Guest User!

You are not Sophos Staff.

This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

OTP enabled - user can no longer login to userportal

at a remote location I tested with OTP today on a XG106 SFOS 18.0.6 MR-6-Build655

first tested with domain user which was not working as described below.

then tested with local user on XG which did not work either.

1. confirmed, I can login to userportal. OK

2. enabled OTP and enforced it only for the user:

3. tested if user can login to userportal to create otp password with his token generator

login fails

4. if I remove the user from "OTP required for these users and groups", login to userportal works again

The test user has a complex password with 18 characters. Also doesn't work with short passwords.



This thread was automatically locked due to age.
Parents
  • Seems like the OTP is not correct. 

    Check the access_server Log on the CLI or check the time date of OTP. Also check the time of the device. 

  • from my understanding before OTP is configured for the user, the user needs to log into userportal and scan the QR code there.

    problem here: he cannot get to the portal to do that

    time is correct


    MESSAGE   Dec 20 15:42:52.109171 [OTP_AUTH]: (otp_handle_complete_password_success_request): REJECT4 for user testuserotp (user didn't use OTP, auto-creation of tokens is not enabled)
    ERROR     Dec 20 15:42:52.109253 [access_server]: check_auth_result: VPN/SSLVPN/MYACC Authentication Failed

Reply
  • from my understanding before OTP is configured for the user, the user needs to log into userportal and scan the QR code there.

    problem here: he cannot get to the portal to do that

    time is correct


    MESSAGE   Dec 20 15:42:52.109171 [OTP_AUTH]: (otp_handle_complete_password_success_request): REJECT4 for user testuserotp (user didn't use OTP, auto-creation of tokens is not enabled)
    ERROR     Dec 20 15:42:52.109253 [access_server]: check_auth_result: VPN/SSLVPN/MYACC Authentication Failed

Children