whidbey membership providers

I'm part of the core team of Dotnetnuke, a popular opensource windows .net portal/cms solution. In the next release (3.0), we're integrating an asp.net 1.1 backport of the new whidbey membership providers. Hopefully, this will strengthen our user/role management, as well as allowing us to more easily integrate with others that implement this e.g. communityserver, and minimise the conversion effort once we move to asp.net 2.0.

However, one issue we've found, that isn't documented very well (at least not in the information we have to hand), is that two of the membership provider settings are mandatory. Most of them, such as enablePasswordRetrieval can be set to true or false, but both passwordAttemptThreshold and passwordAttemptWindow require postive, non-zero values. If you don't include these, they default to 5 and 10 respectively. Whilst I applaud Microsoft's efforts at encouraging users to code more secure applications, I would have preferred the option of disabling these i.e. setting them to 0. As it is it looks likely we'll simply have to set reasonable values for the items, and educate our users. Obviously, theres nothing to stop you writing your own alternative version of a membership provider, but it seems a lot of effort for a small return.

The two to watch out for are:

passwordAttemptThreshold="int"             The number of failed password attempts, or failed password answer attempts that are allowed before locking out a user's account

passwordAttemptWindow="int"                The time window, in minutes, during which failed password attempts and failed password answer attempts are tracked

Print | posted on Tuesday, November 16, 2004 1:20 AM

Feedback

# One thing to watch with Microsoft's Membership Management Component (MMC) Prototype

Left by Tim Haines' Blog at 1/20/2005 10:11 AM
Gravatar

# Two things to watch with Microsoft's Membership Management Component (MMC) Prototype

Left by Tim Haines' Blog at 1/20/2005 10:11 AM
Gravatar

#  duffel bag

Left by duffel bag at 3/25/2008 3:14 AM
Gravatar http://island.geocities.jp/handbags_choice/duffel-bag duffel bag

#  marc jacobs handbag

Left by marc jacobs handbag at 3/25/2008 3:14 AM
Gravatar http://www.geocities.jp/handbagssolid/marc-jacobs-handbag marc jacobs handbag

#  jet blue airlines

Left by jet blue airlines at 3/25/2008 3:14 AM
Gravatar http://topair.host93.com/jet-blue-airlines jet blue airlines

#  delta airlines

Left by delta airlines at 3/25/2008 3:14 AM
Gravatar http://bestairtickets.freehostpage.com/delta-airlines delta airlines

Your comment:





 
Please add 4 and 8 and type the answer here:

Copyright © Cathal Connolly

Design by Bartosz Brzezinski

Design by Phil Haack Based On A Design By Bartosz Brzezinski