PWM v2.0.3 bc96802e - forgotten password - pwm asks everytime questions, but no questiona are configured

794 views
Skip to first unread message

stefan....@gmail.com

unread,
Aug 26, 2022, 5:57:18 AM8/26/22
to pwm-general
hi,
i have installed and configured PWM v2.0.3 bc96802e.

i have configured the public module "forgotten password".
but i haven't configured the security questions.

if a user clicks to "forgotten password" the user must answer to two questions. and the user has never answered to some questions (see attached files).

where i can disable this questions? i cannot find this settting(s).

thanks
best regards
stefan


pwm2.JPG
pwm3.JPG
pwm1.JPG
pwm4.JPG

stefan....@gmail.com

unread,
Aug 26, 2022, 7:45:56 AM8/26/22
to pwm-general
if i set "minimun random required" to "0" (see attached file pwm5.jpg) i have the error 5033 (see attached file pwm6.jpg)
pwm5.JPG
pwm6.JPG

Stefan Lanziner

unread,
Aug 26, 2022, 7:48:33 AM8/26/22
to pwm-g...@googlegroups.com
in the log i have this messages:

ERROR, http.PwmResponse, {BaeSB} 5033 ERROR_INVALID_CONFIG (user is required to complete LDAP attribute check, yet there are no LDAP attribute form items configured) [x.x.x.x]
FATAL, servlet.AbstractPwmServlet, {BaeSB} unexpected error: 5033 ERROR_INVALID_CONFIG (user is required to complete LDAP attribute check, yet there are no LDAP attribute form items configured) [x.x.x.x]
ERROR, http.PwmResponse, {BaeSB} 5033 ERROR_INVALID_CONFIG (user is required to complete LDAP attribute check, yet there are no LDAP attribute form items configured) [x.x.x.x]

--
You received this message because you are subscribed to a topic in the Google Groups "pwm-general" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/pwm-general/zNeRfpshUl8/unsubscribe.
To unsubscribe from this group and all its topics, send an email to pwm-general...@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/pwm-general/c35eac2b-3d90-446d-a6aa-114f508b4b1bn%40googlegroups.com.

Jason Rivard

unread,
Aug 26, 2022, 11:59:16 AM8/26/22
to pwm-general
Your confusing the 'Setup Responses' section which controls question enrollment with already authenticated users with the 'Forgotten Password' policy which controls what happens when the user clicks forgotten password.  You need to adjust the setting:  Modules ⇨ Public ⇨ Forgotten Password ⇨ Profiles ⇨ [profile] ⇨ Definition ⇨ Verification Methods which now is prompting for LDAP attribute verification but you don't have any LDAP attributes defined.

stefan....@gmail.com

unread,
Aug 29, 2022, 8:47:17 AM8/29/22
to pwm-general
ji jason,
can you tell me where i must configure the ldap-atributes?
i have an old installation of the version 1.8 ... the the configurations are similar ...
thanks
best regards

stefan....@gmail.com

unread,
Aug 30, 2022, 11:32:14 AM8/30/22
to pwm-general
hi,
i have configured "ldap attributes"" (see the attached screenshot).
thanks
best regards
verification-methods.JPG
answer.JPG

jason.e...@gmail.com

unread,
Aug 30, 2022, 12:28:40 PM8/30/22
to pwm-general
You need to disable the Security Questions in the Setup Security Questions section,

Capture.PNG

jason.e...@gmail.com

unread,
Aug 30, 2022, 12:31:18 PM8/30/22
to pwm-general
and also go to Policies->Challenge Policies-> default and set minimum number random required and minimum random challenges required to 0 

stefan....@gmail.com

unread,
Aug 31, 2022, 1:22:38 PM8/31/22
to pwm-general
hi,
with this configuration i have an error:

PWM 5033

The configuration is invalid or corrupt. Please correct the error, or remove the configuration file.


thanks
best regards
setting2.JPG
error1.JPG
setting1.JPG

stefan....@gmail.com

unread,
Sep 6, 2022, 4:09:37 AM9/6/22
to pwm-general
i made an export of the configuration from the old version 1.8.0 and an import of the configuration in the new instance 2.0.3
now the pwm works.

Reply all
Reply to author
Forward
0 new messages