okay -- that makes sense to me -- but isn't there functionality to have a newly minted password created and emailed to the user by simply using the <asp:passwordrecovery /> control?
or is there more to it than that?
I'm having trouble finding guidance on this subject ... any ideas?