

Advanced Authentication Service › Getting Started with Advanced Authentication › Advanced Authentication Flows › Advanced Authentication Flows › ArcotID PKI-Based Flows › Forgot Password Flow
Forgot Password Flow
End users who forget their LDAP password can choose to reset their password by answering secret questions, which they set during enrollment. After changing the password, a new ArcotID is placed on the end user’s device.
Prerequisites:
This flow is based on the following configurations:
- The hosting administrator has enabled ArcotID PKI credential in the User Console and has configured the ArcotID PKI Only flow.
- The hosting administrator has configured the Credential Handling Service to protect the resource realm with the CA SiteMinder authentication scheme corresponding to the ArcotID PKI Only flow.
- The device used for transactions has ArcotID PKI native or mobile client installed or is capable of supporting Java Applet or JavaScript Client.
- An ArcotID PKI has been issued to the end user. The ArcotID PKI may or may not be present on the end user’s device.
The Flow:
- In a browser window, the end user attempts to access a protected resource.
- On the login page, the end user specifies their user name and clicks the Forgot Password link.
- The end user is prompted for secondary authentication, and the following steps take place:
- The Advanced Authentication application invokes IdentityMinder to retrieve the security questions.
The page with challenge questions is presented to the end user. On the same page, the end user can specify whether the ArcotID PKI must be stored for future sessions.
- The end user answers the security questions.
- The Advanced Authentication application invokes IdentityMinder again to verify the answers.
- The browser displays the login page with the user name and challenges the end user for the new password.
The end user provides a new password.
Note: The behavior of this flow is also applicable in case a credential expires. The only difference is that the end user does not click on the "Forgot Password" link.
Copyright © 2013 CA.
All rights reserved.
 
|
|