Password changes: Forms Authentication & AD membership provider

Discussion in 'ASP .Net Security' started by am, Aug 22, 2007.

  1. am

    am Guest

    I'm looking for some guidance on expected behaviour concerning password
    changes.


    The application is a virtual desktop connection broker and is comprised of:

    1. Forms authenticated web site, using the Active Directory membership
    provider. Hosts MSRDP ActiveX.

    2. Remoting service that brokers virtual desktop connections.

    3. Virtual Server farms hosting virtual desktops.


    The application works as follows:

    1. User logs in to the web form.

    2. Web application communicates with broker service to retrieve the
    appropriate virtual desktop name.

    3. User is forwarded to a web page hosting the MSRDP ActiveX and is
    connected to the virtual desktop.

    4. Use logs in using the same account that was used to authenticate to the
    web site.

    5. When the virtual desktop session is terminated, the user is forwarded
    back to the default page of the web site.


    My question is related to the following scenario:

    1. User completes steps 1. – 4. described above.

    2. User changes password within the virtual desktop.

    3. User logs out of virtual desktop and is forwarded to the default page.


    What would be the expected result?

    If the site was using integrated authentication I would expect this to
    result in an account lockout as the credentials provided to Internet Explorer
    when originally prompted would now be out of date. Is this assumption correct?

    Thanks,

    Alex
     
    am, Aug 22, 2007
    #1
    1. Advertising

Want to reply to this thread or ask your own question?

It takes just 2 minutes to sign up (and it's free!). Just click the sign up button to choose a username and then you can ask your own questions on the forum.
Similar Threads
  1. Replies:
    0
    Views:
    1,008
  2. sloan
    Replies:
    5
    Views:
    1,529
    sloan
    Jun 4, 2006
  3. sloan
    Replies:
    1
    Views:
    551
    Chad Scharf
    Jul 3, 2007
  4. vcuankitdotnet
    Replies:
    3
    Views:
    2,287
    vcuankitdotnet
    Mar 19, 2008
  5. hfdev

    Forms Authentication without Membership provider?

    hfdev, Aug 9, 2007, in forum: ASP .Net Web Controls
    Replies:
    2
    Views:
    1,017
    hfdev
    Aug 10, 2007
Loading...

Share This Page