Version Affected: All
Overview
Users can fail to authenticate with TOTP (Time-based One-Time Password) during Two-Factor Authentication after the realm's datastore type is changed.
Cause
When a user enrolls for TOTP, the value is looked up against whichever Active Directory attribute the datastore type's Search Attribute pointed to at the time of enrollment -- for example, sAMAccountName. Changing the realm's datastore type afterward can change the default Search Attribute, so the realm can no longer find the user's TOTP value using the new attribute.
Resolution:
- Go to the realm's Data tab and open Membership Connection Settings.
- In the Search Filter section, set Search Attribute back to whichever attribute was in use when users originally enrolled for TOTP. The searchFilter field itself does not need to change.
Users should now be able to authenticate with TOTP again.
SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.
Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.
Comments
Please sign in to leave a comment.