Version Affected: 9.0 and later
Overview
When a Password Reset realm's Data tab uses a Web Service connection instead of a direct Active Directory (AD) connection, enabling the Enforce History option on that realm does not actually enforce password history.
Cause
When a realm's Data tab uses a Web Service connection, that realm's Password Reset settings — including Enforce History — are not read from the current realm. Instead, they are read from the Web Service realm the connection points to. Configuring Enforce History on the current realm has no effect, because the current realm does not use its own Password Reset settings in this configuration.
To resolve this:
- Open the SecureAuth Admin Console.
- Navigate to the Password Reset realm.
- Open the Post Auth tab.
- Click Configure Password Reset Page.
- Click through to the Web Service realm. This opens the Password Reset settings for the Web Service realm itself, rather than the realm you started from.
- Configure Enforce History (and any other required Password Reset settings) here, then click Save.
SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.
Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.
Comments
Please sign in to leave a comment.