-Forgotten-Passwords

 

I've added all their required exceptions, including SSL do not inspect rules, destination proxy exceptions too. No dice.

 

I've got a ticket open with Smoothwall who sent me a really unhelpful response (That doesn't match their unblocking guidance nor tallys up with Pearsons article)

 

Additionally please add the below IP addresses into the destination exception and see if this helping you or not.

 

64.106.193.0/24

64.106.220.0/24

206.188.17.0/24

159.182.0.0/16

13.107.246.0/24

13.107.253.0/24

147.243.0.0/16

159.182.72.158

 

Please add the below URL's to the category which you have created for person.

 

https://support.pearson.com/uk/s/article/Edexcel-Online-Forgotten-Passwords

support.pearson.com

cdn.cookielaw.org

pearsoncommunity.force.com

Google

http://www.pearsonmylabandmastering.com

https://userportal.pqs.pearsonprd.tech

userportal.pqs.pearsonprd.tech

https://springboot-prod.priv.pearsonprd.tech:8443/v1/identity/password/checkDictionary

https://btecng.pearson.com

https://iam.pearson.com

 

Needless to say - I've told them that's made no difference and I'm still waiting from both Pearson and Smoothwall. This is going to turn into them blaming each other and our exams team getting angry.

  • Thanks 1
Posted
I've been getting this too and have been digging into it as deeply as I can.

 

When a user reset password, they start typing and the second they get past 8 characters, they instantly get a message saying that it's a common password or discovered in a databreach (I know it's not - Keepass password generated....).

 

Developer tools point to a call to an API - here: https://springboot-prod.priv.pearsonprd.tech:8443/v1/identity/password/checkDictionary

 

Which fails with ERR_TUNNEL_CONNECTION_FAILED in Chrome, other browsers show their equivalent messages.

 

I've tried everything I can do to allow that URL. No dice.

 

I've got a ticket open with pearson who just sent me this link: https://support.pearson.com/uk/s/article/Edexcel-Online-Forgotten-Passwords

 

I've added all their required exceptions, including SSL do not inspect rules, destination proxy exceptions too. No dice.

 

I've got a ticket open with Smoothwall who sent me a really unhelpful response (That doesn't match their unblocking guidance nor tallys up with Pearsons article)

 

 

 

Needless to say - I've told them that's made no difference and I'm still waiting from both Pearson and Smoothwall. This is going to turn into them blaming each other and our exams team getting angry.

 

We have the problem, but no Smoothwall.

  • Thanks 1
Posted (edited)

Same issue at both my schools.

 

At the change password prompt, were getting the "This password is a common one" when entering something random such as "lpOUIYTRFCVNdddghh__@@999222"!

 

Curiously, last week when this was first reported I was able to do the mandatory password change using laptop connected to phone hotspot - thereafter it behaved properly.

 

This morning at my other school I have tried the same trick but it fails. I am able to change the password and I get "Profile Updated" but am then shown the "Change Password" option again and get no further.

 

We use LA ISP with Smoothwall and the only response from Pearson was the link above. Hadn't even recognised it as a problem and were quite adamant it was school Internet problem and nothing to do with them.

 

On another note, who in their right mind thinks it a good idea to implement such major breaking changes just prior to exams?!

 

John

Edited by johnfermor
  • Thanks 1
Posted
Same issue at both my schools.

 

At the change password prompt, were getting the "This password is a common one" when entering something random such as "lpOUIYTRFCVNdddghh__@@999222"!

 

Curiously, last week when this was first reported I was able to do the mandatory password change using laptop connected to phone hotspot - thereafter it behaved properly.

 

This morning at my other school I have tried the same trick but it fails. I am able to change the password and I get "Profile Updated" but am then shown the "Change Password" option again and get no further.

 

We use LA ISP with Smoothwall and the only response from Pearson was the link above. Hadn't even recognised it as a problem and were quite adamant it was school Internet problem and nothing to do with them.

 

On another note, who in their right mind thinks it a good idea to implement such major breaking changes just prior to exams?!

 

John

Same issue, but we are Sophos XGS.

