Version Affected: 26.1.2
Bug Number: Not provided in source
Bug Status: Closed - Fixed
Fixed in Version(s): 26.1.3
Overview
After upgrading to SecureAuth Identity Platform 26.1.2, realms using Transparent SSO (TSSO) can immediately fail authentication with the error shown below. Selecting Please click here to use an alternate verification method lets the user pick an MFA method manually and continue through to a successful authentication into the TSSO realm.
Cause
Identity Platform 26.1.2 introduced Session Validation, which checks for a valid session and then carries out automatic authentication into TSSO realms (or other actions) based on Policy Settings.
If the Session Validation process determines that a new MFA prompt needs to be presented as part of the TSSO flow, that prompt can fail if the Preferred Auto-Submit Method Policy Setting is set to anything other than None (Admin, User, and Admin/User all enable Auto-Submit):
This only happens with MFA methods that require an action from Identity Platform itself, such as Push, OTP to SMS, Link to SMS, OTP to Email, or Link to Email. MFA methods that do not require action from Identity Platform, such as TOTP, continue to work as expected.
Resolution / Workaround
This is fixed in 26.1.3, which allows all Auto-Submit and MFA options to work as expected.
Until you can upgrade to 26.1.3, set the Preferred Auto-Submit Method Policy Setting to None as a workaround. This stops the error, but it also presents the end user with an MFA-selection screen whenever an MFA prompt is required, adding a slightly higher level of friction to the login process for TSSO realms.
SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.
Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.
Comments
Please sign in to leave a comment.