Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations John Tel on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

ALoha 6.x user locked out

Status
Not open for further replies.

alohaakamai3

IS-IT--Management
Aug 11, 2006
482
US
We have a store where the users were sharing a login with complex, case sensitive password, and one
of the braniac managers entered the password enough times to get a message saying they were locked out
for 30 minutes. The problem is, it's been several days and still won't allow a login, and they don't
know any other BOH passwords to login since they were sharing this one... ugh! Any help is appreciated!
 
Try replacing the emp.dbf from a dated subdirectory to the new data directory. Then open up AlohaMgr and enter the old password.
 
Thanks, Menulinkman... tried this literally about 60 seconds before I saw your post, it didn't work. I'll try going further back in the week tho.
 
Hi again,

My mistake. That did in fact work. This store has an exact duplicate Aloha directory replicated on another partition, and in my haste,
I initially made the file changes there and not in Aloha's working directory.

Incidentally, I also found out that the reason they had this problem is because Aloha forced them to change the password, which they
did, but then forgot (as users often do with complex passwords). Is there a way for me to disable this password expiration in version 6.5?

Thanks again.
 
Not without breaking PCI Compliance... Meaning: no, don't do it!
 
Thnks Moregelen, I'm not too worried about the "password guessing" part of PCI. I'm not trying to disable passwords or even get
rid of complex passwords, I just didn't want them to have to redo it at unknown intervals.
 
The interval isn't unknown, or at least it shouldn't be. I don't really know Aloha, but you can set the interval in Micros through the system -> restaurant -> security tab, I'm sure aloha has something similar.

And remember, when it comes to PCI Compliance, it doesn't matter which part you violate. If you violate any part of it, they will slam you for it if you get audited. And want to see a recent breach going around? Look at what happened to Zaxby's. They are going to be going over their servers with a fine toothed comb looking for anything that they can go 'ah-ha!' over.
 
To see how often you are required to change your password, look under Maintenance -> Store Settings -> Security -> POS Password settings. If its like mine, the settings are 6 tries, 90 day until expiration, can't use previous 4 passwords, and use strong BOH Password rules.

If you use Configuration Center, thats a different story. It is located in Maintenance -> Labor -> Security Roles.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top