Version Affected: All
Overview
This article explains how to allow or prevent the reuse of a Time-based One-Time Password (TOTP) code. Preventing reuse is the more secure option, but this is left up to the administrator to configure.
In this article
Method 1: Prevent the reuse of TOTP
- Go to the Data tab.
- Scroll down to the One Time OATH list.
- Set an Active Directory (AD) attribute here — for example, wWWHomePage works, but confirm it is not already in use by another program first.
- Mark this attribute as Writable, as shown below.
With this setting in place on every realm that uses TOTP, each code can only be used once.
Method 2: Allow the reuse of TOTP
- On the realm where you want to allow TOTP reuse, go to the Data tab.
- Scroll down to the One Time OATH list.
- Remove the AD attribute from this field.
With this setting removed, this realm allows the reuse of TOTP.
Special Considerations
On the Multifactor Methods tab, the Password Change Interval and Passcode Offset length settings combine to determine how long a TOTP code remains valid, minus the current clock skew.
SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.
Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.
Comments
Please sign in to leave a comment.