Troubleshooting: H/TOTP Enrollment Shows the Same URL Across Multiple Realms

Follow
    Applies to:
  • SecureAuth Identity Platform
Deployment model:
  • Cloud
  • Hybrid
  • On Premises
  • Version Affected: All
     
     

    Overview

    Using multiple enrollment realms on the same IdP server for multiple users can confuse end users, because the URL shown within the Authenticate application is the same for each realm the user has enrolled in.

     

    Cause

    The Authenticate application uses the fully qualified domain name (FQDN) of the external connection as the distinguishing label shown within the application. Since multiple enrollment realms on the same server typically share the same external FQDN, their labels look identical.

     

    Resolution:

    If the IdP server has a wildcard certificate installed (*.domain.ext), whoever manages DNS for the environment can create a new A record or CNAME pointing to the same IP address/record as the main IdP FQDN, for each enrollment realm that needs its own distinct label. Upon enrolling for a new Hardware/Time-based One-Time Passcode (H/TOTP) token within a realm, the new FQDN appears within the Authenticate application, making it easier for end users to distinguish which realm the token is valid for.


     

    Special Considerations

    A wildcard certificate, or multiple individual certificates, must be installed on the IdP server and bound within IIS. If using multiple individual certificates instead of a wildcard, IIS requires a separate IP address per certificate, since IIS can only bind one IP address to one certificate.


     

    SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.

    Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.

    0 out of 0 found this helpful

    Comments

    0 comments

    Please sign in to leave a comment.