Restricting Security Questions in QnA Credential Creation
search cancel

Restricting Security Questions in QnA Credential Creation

book

Article ID: 450544

calendar_today

Updated On:

Products

CA Advanced Authentication - Strong Authentication (AuthMinder / WebFort) CA Advanced Authentication CA Strong Authentication

Issue/Introduction

During the creation of QnA (Questions and Answers) credentials, the system currently allows users to submit custom security questions directly within the API request, bypassing the predefined question set configured in the environment.

To enforce strict security policies, organizations may need to disable custom question submission and restrict users to selecting only predefined security questions fetched from the existing QnA configuration.

Environment

Symantec Strong Authentication 9.1.5.1
RHEL 9.4

Resolution

To enforce the restriction and limit security questions strictly to the predefined configuration, apply the required software update:

  1. Download the patch Symantec-StrongAuth-DE669847-DevPatch from this knowledge base article.

  2. Apply the patch to your environment following standard hotfix deployment procedures.

Once applied, custom questions submitted in SOAP requests or console profiles during QnA credential creation will be rejected, ensuring only predefined, configured questions are permitted.

Please reach out to Support if there are any questions or concerns.

Attachments

Symantec-StrongAuth-DE669847-DevPatch.zip get_app
Symantec-StrongAuth-DE669847-DevPatch_Instructions.txt get_app