You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The self registration workflow doesn't validate the user's email address yet. It's common practice to validate the email address.
Suggested workflow
User registers herself with username, temporary password and email address. The stage user is not created. Instead the information are stored in a local sqlite database.
Portal sends user an email with a validation token and a temporary password
User clicks on link and validates the token.
Portal creates stage user in FreeIPA.
Security concern
The temporary password is send plain text. Since it's a temporary password (user has to set a new password in FreeIPA web UI anyway) it is not so bad.
In order to mitigate flooding and DoS attacks on FreeIPA and LDAP servers, the portal must create the staging user after the mail address has been validated.
The text was updated successfully, but these errors were encountered:
The self registration workflow doesn't validate the user's email address yet. It's common practice to validate the email address.
Suggested workflow
Security concern
The temporary password is send plain text. Since it's a temporary password (user has to set a new password in FreeIPA web UI anyway) it is not so bad.
In order to mitigate flooding and DoS attacks on FreeIPA and LDAP servers, the portal must create the staging user after the mail address has been validated.
The text was updated successfully, but these errors were encountered: