OPNsense Forum

English Forums => General Discussion => Topic started by: pixel on April 15, 2022, 06:09:22 AM

Title: TOTP+LDAP Not working on newly imported users
Post by: pixel on April 15, 2022, 06:09:22 AM
Hi,

this is my first time posting here, i have a kinda weird issue here, the TOTP+LDAP auth failed for newly imported users, but i dont have any issues for current users. The issue happened today and my last working import is yesterday.
i have tried to reimport the new user as well as generate a new qr but it still throws auth failed error when i try to verify  on Tester.

Title: Re: TOTP+LDAP Not working on newly imported users
Post by: zerwes on April 15, 2022, 06:13:24 AM
Some hints in the audit log file (System -> Log Files -> Audit)?
Title: Re: TOTP+LDAP Not working on newly imported users
Post by: pixel on April 15, 2022, 06:17:09 AM
i have checked , but there is nothing in audit
Title: Re: TOTP+LDAP Not working on newly imported users
Post by: zerwes on April 15, 2022, 06:47:59 AM
Can you perform some sniffing on the network if the ldap user is fetched successfully?
Do you have "Match case insensitive" checked on the server config? Same for "Read properties"?
Title: Re: TOTP+LDAP Not working on newly imported users
Post by: pixel on April 15, 2022, 08:07:56 AM
i tried to authenticate using the tester function in System>Access>Tester.
When select LDAP only it passed but when select TOPT+LDAP it will throw Authentication Failed Error
Title: Re: TOTP+LDAP Not working on newly imported users
Post by: zerwes on April 15, 2022, 09:16:18 AM
Just to be sure: do you use the default token order or do you have the "Reverse token order" configured (and do you follow these?)
Did you try regenerating the OTP seed?
And with TOTP you have to pay attention to ntp ...
Title: Re: TOTP+LDAP Not working on newly imported users
Post by: pixel on April 15, 2022, 09:21:29 AM
Hi thank you for the support, i managed to solve my issue.
By deleting and create a new user and import that user to FW solve the issue.