Still can authenticate with previous password on PWM Login page.
25 views
Skip to first unread message
Linu
unread,
Jun 12, 2024, 3:56:09 AMJun 12
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to pwm-general
Example, previous password is '1234' but current password is '5678'. When i try to authenticate with '1234' on LDAP, not authenticated. only '5678' is working cause current password is '5678'. But, when i try to authenticate with '1234' on PWM login page. it was still working and '5678' also work. I can't understand this situation and tried to find option. can't find any option like 'Previous Password Allowed' or 'Can authenticate with old password'. I want get some help for this problem. Thank you.
Jason Rivard
unread,
Jun 13, 2024, 8:04:21 AMJun 13
Reply to author
Sign in to reply to author
Forward
Sign in to forward
Delete
You do not have permission to delete messages in this group
Copy link
Report message
Show original message
Either email addresses are anonymous for this group or you need the view member email addresses permission to view the original message
to pwm-general
PWM doesn't store passwords, so it's the LDAP server your using that accepts or rejects an authentication password. You didn't mention which LDAP server your using, but I'm guessing it's AD because it's an AD behavior to let old passwords work for up to an hour after changing.