To force web only users to change their password every 3 months I am testing the new security policy feature. After creating a test group then creating a Security Setting and assigning it to a Policy and then in the Admin client assigning the Policy to a test group I have had the following result. User 1. Changed person document to force change of Internet Password on next log on. Pop up dialog worked just fine but when the user changed his password the new password wasn’t recognized but the old one was. I went back to the user’s person document and reselected the force change on next logon. This was done yesterday and the check box still has the check in it and the user is never requested to change his password.
User2. Performed the same action as above changed the person document to force user to change password on next logon which it did. For the last 2 days the user can now use both his old and his new password.
In the Adminp.nsf db there is a log the first time the users changed their password but there hasn’t been any reference to it since.
Both users have a reference to the security policy in their person document.
Whats happening?