An Issue with Google Authenticator MFA

28 views
Skip to first unread message

Umut Arus

unread,
Apr 7, 2020, 6:54:38 AM4/7/20
to cas-...@apereo.org, System Administrator
Hi,

We are getting an error on the below with version 5.3.2. I am adding the config. How can we fix the error?

Error:
----------------
2020-04-07 13:25:38,900 ERROR [org.apereo.cas.authentication.PolicyBasedAuthenticationManager] - <Authentication has failed. Credentials may be incorrect or CAS cannot find authentication handler that supports [OneTimeTokenCredential(token=552157)] of type [GoogleAuthenticatorTokenCredential]. Examine the configuration to ensure a method of authentication is defined and analyze CAS logs at DEBUG level to trace the authentication event.>

Config:
----------------
cas.properties

cas.authn.mfa.gauth.issuer=CAS
cas.authn.mfa.gauth.label=CASLabel
cas.authn.mfa.globalProviderId=mfa-gauth
cas.authn.mfa.globalFailureMode=CLOSED
cas.authn.mfa.gauth.issuer=TEST
cas.authn.mfa.gauth.codeDigits=6
cas.authn.mfa.gauth.timeStepSize=60
cas.authn.mfa.gauth.windowSize=3
cas.authn.mfa.gauth.label=TEST
cas.authn.mfa.gauth.rank=0
cas.authn.mfa.globalPrincipalAttributeNameTriggers=memberOf
cas.authn.mfa.globalPrincipalAttributeValueRegex=mfa-eligible

json file;

{
  "@class" : "org.apereo.cas.services.RegexRegisteredService",
  "serviceId" : "^(https|imaps)://.*",
  "id" : 100,
  "multifactorPolicy" : {
    "@class" : "org.apereo.cas.services.DefaultRegisteredServiceMultiactorPolicy",
    "bypassEnabled" : "false"
  }
}


--
UMUT ARUS
SİSTEM SORUMLUSU
SYSTEM SPECIALIST

Sabancı Üniversitesi
Üniversite Caddesi No:27
34956 Orta Mahalle
Tuzla - İstanbul
T   0 216 483 91 72
F   0 216 483 91 86
www.sabanciuniv.edu

Umut Arus

unread,
Apr 7, 2020, 12:41:22 PM4/7/20
to cas-...@apereo.org, System Administrator
Hi all

Or I would like to ask you to what the right configuration to make it work mfa with Google 

thank you so much
Reply all
Reply to author
Forward
0 new messages