Hello,
We are currently on Lawson Security 9 (CheckLS=Y). When logging into portal our users are able use their current password or previous password. Our Lawson LDAP is bound to our Corporate LDAP so all passwords come from the Corporate LDAP. None of our other non-Lawson systems bound to LDAP have this issue so my theory is that it is a problem with our bind settings or setup. Anyone have any ideas how to correct the problem?
This can be a big security hole since when a user's password is reset it is initally set to a dummy password before the user changes it. So the dummy password can be used even after the user has changed the password.
Any help would be awesome. Thanks.
Matt