Password recovery - can someone make sense of this?

I have had Password Recovery set up since 1999, but I’ve never used it. With the introduction of policies in ND6, I finally have my users set up so their passwords expire every 90 days. In preparation for the first round of expirations, which will happen in a week, I decided to give it a try. The Admin help tries to be thorough, but it ends up being a convoluted and confusing mess. I finally tried muddling through, and I got it to work, but I’m not sure if it’s supposed to be like this. Here’s what I did:

  1. Open the password recovery database, sorted by name and looked for my entries. The most recent one was from 2003. According to the help it’s supposed to update recovery information automatically in ND6. Anyway, I saved the ID file to hard drive and extracted the recovery password using the Admin client.

  2. I Closed all Notes clients, reopened Notes, clicked Cancel on the password prompt and selected Recover Password from the screen.

  3. The prompt that appeared said “Enter a password for one of the following administrators”. I am one of the administrators listed, so I tried entering my password. No go. Okay, so it means use the recovery password, so I tried that. It didn’t work, either.

  4. I logged in normally and did a screen print of the password recovery screen to make sure I hadn’t written it down wrong, then went back through the recovery process in the Note client. The password still didn’t work.

  5. I exported the recovery information to myself, accepted it, extracted the recovery password again, and went back through the process. Lo and behold, it worked!

  6. I was presented with the normal password prompt for “Location None”. I tried entering the recovery password here, but it didn’t work. I clicked Cancel, the same prompt reappeared. After clicking Cancel an estimated 10 times, I was finally given a dialog to change my password.

Based on my experience I have the following questions:

  1. Why was the most recent ID for me from 2003? Is it supposed to update automatically?

  2. Why did I have to export recovery information and accept it before I could get a valid recovery password? Should the recovery password from the older ID have worked?

  3. Since the point of this is the user forgot his password, why does it prompt the user for his password after he enters the recovery password? It would make more sense if it prompted the user to change his password rather than him having to click Cancel a bunch of times.

Any insight would be greatly appreciated.

Thanks,

Charles

Subject: password recovery - can someone make sense of this?

Hi Charles,

There are two things :

  • Password Recovery

  • ID Recovery

Even though they are in the same dialog box, they don’t work the same way :

  • ID Recovery saves every new or mofified ID in a DB

  • Password Recovery add some recovery informations in ID’s.

This last point is not so simple, the first modified ID (when you fill the dialog box) is the certifier, so if then a user is created, recovery process can recovery the password. But if the certifier is updated (to allow recovery, or to modify admins who can do that) after a user is created, you need to send this modification to this (or every)user, to be more precise, to the ID file of this user (it’s the export button in the dialog box).

If you do it, if then this new ID (with theses new recovery informations) is sent to the recovery db, you can use this ID to open notes, then click on cancel three times. You will be able to enter the (long) password(s) (1 to X passwords depending of the setting of the dialog box) you get from the admin client. Then a dialog box opens and asks you the new password

To be more complete, the user must accept the sent of his new ID information, he receives a mail like “your ID informations has changed clic to send your ID to …” of something like that, if he doesn’t clic the button (and a lot of users don’t clic the button because they don’t know what it is), the ID will never be sent to the recovery db and password will never can be recovery

I am sorry, it’s not very easy to explain, but I tried it !

Hope this helps

Christian

Subject: password recovery - can someone make sense of this?

several things;

the certificate needs to have recovery information in it first

you will need to recertify (or wait for them to expire) any users who currently don’t have the recovery information (from the certificate) in their id files.

older versions of the client used to prompt the user to send the recovery email, most users cancelled it (obviously). newer clients don’t prompt the user and send it automatically.

now;

if you’re just going for a lost password then you must have the matching recovery message to the current id file, as the recovery passwords are different for each ‘version’.

if they’ve lost their id then you could use any message so long as you send them the id file in it, or detach the id and do the recovery and new password assignment yourself and then send them the recovered id file (web mail/network drive/alternate email address).

the password prompt after the recovery password is entered is a prompt to enter a new password.