Membership Authentication Treats Username as Case Sensitive When Blacklisting Account

ID: Q240660


The information in this article applies to:
  • Microsoft Site Server version 3.0


SYMPTOMS

When a user is blacklisted as a result of too many attempts to use the wrong password, Membership Authentication will deny access for a set period of time. However, because the username is case sensitive, that same user can attempt authentication again, using the same username with different a case letter used on one or more letters in the username. The user will still need to know the correct password to gain access, but will be given more chances to guess the password then was originally intended.


RESOLUTION

To resolve this problem, obtain the latest service pack for Site Server 3.0. For additional information, please see the following article in the Microsoft Knowledge Base:

Q219292 How to Obtain the Latest Site Server 3.0 Service Pack


STATUS

This problem was first corrected in Site Server 3.0 Service Pack 3.


MORE INFORMATION

You can configure the account lockout variables, such as retry attempts and blacklist time. From your <SiteServer>\bin\p&m folder, run the following from a command line:

pmadmin.vbs set master /authaccountdenythreshold:3 /authaccountdenytimeout:2
Please refer to your Site Server online documentation for additional information on using the Pmadmin.vbs script utility.

Additional query words:

Keywords : SS3SP3Fix
Version : winnt:3.0
Platform : winnt
Issue type : kbbug


Last Reviewed: October 26, 1999
© 2000 Microsoft Corporation. All rights reserved. Terms of Use.