Version Affected: 21.04 and later
Overview
For some users, Push Notification does not work as a multi-factor authentication (MFA) method, even though it appears to be configured correctly. The Debug log shows an entry similar to:
Message="Mobile Service SendPushNotification, StatusCode: BadGateway. ResponseTime='155'"
Cause
Although the "Bad Gateway" status suggests a communication error, the real cause is masked by the time it reaches the log. The affected user did not allow push notifications on the SecureAuth Authenticate app when they enrolled. If push notifications are disabled at enrollment time, TOTP enrollment still completes, but some of the details Identity Platform needs in order to send a push to that device are never captured during enrollment — so push notification never works for that enrollment, even if the user enables push notifications on their device at a later date. Re-enabling push after the fact does not fix it without a full re-enrollment.
Resolution/Workaround
A feature enhancement has been released in the below versions to disable - Enrollment now verifies that push notifications are available before enrolling a device in Push MFA. If notifications are disabled, users get a clear, actionable message at enrollment and can register for passcode (TOTP) only. Push is no longer offered at login for devices that are unable to receive it.
- iOS Authenticate 25.3.02+
- Android Authenticate 25.3.03+
If an update to one of the above versions is not possible:
- Enable push notifications for the SecureAuth Authenticate app on the affected user's device.
- Remove the user's current enrollment.
- Have the user re-enroll.
SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.
Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.
Comments
Please sign in to leave a comment.