Troubleshooting: Login for Windows TOTP Error "Sorry, Something You Entered Was Incorrect"

Follow
    Applies to:
  • SecureAuth Identity Platform
Deployment model:
  • Cloud
  • Hybrid
  • On Premises
  • Version Affected: 9.2 and later — the version range differs by cause, noted individually below.
     
     

    Overview

    When logging in to SecureAuth Login for Windows (L4W) using a TOTP (OATH) device, users may see the error "Sorry, something you entered was incorrect." If SADIAG debug logging is enabled, the log shows an entry similar to Failed to validate OTP: ret=0, valid_otp=0 (sometimes with error: 1436). There are two independent causes:

    • See Cause 1 - Only hard tokens are affected, and the appliance is running L4W 1.0.0–1.0.3
    • See Cause 2 - The error happens on any token type, regardless of L4W version

    These causes are not related, so a fix for one will not resolve the other.

     

    In this article


     

    Cause 1: Passcode Offset defect for hard tokens (L4W 1.0.0–1.0.3)

    Applies to L4W 1.0.0 through 1.0.3, hard tokens only. Soft tokens such as the Authenticate app are unaffected, and realms that use TOTP as an MFA method directly (not through L4W) are unaffected regardless of token type.

    L4W calculates the Passcode Offset for hard tokens in seconds instead of minutes, which puts L4W's TOTP calculation about 35 seconds behind (the TOTP interval plus 5 seconds). In practice, a hard token's current code is only accepted by L4W 5 seconds after that code has already been replaced by the next one — so it always looks incorrect at the moment the user types it.

    This is product defect CP-490, fixed in L4W 1.0.4. To resolve this, upgrade to L4W 1.0.4 or later.


     

    Cause 2: Passcode Change Interval mismatch between realms

    Applies to version 9.2 and later, any token type.

    The error appears the first time a user tries to log in with a TOTP:

    Windows login screen showing the error 'Sorry, something you entered was incorrect.' after entering a TOTP code.

    This is caused by a mismatch in the Passcode Change Interval setting between the realm used for enrollment (the URL or QR-enrollment realm, or Device Enrollment realm) and the Login for Endpoints realm the user authenticates against. Both realms must have this value set to the same number of seconds.

    To resolve this:

    1. On the URL or QR-enrollment realm, open the Post Authentication tab and note the Passcode Change Interval value.
    2. On the Login for Endpoints realm, open the Multi-Factor Methods tab and set its Passcode Change Interval to the same value.
    3. Have the user try logging in again with a fresh TOTP code.

    If a realm has both OATH Seed and OATH Token mapped, devices originally enrolled as OATH Seed are automatically migrated to OATH Token starting in version 9.2. Make sure the Passcode Change Interval is correct for these migrated realms too, since a realm that was matched correctly before the migration can drift out of sync afterward.

    For details on enabling SADIAG and debugging Login for Endpoints issues, see this article.


    SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.

    Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.

    0 out of 0 found this helpful

    Comments

    0 comments

    Please sign in to leave a comment.