Educause Security Discussion mailing list archives

Re: self service password reset questions


From: "SCHALIP, MICHAEL" <mschalip () CNM EDU>
Date: Fri, 22 Oct 2010 08:49:59 -0600

We're currently using Banner's/Luminus password reset function - and it's been pretty horrible.  We're looking for 
something a lot simpler, more bullet-proof, integrates with AD, non-open source (I'd like to be able call one place for 
support, rather than relying on distribution lists....;-).....any success stories out there?

Thanks,

Michael

From: The EDUCAUSE Security Constituent Group Listserv [mailto:SECURITY () LISTSERV EDUCAUSE EDU] On Behalf Of Todd 
Britton
Sent: Friday, October 22, 2010 8:42 AM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: Re: [SECURITY] self service password reset questions

Brian,

                We have instituted a 6 question panel, requiring 3 at one time to be answered correctly in order to 
reset one's password. These questions are of the student's own design; however, we provide guidance and suggest they 
use passwords that are easy for them to remember, but hard to guess by someone else.

Todd Britton - MBA, PMP, CISM, ITILv3F, MCSE, CGEIT
Director of Enterprise Applications
Information Security Officer
OIT Project Manager
University of La Verne
909-593-3511 x4234
tbritton () laverne edu<mailto:tbritton () laverne edu>

From: The EDUCAUSE Security Constituent Group Listserv [mailto:SECURITY () LISTSERV EDUCAUSE EDU] On Behalf Of Kellogg, 
Brian D.
Sent: Friday, October 22, 2010 7:21 AM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: [SECURITY] self service password reset questions

Just wondering what questions other Universities are using that have deployed a self service password reset portal?  
How many questions do you require students to answer in order to reset their passwords?  And any other relevant insight 
and wisdom would be appreciated as well.


Thanks,
Brian

--
This message has been scanned for viruses and
dangerous content by MailScanner<http://www.mailscanner.info/>, and is
believed to be clean.

-- 
This message has been scanned for viruses and
dangerous content by MailScanner, and is
believed to be clean.


Current thread: