{"id":1162,"date":"2007-05-18T16:55:00","date_gmt":"2007-05-18T21:55:00","guid":{"rendered":"http:\/\/blogs.devhorizon.com\/reza\/?p=1162"},"modified":"2007-05-18T16:55:00","modified_gmt":"2007-05-18T21:55:00","slug":"forms-based-authentication-headaches-aka-fbah","status":"publish","type":"post","link":"https:\/\/blogs.devhorizon.com\/reza\/2007\/05\/18\/forms-based-authentication-headaches-aka-fbah\/","title":{"rendered":"Forms Based Authentication Headaches a.k.a FBAH:)"},"content":{"rendered":"<p><P class=MsoNormal style=\"MARGIN: 0in 0in 0pt\">Here is the situation:<\/P><br \/>\n<P class=MsoNormal style=\"MARGIN: 0in 0in 0pt\">&nbsp;<\/P><br \/>\n<P class=MsoNormal style=\"MARGIN: 0in 0in 0pt\">-You have set up your SharePoint site to use forms based authentication using standard out of the box System.Web.Security.SqlMembershipProvider provider.<?xml:namespace prefix = o ns = \"urn:schemas-microsoft-com:office:office\" \/><o:p><\/o:p><\/P><br \/>\n<P class=MsoNormal style=\"MARGIN: 0in 0in 0pt\">-You have set up your membership provider to use passwordFormat=&#8221;Encrypted&#8221; <o:p><\/o:p><\/P><br \/>\n<P class=MsoNormal style=\"MARGIN: 0in 0in 0pt\">-You are using ASP.NET Web Site Administration Tool to insert your first user <o:p><\/o:p><\/P><br \/>\n<P class=MsoNormal style=\"MARGIN: 0in 0in 0pt\">-You hit your sharepoint site , you are redirected to the login page , then you enter user name and password you created above and you are very excited to see everything works like a charm<SPAN style=\"COLOR: black\">&#8230;&#8230;&#8230;&#8230;&#8230;Boom<\/SPAN>&#8230;&#8230;&#8230;&#8230;&#8230;. You get this message:)<o:p><\/o:p><\/P><br \/>\n<BLOCKQUOTE dir=ltr style=\"MARGIN-RIGHT: 0px\"><br \/>\n<P class=MsoNormal style=\"MARGIN: 0in 0in 0pt\"><B>&#8220;The server could not sign you in. Make sure your user name and password are correct, and then try again&#8221;.<\/B><\/P><\/BLOCKQUOTE><BR><br \/>\n<DIV align=\"center\"><IMG src=\"http:\/\/farm1.static.flickr.com\/210\/504423529_1fcb6bc596.jpg?v=0\"><\/DIV><br \/>\n<P class=MsoNormal dir=ltr style=\"MARGIN: 0in 0in 0pt\">-You are 100% certain that what you entered as username and password is correct,so what the hell is going on and why it is not working?!!! <\/P><br \/>\n<P class=MsoNormal style=\"MARGIN: 0in 0in 0pt\">Well, Let me give you couple of simple advices that might be helpful:<\/P><br \/>\n<P class=MsoNormal style=\"MARGIN: 0in 0in 0pt\">1) Don&#8217;t use this ugly tool. Just drag and drop a &#8220;CreateUserWizard&#8221; control onto your aspx page and hook it up to your membership provider. Sometimes&nbsp;it&nbsp;is much easier to do things yourself&nbsp; than relying on this strange creature.<o:p><\/o:p><\/P><br \/>\n<P class=MsoNormal style=\"MARGIN: 0in 0in 0pt\">2) Most probably, machinekey element in the <MACHINEKEY>asp.net application&#8217;s web.config&nbsp;is different than the one defined in your SharePoint site&#8217;s web.config . Check the keys (validationKey, decryptionKey) and the encryption algorithm to make sure they are identical.<\/P><br \/>\n<P class=MsoNormal style=\"MARGIN: 0in 0in 0pt; mso-layout-grid-align: none\"><SPAN style=\"FONT-SIZE: 10pt; COLOR: blue; FONT-FAMILY: 'Courier New'; mso-no-proof: yes\">&lt;<\/SPAN><SPAN style=\"FONT-SIZE: 10pt; COLOR: maroon; FONT-FAMILY: 'Courier New'; mso-no-proof: yes\">machineKey <\/SPAN><SPAN style=\"FONT-SIZE: 10pt; COLOR: red; FONT-FAMILY: 'Courier New'; mso-no-proof: yes\">validationKey<\/SPAN><SPAN style=\"FONT-SIZE: 10pt; COLOR: blue; FONT-FAMILY: 'Courier New'; mso-no-proof: yes\">=<\/SPAN><SPAN style=\"FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'; mso-no-proof: yes\">&#8220;<SPAN style=\"COLOR: blue\">21F0F891A36D12A278DB4FD8699C164EDBDA1FF9713A546C133CBE26DB026C5A5A10C884EF312DE5123959C8D96638423F8A6A3AE77F39E2B7A2596749B8C275<\/SPAN>&#8221; <SPAN style=\"COLOR: red\">decryptionKey<\/SPAN><SPAN style=\"COLOR: blue\">=<\/SPAN>&#8220;<SPAN style=\"COLOR: blue\">D868653A8B663BD752B01277E0465C0788D5BB9A5A9A405E<\/SPAN>&#8220;<SPAN style=\"COLOR: