Bug 2228529 - [RFE] Second Factor prompts in IPA (password + OTP) are misleading. [NEEDINFO]
Summary: [RFE] Second Factor prompts in IPA (password + OTP) are misleading.
Keywords:
Status: NEW
Alias: None
Product: Red Hat Enterprise Linux 9
Classification: Red Hat
Component: sssd
Version: 9.2
Hardware: s390x
OS: Linux
unspecified
high
Target Milestone: rc
: ---
Assignee: sssd-maint
QA Contact: sssd-qe
URL:
Whiteboard:
Depends On:
Blocks:
TreeView+ depends on / blocked
 
Reported: 2023-08-02 14:35 UTC by Danish Shaikh
Modified: 2023-08-07 13:20 UTC (History)
5 users (show)

Fixed In Version:
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed:
Type: Bug
Target Upstream Version:
Embargoed:
atikhono: needinfo? (dshaikh)


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Issue Tracker RHELPLAN-164215 0 None None None 2023-08-02 14:37:52 UTC

Description Danish Shaikh 2023-08-02 14:35:39 UTC
Description of problem:

RHEL 9.2
ipa-server-4.10.1-8.el9_2.s390x


Second Factor prompts in (password + OTP) are misleading.

While the prompts would lead a user to enter the 2 factors in the separate prompts, they in fact needed to be entered in the first prompt only, or authentication failed." 


Actual results:

The ssh prompts look like:
 First Factor:
| Second Factor:
                 Send automatic password (Using keyboard-interactive authentication)


1. If I supplied the password+OTP to the first factor, and nothing to the second factor, I get in.

2. However If the password and OTP are supplied to separate Factor prompts, the login fails.

For the average user, the current prompting would be misleading.


Expected results:

There should only be a single prompt for password+OTP token.



Regards,
Danish Shaikh

Comment 2 Trivino 2023-08-07 12:29:50 UTC
I think this ticket is a duplicate of an old ticket:
https://github.com/SSSD/sssd/issues/4846

It was marked as wontfix, hence moving to sssd component for a re-evaluation.

Comment 3 Alexey Tikhonov 2023-08-07 13:20:39 UTC
> There should only be a single prompt for password+OTP token.

Please see `man sssd.conf`::PROMPTING CONFIGURATION SECTION::[prompting/2fa]::single_prompt

Would this work for your use case?


Note You need to log in before you can comment on or make changes to this bug.