Overview#
The objective is how to provide the user with the ability to securely Password Reset their password or retrieve their password when they have forgotten.Automated Password Self Service (APASS)#
Novell's Challenge Response NSPM
Novell has implemented some very secure methods that allow this objective to be reached.
The methodology utilized is done by the user answering "Challenge Questions" correctly and submitting the "Challenge Responses" to the LDAP Directory via the NMAS Challenge Response authentication mechanism. The NMAS Challenge Response authentication mechanism is implemented over LDAP as a SASL bind which allows operations to be performed as if the user utilized their password for authentication. No "admin" level credentials are required for operation.