Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

ADFSMFA 3.0.0.2 TOTP code #98

Closed
MDaugaardDK opened this issue Apr 19, 2020 · 5 comments
Closed

ADFSMFA 3.0.0.2 TOTP code #98

MDaugaardDK opened this issue Apr 19, 2020 · 5 comments
Labels

Comments

@MDaugaardDK
Copy link

Im experince some problems in ADFSMFA 3.0.0.1 and 3.0.0.2. When im registre my self with TOTP (Microsoft and Google auth.) its OK. im entering the code 1. time and am aprroved.
But afterwards, when im entering the code from TOTP app, it wont go on.... the boks with "Enter Code" just keep coming back. Nothing to see in ADFS log.

My setup is.
Active Directory Storage Mode
Security Configuration: RNG 256 Bits
TOTP;
Code history: 2
algorithm: SHA512
Security mode: RNG
Key Length: DEFAULT (1024 Bits)

Maybe my setup is wrong?

@redhook62
Copy link
Member

Hi, @MDaugaardDK

I don't really understand the sequence you have explain.
But keep in mind that your adfs servers, the client device MUST be sync with universal time.
eg time.windows.com
TOTP is based on current time. (in your case : the current and the 2 prior codes).
You must also provide a company name see : #9

Regards

Regards

@MDaugaardDK
Copy link
Author

i think all is in sync. GMT+2.

But when im entering the TOTP code it is not invalid.. but im getting redirectet to entering the code again... maybe ADFS problem on my side?
Im trying to use ADFSMFA on Exchange ECP

@redhook62
Copy link
Member

Yes, by default you have three tries, finally this is configurable. at the last unsuccessful attempt you must be blocked and restart your session.
Also check, the "Anti Replay" function if this is activated you cannot enter the same code during the validation window which is 5 minutes by default.
I will confirm you tomorrow by testing with the parameters which you indicated to me.
Using Exchange has no impact.

Regards

@redhook62
Copy link
Member

Hi, @MDaugaardDK

I just tested with the parameters provided, and of course everything works perfectly.

It is therefore necessary that you check a few points.

If you have more informations ?

Regards

@MDaugaardDK
Copy link
Author

Today everything works fine.... think it was because our Service Account was not a part of Account Operators :-)

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants