I am setting up SSPR 3.3.1 and using CLE 3.9.13 on Windows 8.1. Our ldap
is Active Directory and we are using remote database to MS SQL for
Response Read and Write Location in Forgotten Password Settings.

When using CLE, the Forgotten Password feature works, but apparently
only if you have already logged in to SSPR and set challenge/response
questions. If you have not you receive the SSPR 5006 "... not eligible"

Both the documentation and the CLE installer config utility give the
impression that you can force challenge/response setup at the GINA
during login. Is this not the case? If it is supposed to force this, how
can I troubleshoot my environment where this is not working?


