Passing forgotten password user validation screen
search cancel

Passing forgotten password user validation screen

book

Article ID: 369667

calendar_today

Updated On:

Products

CA Identity Suite

Issue/Introduction

Is it possible to configure the forgotten password flow such that regardless of what user they enter, they will be prompted to answer Q/A? Under the current workflow,  If the userid exists, they are led to answer Q/A.  If the userid doesn't exist, they return a "The User information entered does not match an existing user." Error message.

Environment

Identity Manager 14.4/14.5

Cause

To prevent hackers from being able to figure out what users exist in the system

Resolution

The forgotten password verification screen is required  It is not possible to configure the forgotten password flow to ignore the user id and move to Q/A . 

The alternative to remedy the situation is to change the message "The User information entered does not match an existing user." Error message." to something generic so that hackers won't be able to tell if the user exists.  Please refer to the following KB

https://knowledge.broadcom.com/external/article?articleNumber=282347