blue\"> <\/SPAN><SPAN style=\"COLOR: red\">validation<\/SPAN><SPAN style=\"COLOR: blue\">=<\/SPAN>&#8220;<SPAN style=\"COLOR: blue\">SHA1<\/SPAN>&#8220;<SPAN style=\"COLOR: blue\">\/&gt;<\/SPAN><\/SPAN><o:p><\/o:p><\/P><br \/>\n<P class=MsoNormal style=\"MARGIN: 0in 0in 0pt\">3) It is much easier if you create the first user using &#8220;Clear&#8221; format using passwordFormat=&#8221;Clear&#8221;&nbsp;(so you can see the password in database) and when you deploy your provider to the web.config of your SharePoint site you can go ahead and change it to &#8220;Encrypted&#8221; and re-create the initial user one more time.<\/P><br \/>\n<DIV class=MsoNormal style=\"MARGIN: 0in 0in 0pt\"><br \/>\n<HR align=left width=\"50%\" color=#aca899 noShade SIZE=10><br \/>\n<\/DIV><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Here is the situation: &nbsp; -You have set up your SharePoint site to use forms based authentication using standard out of the box System.Web.Security.SqlMembershipProvider provider. -You have set up your membership provider to use passwordFormat=&#8221;Encrypted&#8221; -You are using ASP.NET Web Site Administration Tool to insert your first user -You hit your sharepoint site , you [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[],"tags":[],"class_list":["post-1162","post","type-post","status-publish","format-standard","hentry"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.4 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Forms Based Authentication Headaches a.k.a FBAH:) - Reza Alirezaei&#039;s Blog %<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/blogs.devhorizon.com\/reza\/2007\/05\/18\/forms-based-authentication-headaches-aka-fbah\/\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Reza Alirezaei\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/blogs.devhorizon.com\\\/reza\\\/2007\\\/05\\\/18\\\/forms-based-authentication-headaches-aka-fbah\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/blogs.devhorizon.com\\\/reza\\\/2007\\\/05\\\/18\\\/forms-based-authentication-headaches-aka-fbah\\\/\"},\"author\":{\"name\":\"Reza Alirezaei\",\"@id\":\"https:\\\/\\\/blogs.devhorizon.com\\\/reza\\\/#\\\/schema\\\/person\\\/cdbb24d283697a65951cb4a14e474938\"},\"headline\":\"Forms Based Authentication Headaches a.k.a FBAH:)\",\"datePublished\":\"2007-05-18T21:55:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/blogs.devhorizon.com\\\/reza\\\/2007\\\/05\\\/18\\\/forms-based-authentication-headaches-aka-fbah\\\/\"},\"wordCount\":351,\"commentCount\":0,\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/blogs.devhorizon.com\\\/reza\\\/2007\\\/05\\\/18\\\/forms-based-authentication-headaches-aka-fbah\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/blogs.devhorizon.com\\\/reza\\\/2007\\\/05\\\/18\\\/forms-based-authentication-headaches-aka-fbah\\\/\",\"url\":\"https:\\\/\\\/blogs.devhorizon.com\\\/reza\\\/2007\\\/05\\\/18\\\/forms-based-authentication-headaches-aka-fbah\\\/\",\"name\":\"Forms Based Authentication Headaches a.k.a FBAH:) - Reza Alirezaei's Blog %\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/blogs.devhorizon.com\\\/reza\\\/#website\"},\"datePublished\":\"2007-05-18T21:55:00+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/blogs.devhorizon.com\\\/reza\\\/#\\\/schema\\\/person\\\/cdbb24d283697a65951cb4a14e474938\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/blogs.devhorizon.com\\\/reza\\\/2007\\\/05\\\/18\\\/forms-based-authentication-headaches-aka-fbah\\\/\"]}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/blogs.devhorizon.com\\\/reza\\\/#website\",\"url\":\"https:\\\/\\\/blogs.devhorizon.com\\\/reza\\\/\",\"name\":\"Reza Alirezaei's Blog\",\"description\":\"Blogging from the field!\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/blogs.devhorizon.com\\\/reza\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/blogs.devhorizon.com\\\/reza\\\/#\\\/schema\\\/person\\\/cdbb24d283697a65951cb4a14e474938\",\"name\":\"Reza Alirezaei\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/3ba940d84e0ecb909e62e93df4c56daf0395c7e53c914467ab2ee73124a7d7b6?