OPNsense Forum

Archive => 22.7 Legacy Series => Topic started by: haebi5 on November 21, 2022, 07:31:42 PM

Title: OTP auto-enrollment
Post by: haebi5 on November 21, 2022, 07:31:42 PM
I have configured an access server profile for LDAP + Timebased One Time Password and I have now two issues:

- the first login to the portal ist not possible, when I use UserPrincipalName instead of sAMAccountName Attribute. So the user will not be created accordingly. When I change to sAMAccountName, it works as expected. User is being created and the user ends up, where ever I have defined in the security matrix. This is btw something which is perfectly working on pfSense

- I have not figured out how to implement an autoenrolment process. The user should be able to login to his portal shoot the QR to his Auth App and done. It is kind of a chicken and eggs question, so I have to provide the user with a QR to get it done but why . . .?

Do I miss somethings here?

Best, rene
Title: Re: OTP auto-enrollment
Post by: mimugmail on November 22, 2022, 08:57:46 AM
Hm, I have this running with local users, LDAP should be same. Do they get created locally when first login to UI?