1. replace their current hash with "LOCKED", plus some random noise.
2. generate a random string, and store the hash in a "forcedResetToken" field for the user.
3. email them a URL, part of which is the token.
4. when the link is activated, I look up the user account by the hash of the token, force them to choose a new pw, and remove the forcedResetToken.
That's the approach I take in my Wicket Quickstarter project (http://armhold.com/store).
Based on other comments I'm seeing, I'm now planning to also add an expiration of the token (say 24 hours or something).