Forum Discussion

Bengt_Andersson's avatar
Bengt_Andersson
Icon for Nimbostratus rankNimbostratus
Apr 23, 2019

Changing password in APM Logonpage

APM Policy - We enabled the change password mechanism for Active Directory in our policy We used post variable name and session variable name to "change_password" according to instructions. But will the newly changed password be present in a new session parameter called session.logon.last.change_password or how does it work? Our policy just have a standard SSO mapping after the AD Auth and it seems like the changed pw is not sent in the first request to the webserver after a pw change, it sends the original pw entered in the logon page.

 

//Bengt A

 

1 Reply

  • i assume you followed this KB: https://support.f5.com/csp/article/K15676

     

    did you indeed get the possibility to change the password?

     

    i played around with it a bit and saw that variable change_password to be only used for the enabling of the feature, not to store the password.

     

    i saw no other variables getting filled with the new password. so i would assume the password is indeed the old one, which makes sense because that is what you enter in the logon password field to start with.

     

    you might want to do something with checking if that checkbox is enabled you redirect back to start after the change. and ask to login with the new password. you could also consider just informing your users to do that if they change the password. or create a portal just for the changing.