<div dir="ltr"><div class="gmail_quote"><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div lang="EN-US" link="blue" vlink="purple"><div><p class="MsoNormal"><span style="font-size:11.0pt;font-family:"Calibri","sans-serif";color:#1f497d">I look forward to seeing what you have.</span></p></div></div></blockquote><div>Following is a zip archive of the source tree:</div><div><br></div><div><a href="https://docs.google.com/a/vt.edu/uc?id=0Bz3YRk8WRdWrY05LY3Q4bEN4dU0&export=download">https://docs.google.com/a/vt.edu/uc?id=0Bz3YRk8WRdWrY05LY3Q4bEN4dU0&export=download</a></div><div><br></div><div>There are a number of flows in this project. The one you should study is flows/intercept/vt-account-mgmt. We don't use security questions per se, but rather out-of-band methods to reset or change a password which we call "recovery options." Users must define these initially and maintain them yearly. Note that we drive the flow using the ResolveAttributes action, which is decoupled from the authentication subsystem, but ultimately contains LDAP directory data per our attribute-resolver.xml config.</div><div><br></div><div>I'm happy to field further general questions about the source on the list. Contact me privately if it's down in the weeds.</div><div><br></div><div>M</div><div><br></div></div></div>