Uppercase Answers in Challenge Questions - 5002 Invalid

82 views
Skip to first unread message

Stephen Price

unread,
Sep 14, 2023, 11:13:12 AM9/14/23
to pwm-general
Driving me crazy here. I have installed 2 PWM 2.0.6 servers utilziing a SQL server to store the Challenge answers.

Whenever a users defines their challenge answers with a word that has a Capital letter in it, the platform saves it without issue. But when a user utilizies the answer to the challenge question it says that it is an Invalid response.

If the user defines the same question with the same answer, but uses only lowercase letters in the answer, then it works just fine.

What is going on with the Uppercase letters in challenge answers?

Jason Rivard

unread,
Sep 15, 2023, 9:34:44 PM9/15/23
to pwm-general
It's most likely the setting 'Max Question Characters' on your challenge policy.  Apparently there is casing bug in that check.  You can watch the logs or turn on detailed error messages to see the cause of the error.

Stephen Price

unread,
Feb 20, 2024, 10:58:47 AMFeb 20
to pwm-general
Logging does not seem to show anything more than that the password answer is invalid. Not sure how to tell if the 'Max Question Characters' configuration would be relevant or how to disable it to test.

Jason Rivard

unread,
Feb 20, 2024, 9:16:03 PMFeb 20
to pwm-general
Did you change the max question characters setting on the challenge policy?   Try setting it to 0.   Also, I think there is a bug in the case checking of this restriction, I'll be looking into it soon.

Stephen Price

unread,
Feb 21, 2024, 9:51:05 AMFeb 21
to pwm-general
1st of all. Thank you for all your help.

Yes. I tried it with zero.

To be clear:
It accepts the answer when defining the question and answers no problem. I would think the max question setting would be more related to this step.

It is during the actual checking of the answer when it states the password is incorrect. If I define an all lowercase answer then it will accept the all lowercase answer just fine when requested. 
But if there are any uppercase letters in the answer, then it will not validate at all.

One or more responses are not correct. Pleasee try Again {5002 ERROR_INCORRECT_RESPONSE (incorrect response to one or more challenges)}
Reply all
Reply to author
Forward
0 new messages