Posted

We found ours worked after changing firewall, some odd ports used

 

Think some staff may have changed at home prior to work around it, so it was definitely filter related

  • Thanks 1
Posted
Yep on Smoothwall we went into Web Proxy / Settings / Advanced and added port 8443 to the list of additional ports, which fixed the issue. Very odd that they would choose to use a non-standard port like this. Makes me wonder if it is a dev system that went live and someone forgot to change the port number.
  • Thanks 4
Posted
Hello, we are having the same issues too. Do you happen to know what "odd ports" needed to be opened? In the guidance at pearson it only tells you to unblock 443 and 8443?
Posted
Yep on Smoothwall we went into Web Proxy / Settings / Advanced and added port 8443 to the list of additional ports, which fixed the issue.

 

Made no difference to be last week when I did it, since seeing this thread I've seen that other firewalls are getting this issue.

Posted
Made no difference to be last week when I did it, since seeing this thread I've seen that other firewalls are getting this issue.

 

Is that because we've conflated 2 problems in this thread?

 

1. Not being able to change a password.

2. With 2FA and the authentication app.

Posted
Personally I feel this is a user specific issue and each issue needs to be addressed on an individual basis but the problems Pearson have had has exasperated the problem and with an admin console that does nothing to help user management I cant see what else to do other than point the user to contact Pearson.
Posted
We just been asked to submit a HAR file

 

We have too...

The message you are receiving indicates that either your password has matched a commonly used one found on the internet, or the verification step coded into the password reset process is being blocked or restricted by your network/firewall(s).

 

We recently introduced password-strengthening measures, to ensure that passwords being used are not matched to flagged "bad passwords" (these are common passwords or passwords that have already been flagged as being used in a data breach).

 

Please ensure you are not trying commonly used passwords, such as Password1 or Letmein1. Further guidance can be found here (https://support.pearson.com/uk/s/article/Edexcel-Online-Forgotten-Passwords)

 

Should you continue to receive the ‘common password’ message and are confident the password you are trying is adequate, please liaise with your internal IT team to confirm the following websites have been allowed within your centre network/firewalls (you may also need to check this with your internet service provider):

 

https://edexcelonline.pearson.com/

https://www.edexcelgateway.com/Account/Login.aspx

https://www.examwizard.co.uk/

https://www.resultsplusdirect.co.uk/ResultsPlus/Default.aspx

https://www.resultsplusdirect.co.uk/students/login.html

https://support.pearson.com/uk/s/

https://qualifications.pearson.com/content/dam/secure/

https://pqg.pearson.com/

https://userportal.pqs.pearsonprd.tech/

https://iam.pearson.com

https://springboot-prod.priv.pearsonprd.tech

https://springboot-dev.priv.pearsondev.tech

 

*Your IT department must also ensure that traffic on ports 443 and 8443 are allowed for above URLs.

 

We would also advise checking you do not have any additional software installed on your computer/laptop that may be affecting your network/firewalls. For example; we have received a few responses from customers, reporting that their safeguarding software was affecting this process. Again, your internal IT Support team may be required to check this.

During the password reset process, when checking whether the password is common, the site makes a POST request to

https://springboot-prod.priv.pearsonprd.tech:8443/v1/identity/password/checkDictionary

with form-data {password: "whichever password has been typed"}. It then expects either a response of {"ok":true} if the password hasn't been found on a list of common passwords e.g. {password: "kxKtTGtitr2nF2pcrR76"}, or {ok:false} if it has matched a common password e.g. {password: "Password1"}. However, if it is unable to make the request or does not receive a response back, the site will treat that as getting an {ok:false} response, which is why you may get the 'common password' error even for a very obscure password. You may want to check that this request can be made successfully within the centre network.

Please see an attached example .har file, which you can open in Chrome Developer Tools by pressing Ctrl + Shift + I to open the Network section, and drag the file in to view. The checkPassword.js request shows a remote address and a 200 response code for the successful attempt, but this will be missing if it is unable to connect to the site (please note, the remote IP address is not static, and likely to change).

