Hi all,

I am currently working on $subject.

Password recovery can be provided in two ways, as currently supported by IS
User Recovery Information Service.

   - Password recovery with Notifications [1]

Notifications are provided in the form of emails. At the request of the
user, an email will be sent to the email address configured in user profile.

The format of the email can be configured in
{carbon_home}/repository/conf/email/*email-­admin-­config.xml*


   - Password recovery with secret questions [2]

Set of pre-configured secret questions will be displayed on the UI at the
request of the user.
The questions and answers is managed via claims.

Considering the popular stores (i.e. Amazon, Target, Best Buy), first
option is the commonly used method. In my opinion password reset via the
reset-link in the email, is also more convenient for the user.


Which of above would be the most appropriate password recovery method for
ES?

Thank you,
Sameera

[1] https://docs.wso2.com/display/IS450/Recover+with+Notification
[2] https://docs.wso2.com/display/IS450/Recover+with+Secret+Questions


-- 



*Thanks & Regards,Sameera Jayaratna Software Engineer; **WSO2 Inc. *

*lean . enterprise . middleware |  http://wso2.com <http://wso2.com> *
_______________________________________________
Architecture mailing list
Architecture@wso2.org
https://mail.wso2.org/cgi-bin/mailman/listinfo/architecture

Reply via email to