How To: Prevent or Allow Reuse of an OATH TOTP Code

Follow
    Applies to:
  • SecureAuth Identity Platform
Deployment model:
  • Cloud
  • Hybrid
  • On Premises
  • Version Affected: All

     

    Overview

    This article explains how to allow or prevent the reuse of a Time-based One-Time Password (TOTP) code. Preventing reuse is the more secure option, but this is left up to the administrator to configure.

    In this article

     

    Method 1: Prevent the reuse of TOTP

    1. Go to the Data tab.
    2. Scroll down to the One Time OATH list.
    3. Set an Active Directory (AD) attribute here — for example, wWWHomePage works, but confirm it is not already in use by another program first.
    4. Mark this attribute as Writable, as shown below.

    Data tab showing an AD attribute set in the One Time OATH list and marked as Writable.

    With this setting in place on every realm that uses TOTP, each code can only be used once.


     

    Method 2: Allow the reuse of TOTP

    1. On the realm where you want to allow TOTP reuse, go to the Data tab.
    2. Scroll down to the One Time OATH list.
    3. Remove the AD attribute from this field.

    With this setting removed, this realm allows the reuse of TOTP.

     

    Special Considerations

    On the Multifactor Methods tab, the Password Change Interval and Passcode Offset length settings combine to determine how long a TOTP code remains valid, minus the current clock skew.




    SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.

    Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.

    0 out of 0 found this helpful

    Comments

    0 comments

    Please sign in to leave a comment.