Version Affected: 21.04 and later
Overview
The Helpdesk realm or Self Service realm does not show a user's mobile or one-time passcode (OTP) devices when looking up that user, even though the user has enrolled devices.
There are two unrelated causes, so a fix for one cause will not resolve the other:
- See Cause 1 - The realm cannot connect to the Mobile Service because the wrong client certificate is selected
- See Cause 2 - The realm's Mobile Tokens display setting is not set to show devices
In this article
Cause 1: Incorrect Client Certificate Selected
The realm cannot connect to the Mobile Service because the correct client certificate is not selected on the System Info tab. Audit logs show an authorization failure similar to:
Message="[ReportIp].[ReportAsync] Exception Error while retrieving or refreshing Titan access_token. Cloud Response: Unauthorized-{"error":"invalid_client","errorMessage":"Client authentication failed (e.g., unknown client, no client authentication included, or unsupported authentication method). not_found"}
Resolution 1:
To resolve this:
- Open the Admin Console and navigate to the System Info tab of the affected realm.
- Check the Client Cert Serial Nbr field. Make sure it is set to the SecureAuth Appliance Cert.
- Save the settings.
Cause 2: Mobile Tokens Display Setting Not Enabled
Starting in 21.04, Mobile Service introduced a separate display setting for whether Mobile Devices appear on the Helpdesk or Self Service page. This setting defaults in a way that can leave Mobile Devices hidden even though the user has devices enrolled.
Resolution 2:
To resolve this:
- Open the Admin Console and navigate to the Post Authentication tab of the affected realm.
- Click the Configure Self Service Page link (or the Helpdesk equivalent, if configuring a Helpdesk realm).
- Set Mobile Tokens to Show Enabled.
- Save the settings, then log in again.
The user's mobile and OTP devices now appear on the Helpdesk or Self Service page:
SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.
Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.
Comments
Please sign in to leave a comment.