AD Old Password Still Accepted

book

Article ID: 4887

calendar_today

Updated On:

Products

CA Single Sign On Secure Proxy Server (SiteMinder) AXIOMATICS POLICY SERVER CA Single Sign On SOA Security Manager (SiteMinder) CA Single Sign-On

Issue/Introduction

We have recently implemented a change password mechanism using smpwservices.fcc for a new application. It is working as expected and if I logoff and logon with new credentials everything seem to work fine.

The problem is that (for a certain period of time) I'm able to login with old credentials too. Why is this possible? Is it a caching issue? How can I force Siteminder to accept only the new credentials?

Cause

This is expected as AD will keep old password valid for some time:


https://support.microsoft.com/en-us/kb/906305

Environment

Release:
Component: SMPLC

Resolution

Product is working as designed.

Delay is in 'new password' propagation in AD infrastructure