Small width layout Medium width layout Maximum width layout Small text Medium text Large text
     Search
Downloads Downloads Directory Directory Forums Forums Forge Forge Blogs Blogs        Marketplace Marketplace Careers Program Careers
Community › Forums Register  |  

telerik -- supercharge your DNN websites
  Ads  
OnyakTech
 


  Sponsors  

Meet Our Sponsors

The Official Microsoft ASP.NET Website
Portal Webhosting - Hosting For Developers
Red-Gate Software
MaximumASP
SourceGear - Tools for Developers
.: CounterSoft :.
 


DotNetNuke Forums
 
  Forum  General DotNetN...  Chat About It!  Security Behind Password Reset
Previous Previous
 
Next Next
New Post 5/6/2008 10:41 AM
Unresolved
User is offline Michael Sumerano
59 posts
10th Ranked


Security Behind Password Reset 

The current DNN password reset functionality basically emails your password in clear-text.  Has anyone raised any security red flags about doing this these days?  Are there options I am missing to turn on to prevent that from happening and allow the user who forgot their password to somehow perform some secure self-service to do so?

 
New Post 5/26/2008 8:17 AM
User is offline Mark Langille
268 posts
9th Ranked


Re: Security Behind Password Reset 
Modified By Mark Langille  on 5/26/2008 10:17:58 AM)

DELETED

 
New Post 5/26/2008 10:06 AM
User is offline Brandon Haynes
705 posts
brandonhaynes.org
7th Ranked


Re: Security Behind Password Reset 

Hi Michael,

The ASP.NET membership providers support a variety of configurations, most (All?) of which are supported by DNN.  If you are concerned about the plaintext transmission of passwords, you might consider disabling password retreival (enablePasswordReset), enabling password reset (enablePasswordReset), requiring a question and answer combination prior to allowing a user to reset (requireQuestionAndAnswer), and/or hashing passwords (versus encryption, using passwordformat).

All of these configuration settings are implemented under the ASP.NET membership element in your web.config.  The default DNN configuration, while perhaps at non-zero risk for an intercepted password via e-mail transmission, is also probably the easiest to administer.  When I recently implemented Commerce Server's UpmMembershipProvider within DNN, the provider's strict requirements (hashing, no retrieval, email addresses as username, etc) caused a lot of headaches.  I wish I could have just enabled user retrieval of passwords via email!

Brandon


Brandon Haynes
BrandonHaynes.org
 
New Post 5/27/2008 11:16 AM
User is offline Mitch Sellers
5719 posts
www.mitchelsellers.com
3rd Ranked




Re: Security Behind Password Reset 

Please note that if you enable Question & Answer within a DNN installation you will have issues creating new portals and users via the admin interfaces.


-Mitchel Sellers
MCITP, MCPD, MCTS
CEO/Director of Development - IowaComputerGurus Inc.
LinkedIn Profile

Visit mitchelsellers.com for my mostly DNN Blog and support forum.

Visit IowaComputerGurus.com for free DNN Modules, DNN Consulting Quotes, and DNN Technical Support Services

I reccomend 3Essentials for shared hosting and BaseCamp for project management
 
New Post 5/27/2008 11:23 AM
User is offline Charles Nurse
2915 posts
5th Ranked










Re: Security Behind Password Reset 

 Mitch Sellers wrote

Please note that if you enable Question & Answer within a DNN installation you will have issues creating new portals and users via the admin interfaces.

Most of which are/will be fixed in 5.0


Charles Nurse
DotNetNuke Trustee,
Senior Architect, DotNetNuke Coporation
MVP (ASP.NET) and
ASPInsiders Member
View my profile on LinkedIn
See my Blog for Articles on .NET, DNN and Module Development

View my Blog
 
Previous Previous
 
Next Next
  Forum  General DotNetN...  Chat About It!  Security Behind Password Reset
 


Forum Policy

These Discussion Forums are dedicated to the discussion of the DotNetNuke Web Application Framework.

For the benefit of the community and to protect the integrity of the project, please observe the following posting guidelines:

1. No Advertising. This includes promotion of commercial and non-commercial products or services which are not directly related to DotNetNuke.
2. Discussion or promotion of DotNetNuke product releases under a different brand name are strictly prohibited.
3. No Flaming or Trolling.
4. No Profanity, Racism, or Prejudice.
5. Site Moderators have the final word on approving/removing a thread or post or comment.
6. English language posting only, please.

 


telerik
telerik r.a.d.controls suite is the most innovative and comprehensive toolset for ASP.NET development, tailored for seamless integration with the DotNetNuke project. This integrated collection of controls allows professionals to build web-solutions with the UI richness and responsiveness of desktop applications.
dnn.telerik.com
CrystalTech
CrystalTech Web Hosting™ provides first-class service and support. Our value-packed ASP.NET plans offer DNN installation, SQL 2005 and up to 100 domain names starting at only $16.95 per month!
CrystalTech.com
DotNetNuke® in Sweden
All service of DotNetNuke® in Sweden.
Olsmar Konsult

DotNetNuke Corporation   Terms Of Use  Privacy Statement
DotNetNuke®, DNN®, and the DotNetNuke logo are trademarks of DotNetNuke Corporation
Hosted by MaximumASP