 

Once they have confirmed the above has been setup, please clear your cookies & cache and then try logging back into Edexcel Online (please note - until the above has been done, you will find that all passwords you attempt will be flagged as a common password, as the process requires both the URLs and ports configuring, for the check request to be successful).

 

In the unlikely event you still cannot log into Edexcel Online, and your IT team have confirmed all the above has been setup, then we will need to investigate further. To help us with the investigation, we require a .HAR file send to us. Guidance on how to generate this for some commonly used browsers can be found in the attached document.

  • Thanks 1
Posted

Iv told them it still happens when doing it on my home network without a firewall in place and still have the issues.

 

I have used grc to generate me a password which I am told is a common password.

 

I like to see them argue that with GRC.

 

When I fed that back in to the ticket it was an escalation to the developers. I haven’t heard anything back since I originally posted this.

 

Some development though whilst I waited users need to ask to reset the mfa registration and re invite. This fixed 2 out of the four people who were my Guinea pigs. May be worth you lot trying that see if you get the same positive results

Posted
Just a note regarding a post in here - on the Smoothwall, in the advanced proxy settings, adding port 8443 to the 'Also allow these ports' is only needed when proxy settings are used on the clients. With transparent proxy, make sure that port 8443 is allowed outgoing in the firewall.
  • Thanks 1
  • 3 weeks later...
Posted

Thanks for this, our staff are having a nightmare with this currently.

 

I've added it to our smoothwall allow for all, hopefully that does it, if not i'll have to contact the ISP.

  • 4 months later...
Posted (edited)

Yeah so we found this issue was a multiple fold issue

 

1- Pearson documentation on whitelisting endpoints were incomplete

2- it uses a special port (want to say 8443 but can’t 100% be sure) on the internet that cross references a password against its database. If it cant communicate on that port it will fail password validation check when forced to change.

3 - the mfa when setup was the course of the infinite loop our users found themselves in. That and poor handover documentation to the user left everyone frustrated that led to the issue

4- their support are difficult and under prepared for the massive balls up they had set in motion.

5- they need to be able to hand over the ability to revoke the mfa or temp bypass to an onsite admin. At the moment the admin can do anything to help the situation

 

To summarise

Make sure your proxy has the ability to allow all end points and ports now believed to be accurate before rolling out the changes to the school.

 

Maybe document something a lot simpler for the staff to follow. Do it on one or two people first before going out to gen pop

Edited by dapaulio
Posted

Headteacher was having the same problem at home. Made the changes on 14/10/24. Tried yesterday, still not working. Pearson got back to me today and it's working fine.

 

I've directed their support to this thread, it needs a permanent fix.

 

- - - Updated - - -

 

Yeah so we found this issue was a multiple fold issue

 

1- Pearson documentation on whitelisting endpoints were incomplete

2- it uses a special port (want to say 8443 but can’t 100% be sure) on the internet that cross references a password against its database. If it cant communicate on that port it will fail password validation check when forced to change.

3 - the mfa when setup was the course of the infinite loop our users found themselves in. That and poor handover documentation to the user left everyone frustrated that led to the issue

4- their support are difficult and under prepared for the massive balls up they had set in motion.

5- they need to be able to hand over the ability to revoke the mfa or temp bypass to an onsite admin. At the moment the admin can do anything to help the situation

 

To summarise

Make sure your proxy has the ability to allow all end points and ports now believed to be accurate before rolling out the changes to the school.

 

Maybe document something a lot simpler for the staff to follow. Do it on one or two people first before going out to gen pop

 

It's not 2FA, we had the same problem attempting to *create* an account.

Posted
Headteacher was having the same problem at home. Made the changes on 14/10/24. Tried yesterday, still not working. Pearson got back to me today and it's working fine.

 

I've directed their support to this thread, it needs a permanent fix.

 

- - - Updated - - -

 

 

 

It's not 2FA, we had the same problem attempting to *create* an account.

 

Yeah the original issue wasn’t mfa but when they enforce mfa it exasperated the issue even further as it ended up in an infinite loop which left their support scratching their heads for ages (with us)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...