Home
Help
Search
Login
Register
OPNsense Forum
»
Archive
»
20.1 Legacy Series
»
[Solved] LDAP + TOTP authentication failure
« previous
next »
Print
Pages:
1
[
2
]
3
Author
Topic: [Solved] LDAP + TOTP authentication failure (Read 18306 times)
mimugmail
Hero Member
Posts: 6766
Karma: 494
Re: LDAP + TOTP authentication failure
«
Reply #15 on:
August 03, 2020, 03:21:49 pm »
When you use LDAP without encryption and via console you do a:
tcpdump port 389 -n -i vmxX -X
Then you can see your password in cleartext and if it only is the password.
Logged
WWW:
www.routerperformance.net
Support plans:
https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German):
https://opnsense.max-it.de/
CraigS
Newbie
Posts: 25
Karma: 2
Re: LDAP + TOTP authentication failure
«
Reply #16 on:
August 03, 2020, 06:05:52 pm »
So it looks like the ldap query is not sent when totp is used.
Nothing in the packet capture.
Logged
mimugmail
Hero Member
Posts: 6766
Karma: 494
Re: LDAP + TOTP authentication failure
«
Reply #17 on:
August 03, 2020, 07:35:31 pm »
Can you try with IP instead of FQDN and plain 389?
Logged
WWW:
www.routerperformance.net
Support plans:
https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German):
https://opnsense.max-it.de/
CraigS
Newbie
Posts: 25
Karma: 2
Re: LDAP + TOTP authentication failure
«
Reply #18 on:
August 03, 2020, 07:40:34 pm »
It still gives the same error, and no ldap query on tcpdump.
No problems without totp.
Could the ldap function that splits the password and totp be the issue?
Logged
CraigS
Newbie
Posts: 25
Karma: 2
Re: LDAP + TOTP authentication failure
«
Reply #19 on:
August 04, 2020, 08:28:26 am »
Reset all to defaults, configured just a ldap server + totp with same results.
Reverted snapshot and updated to 20.7 with same results as before...
«
Last Edit: August 04, 2020, 08:34:15 am by CraigS
»
Logged
mimugmail
Hero Member
Posts: 6766
Karma: 494
Re: LDAP + TOTP authentication failure
«
Reply #20 on:
August 04, 2020, 09:25:15 am »
This is really crazy. Can you install 20.1 without any patches and try again?
Logged
WWW:
www.routerperformance.net
Support plans:
https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German):
https://opnsense.max-it.de/
CraigS
Newbie
Posts: 25
Karma: 2
Re: LDAP + TOTP authentication failure
«
Reply #21 on:
August 04, 2020, 10:06:21 pm »
Apologies mimugmail, my computer blew cpu or motherboard this morning, or I would have tested sooner.
Following your advice:
1. installed fresh 20.1-amd64 from iso on vmware esxi using freebsd 11 template
2. assigned ip addresses - wan + lan (not accessible from internet)
3. assigned port 4443 for admin portal (otherwise it clashes with ssl vpn) and set authentication servers as all local and ldap servers under System -> Settings -> Administration
4. added ldap cleartext server + authenticate successfully with Tester
5. imported 1x user (me), generated qr code and added to google authenticator
6. added ldap + totp cleartext server + authentication failed with Tester
No other modifications done at all.
OPNsense 20.1-amd64
FreeBSD 11.2-RELEASE-p16-HBSD
OpenSSL 1.1.1d 10 Sep 2019
«
Last Edit: August 04, 2020, 10:10:35 pm by CraigS
»
Logged
mimugmail
Hero Member
Posts: 6766
Karma: 494
Re: LDAP + TOTP authentication failure
«
Reply #22 on:
August 04, 2020, 10:23:10 pm »
No, you first add LDAP+totp server and AFTER this you import and create OTP token in user
Logged
WWW:
www.routerperformance.net
Support plans:
https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German):
https://opnsense.max-it.de/
CraigS
Newbie
Posts: 25
Karma: 2
Re: LDAP + TOTP authentication failure
«
Reply #23 on:
August 04, 2020, 10:33:37 pm »
I did not know the totp server must first be created before creating the qr codes.
I deleted the imported ldap user, re-saved the ldap+totp server (changed code position back to front), then imported user, created qr code, and tested.
Still auth failure.
We use Novell/Microfocus e-Directory for ldap in case it makes a difference...
OpenLDAP template gives the same result.
«
Last Edit: August 04, 2020, 10:52:17 pm by CraigS
»
Logged
CraigS
Newbie
Posts: 25
Karma: 2
Re: LDAP + TOTP authentication failure
«
Reply #24 on:
August 04, 2020, 11:06:15 pm »
Another test:
1. deleted the ldap-totp server and the imported ldap user.
2. created ldap+totp server
3. imported user
4. generated new secret
5. added qr code to google auth
6. auth fails in tester as before
Logged
CraigS
Newbie
Posts: 25
Karma: 2
Re: LDAP + TOTP authentication failure
«
Reply #25 on:
August 04, 2020, 11:21:28 pm »
mimugmail,
what opnsense version do you use with ldap+totp?
Perhaps I can try re-create your setup?
Logged
mimugmail
Hero Member
Posts: 6766
Karma: 494
Re: LDAP + TOTP authentication failure
«
Reply #26 on:
August 06, 2020, 11:12:19 am »
Like I said in github, I now successfully conntected on 21.1a and 20.1.6, the reason was a time difference of two minutes while grace period is one minute.
For the archives: When you use ldap+totp and you dont see LDAP traffic, your OTP verification already failed.
Logged
WWW:
www.routerperformance.net
Support plans:
https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German):
https://opnsense.max-it.de/
CraigS
Newbie
Posts: 25
Karma: 2
Re: LDAP + TOTP authentication failure
«
Reply #27 on:
August 06, 2020, 02:40:52 pm »
I have confirmed that the vpn server and my mobile with authenticator is 2 second out according to
https://time.is/
and our VMWare administrator confirmed that the physical host time is also correct.
So I start again. Just to confirm the sequence:
1. Install opnsense 20.1 and set ip addresses
2. Configure ldap+totp server
3. Import ldap user and create qr code
4. use Tester to verify login.
Logged
mimugmail
Hero Member
Posts: 6766
Karma: 494
Re: LDAP + TOTP authentication failure
«
Reply #28 on:
August 06, 2020, 03:37:41 pm »
Yep, so better tick reverse order to put the token OTP behind the AD password
Logged
WWW:
www.routerperformance.net
Support plans:
https://www.max-it.de/en/it-services/opnsense/
Commercial Plugins (German):
https://opnsense.max-it.de/
CraigS
Newbie
Posts: 25
Karma: 2
Re: LDAP + TOTP authentication failure
«
Reply #29 on:
August 06, 2020, 04:46:13 pm »
Installed clean 20.1 - same issue.
If totp was the problem would local+totp not also be broken?
Logged
Print
Pages:
1
[
2
]
3
« previous
next »
OPNsense Forum
»
Archive
»
20.1 Legacy Series
»
[Solved] LDAP + TOTP authentication failure