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/3ba940d84e0ecb909e62e93df4c56daf0395c7e53c914467ab2ee73124a7d7b6?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/3ba940d84e0ecb909e62e93df4c56daf0395c7e53c914467ab2ee73124a7d7b6?s=96&d=mm&r=g\",\"caption\":\"Reza Alirezaei\"},\"url\":\"https:\\\/\\\/blogs.devhorizon.com\\\/reza\\\/author\\\/rezaa\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Forms Based Authentication Headaches a.k.a FBAH:) - Reza Alirezaei's Blog %","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/blogs.devhorizon.com\/reza\/2007\/05\/18\/forms-based-authentication-headaches-aka-fbah\/","twitter_misc":{"Written by":"Reza Alirezaei","Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/blogs.devhorizon.com\/reza\/2007\/05\/18\/forms-based-authentication-headaches-aka-fbah\/#article","isPartOf":{"@id":"https:\/\/blogs.devhorizon.com\/reza\/2007\/05\/18\/forms-based-authentication-headaches-aka-fbah\/"},"author":{"name":"Reza Alirezaei","@id":"https:\/\/blogs.devhorizon.com\/reza\/#\/schema\/person\/cdbb24d283697a65951cb4a14e474938"},"headline":"Forms Based Authentication Headaches a.k.a FBAH:)","datePublished":"2007-05-18T21:55:00+00:00","mainEntityOfPage":{"@id":"https:\/\/blogs.devhorizon.com\/reza\/2007\/05\/18\/forms-based-authentication-headaches-aka-fbah\/"},"wordCount":351,"commentCount":0,"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/blogs.devhorizon.com\/reza\/2007\/05\/18\/forms-based-authentication-headaches-aka-fbah\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/blogs.devhorizon.com\/reza\/2007\/05\/18\/forms-based-authentication-headaches-aka-fbah\/","url":"https:\/\/blogs.devhorizon.com\/reza\/2007\/05\/18\/forms-based-authentication-headaches-aka-fbah\/","name":"Forms Based Authentication Headaches a.k.a FBAH:) - Reza Alirezaei's Blog %","isPartOf":{"@id":"https:\/\/blogs.devhorizon.com\/reza\/#website"},"datePublished":"2007-05-18T21:55:00+00:00","author":{"@id":"https:\/\/blogs.devhorizon.com\/reza\/#\/schema\/person\/cdbb24d283697a65951cb4a14e474938"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/blogs.devhorizon.com\/reza\/2007\/05\/18\/forms-based-authentication-headaches-aka-fbah\/"]}]},{"@type":"WebSite","@id":"https:\/\/blogs.devhorizon.com\/reza\/#website","url":"https:\/\/blogs.devhorizon.com\/reza\/","name":"Reza Alirezaei's Blog","description":"Blogging from the field!","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/blogs.devhorizon.com\/reza\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/blogs.devhorizon.com\/reza\/#\/schema\/person\/cdbb24d283697a65951cb4a14e474938","name":"Reza Alirezaei","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/3ba940d84e0ecb909e62e93df4c56daf0395c7e53c914467ab2ee73124a7d7b6?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/3ba940d84e0ecb909e62e93df4c56daf0395c7e53c914467ab2ee73124a7d7b6?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/3ba940d84e0ecb909e62e93df4c56daf0395c7e53c914467ab2ee73124a7d7b6?s=96&d=mm&r=g","caption":"Reza Alirezaei"},"url":"https:\/\/blogs.devhorizon.com\/reza\/author\/rezaa\/"}]}},"_links":{"self":[{"href":"https:\/\/blogs.devhorizon.com\/reza\/wp-json\/wp\/v2\/posts\/1162","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.devhorizon.com\/reza\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.devhorizon.com\/reza\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.devhorizon.com\/reza\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.devhorizon.com\/reza\/wp-json\/wp\/v2\/comments?post=1162"}],"version-history":[{"count":0,"href":"https:\/\/blogs.devhorizon.com\/reza\/wp-json\/wp\/v2\/posts\/1162\/revisions"}],"wp:attachment":[{"href":"https:\/\/blogs.devhorizon.com\/reza\/wp-json\/wp\/v2\/media?parent=1162"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.devhorizon.com\/reza\/wp-json\/wp\/v2\/categories?post=1162"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.devhorizon.com\/reza\/wp-json\/wp\/v2\/tags?post=1162"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}