Kentico 11 Password Reset Error

Jacob Mallach asked on May 5, 2021 00:24

Hello,

Our users are experiencing errors when attempting to use Forgotten Password for a password reset.

"Your sign-in attempt was not successful. Please try again."

The password is never accepted.

There have been no modifications to the codebase that I'm aware.

Manually regenerating a new pass does send the user an email, however still no success logging in with the new generated password. Manually reseting the password is also not working.

The event log shows:

Event Code: Authentication Fail or Validation Fail

Description: Message: Request identifier hasn't been found.

Any help would be much appreciated.

Thanks.

Recent Answers


Jake Kula answered on May 5, 2021 01:19

Hi Jacob,

Is this something that can be replicated with any user who choses to reset their password? Or is it only happening to a specific user/s?

It sounds like an issue that happens in both the reset password page (via the password reset email) and a manual password reset on a user from within the CMS. Is that correct?

Do you have access to the database? If so, when you reset the password is the encrypted value in the UserPassword field of the CMS_User table changing?

0 votesVote for this answer Mark as a Correct answer

Juraj Ondrus answered on May 5, 2021 08:41

Are there any firewalls or proxy servers or any other recent changes in the network, which might be blocking the requests? Any other security/filtering software?

0 votesVote for this answer Mark as a Correct answer

Jacob Mallach answered on May 5, 2021 15:55 (last edited on May 5, 2021 15:57)

@Jake - Update: I can manually reset the pass for our users. So the manual reset is working. The generate new pass is also working. Again, good news. So the issue is isolated to the Reset Password process. I will checkin with my team regarding the Database and keep you posted.

@Juraj - Good questions. The error persists both On and Off the network. Will check and reply back. Thanks!

0 votesVote for this answer Mark as a Correct answer

Juraj Ondrus answered on May 5, 2021 16:03

Certain types of web filtering software may interfere with password reset links. If an automatic tool accesses the password reset page before it is opened by the actual user's client, the password recovery request will be invalid. So, it is not about the network, it is more what is installed e.g. on the email server or email client. Maybe something is checking the link before the actual user gets to it...

0 votesVote for this answer Mark as a Correct answer

   Please, sign in to be able to submit a new answer.