NetIQ Self Service Password Reset 3.3 Hotfix 1 Release Notes

September 2015

NetIQ Self Service Password Reset (SSPR) is a Web-based password management solution. It eliminates the users’ dependency on administrators to change their passwords. It reduces the workload of the helpdesk and in turn reduces the cost incurred by the company. Users can change their password and reset forgotten password based on the configured challenge-responses or the one time passwords. SSPR also allows administrators to ensure that all passwords in the organization comply with the established policies. For detailed information about NetIQ Self Service Password Reset, visit the NetIQ Self Service Password Reset Documentation Web site.

This hotfix resolves specific previous issues. Many of these improvements were made in direct response to suggestions from our customers. We thank you for your time and valuable inputs. We hope you continue to help us ensure our products meet all your needs.

This document outlines why you should install this hotfix. For the list of new features, enhancements, and software fixes in the previous release, see NetIQ Self Service Password Reset 3.3 Release Notes.

1.0 What’s New?

The following outlines the issues resolved in this release:

1.1 The Reference Document Displays the Details Partially

Issue: The reference document at /sspr/public/reference/referencedoc.jsp displays the details partially. (Bug 943080)

Fix: With this hotfix the reference document displays all the details.

1.2 SSPR Uses Proxy User Permissions Instead of LDAP User Permission

Issue: When using SSPR with eDirectory, SSPR uses the proxy user permission instead of using the permission of the authenticated LDAP user. (Bug 943181)

Fix: With this hotfix, SSPR will use the authenticated LDAP user permission instead of proxy user permission.

1.3 During the SSPR Configuration, SSPR Checks the Proxy User Connection Before Importing the Certificate

Issue: In the configuration guide, the administrators can import the certificate only after specifying the LDAP proxy user. (Bug 941649)

Fix: With this hotfix, the configuration guide includes a new page and the administrators can import the certificate first and then specify the LDAP proxy user details.

1.4 The Password Rule Text Specified in a Password Policy Profile is Not Displayed on the Change Password Page

Issue: In the change password page, SSPR does not display the password rules that you have specified in the Password Rule Text setting. This happens when you have selected merge as the password policy source at Password Settings > Password Policy Source > merge. (Bug 937298)

Fix: With this hotfix, even if you select password policy source as merge, the password rule text gets displayed on the change password page.

1.5 The LDAP User Photo Does Not Align Properly in the Organization Chart

Issue: The LDAP user photos are not aligned properly in the organization chart because of difference in the dimensions of the photo. (Bug 942045)

Fix: With this hotfix, even when the photos are in variable dimension, the photos are displayed appropriately.

1.6 The Changed Password is Not Sent Through SMS Even When SSPR is Configured to Send Password Through SMS

Issue: When a helpdesk user resets the LDAP user password, the password is not sent through SMS. This happens even when the setting, Forgotten Password > profile name > New Password Send Method is set to use SMS. Where, profile name is the name of the required profile. (Bug 942138)

Fix: With this hotfix, the password that a helpdesk user resets, is sent to the user through SMS.

1.7 Event is Not Generated When User Sets Up One-Time Password

Issue: SSPR does not create an event when a user authenticates the mobile number by setting a one-time password. (Bug 939329)

Fix: With this hotfix, the SET_OTP_SECRET event is generated when the user sets up the one-time password.

1.8 SSPR Does Not Properly Encode the Subject of SMTP E-Mail

Issue: SSPR does not encode the subject of an SMTP e-mail in a correct format because the default encoder used in SSPR does not match with the e-mail client encoder. (Bug 936999)

Fix: With this hotfix, SSPR uses the UTF-8 encoding by default and it matches with the e-mail client encoder.

1.9 During the Change Password Process An Event Log of the User is Added in the Event Log of the Helpdesk Operator

Issue: When a helpdesk operator changes a user’s password, the EventLog_helpdeskSetPassword event is generated and it gets added to the pwmEventlog attribute of the helpdesk operator instead of the pwmEventlog attribute of the user. (Bug 942653)

Fix: With this hotfix, the EventLog_helpdeskSetPassword event is added to the pwmEventlog attribute of the user.

1.10 SSPR Does Not Provide an Option to Access a Separate URL for Each New User Registration Profile

Issue: For any new user registration process, the user has to select a new user registration profile from the list of available profiles from /sspr/public/NewUser. There is no separate URL for each profile. (Bug 942275)

Fix: With this hotfix, users can access a direct URL for the required profile. Now users can start the new user registration from the URL, /sspr/public/NewUser/profile/<profile name>. Where, the profile name should be the name of the profile that was used during the profile creation. You should not specify the display name of the profile that is set in the LDAP Profile Display Name setting.

2.0 System Requirements

For detailed information about hardware and software requirements, see Installation Requirements in the NetIQ® Self Service Password Reset 3.3 Administration Guide.

3.0 Installing and Upgrading SSPR

SSPR hotfix can be installed either as an update or as a fresh install. The install files are available for download in the following two formats:

  • sspr_3.3.0.1.msi: An executable file that contains SSPR Web archive and tools.

  • sspr_3.3.0.1.zip: A compressed zip file that contains SSPR Web archive and tools.

For more information about how to install SSPR, see Installing SSPR in the NetIQ® Self Service Password Reset 3.3 Administration Guide.

For information about how to upgrade SSPR, see Upgrading SSPR in the NetIQ® Self Service Password Reset 3.3 Administration Guide.

4.0 Known Issues

NetIQ Corporation strives to ensure our products provide quality solutions for your enterprise software needs. The following issues are currently being researched. If you need further assistance with any issue, please contact Technical Support.

4.1 Users Can Change Password Even When Changing the Password is Restricted in the Active Directory

Issue: When you select User cannot change password in the Active Directory settings page, a user is restricted to change password. But when the user attempts to change the password by using the Forgotten password link, SSPR allows the user to change the password instead of restricting the user.

Workaround: When you restrict a user from changing the password, you must ensure that you disable the Use Proxy When Password Forgotten setting from the Active Directory template by using configuration editor.

4.2 Cannot Access the SSPR Page When using Internet Explorer Version 11

Issue: When using secured (https) connection to launch the SSPR web console, Internet Explorer 11 does not display the SSPR page.

Workaround: To workaround this issue, install kb3042058 from https://support.microsoft.com/en-us/kb/3042058.

NOTE:For Windows 2008 R2 server, first upgrade it to SP1, then apply kb3042058.

4.3 Users Unable to Login with Old Password If the Forgotten Password Process is Started But Not Completed

Issue: When a user starts the password change process by clicking Forgotten password, a random password is generated and if the user cancels the process without completing it then, user cannot use the old password. This happens because SSPR recognizes the random password is generated when the user clicks on Forgotten password.

Workaround: Perform the following for different directories:

  • For Active Directory, you can enable the Use Proxy When Password Forgotten setting from the Configuration Editor.

  • For eDirectory, you can enable the Allow admin to retrieve passwords option from the eDirectory settings page.

  • For Oracle Directory Server, the user needs to complete the forgotten password process and then use the new password to login.

5.0 Contact Information

Our goal is to provide documentation that meets your needs. If you have suggestions for improvements, please email Documentation-Feedback@netiq.com. We value your input and look forward to hearing from you.

For detailed contact information, see the Support Contact Information Web site.

For general corporate and product information, see the NetIQ Corporate Web site.