Hello,
If I understand correctly, your issue is as follows:
You are authenticating on the Windows machine using the RCDevs Credential Provider, and then the VPN should automatically connect by reusing the credentials from the Windows session. Is that correct?
Could you clarify the following:
Which version of the Credential Provider is running on your Windows clients?
In which format is the username provided? For example: Username, DOMAIN\Username, or us...@domain.com?
Hi,
I connect via Microsoft win 11 vpn like described with ldap username – no domain\ or no @domain
Carsten Rønne
--
You received this message because you are subscribed to the Google Groups "RCDevs Security" group.
To unsubscribe from this group and stop receiving emails from it, send an email to rcdevs-technic...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/rcdevs-technical/8faf1651-7785-4618-89a6-3795bce08155n%40googlegroups.com.
So our Credential Provider is not involved in opening the Windows session, correct?
How is your Windows VPN integrated with our solution? Through RADIUS, I assume?
Ok.
When it fails on the Windows side, does the authentication request reach the WebADM/OpenOTP server?
Regards
Yes, ms vpn – AD server with NPS – webadm -
Carsten Rønne – Sysadmin TeamLead
Alipes Capital ApS
Orientkaj 4, 1. 2150 Nordhavn
To view this discussion visit https://groups.google.com/d/msgid/rcdevs-technical/6e7048c0-0cd2-44df-870a-06aee8cdfac0n%40googlegroups.com.
This looks like an OpenOTP session ID, but we do not have access to your logs, so I cannot check this on your behalf :)
If the session ID is 2C3N9AE9, please provide the output of the following command:
cat /opt/webadm/logs/webadm.log | grep 2C3N9AE9 -A 50 -B 50
I need the logs immediately before and after the failure on the Windows side to understand what happens on the backend.
It is possible that short NPS RADIUS timeouts trigger request retries, and OpenOTP then rejects them because the account is already in a transaction. This typically produces a log entry such as:
User under transaction (retrying user lock in 1 second)
Do you see this in your logs for authentications originating from NPS?
Regards
Or 2C3N9AE9
--
You received this message because you are subscribed to a topic in the Google Groups "RCDevs Security" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/rcdevs-technical/74hfzBKnWQ8/unsubscribe.
To unsubscribe from this group and all its topics, send an email to rcdevs-technic...@googlegroups.com.
To view this discussion visit https://groups.google.com/d/msgid/rcdevs-technical/9edba937-6289-4c8b-9a76-c3e0fd311b85n%40googlegroups.com.
Nps timeout is after 70 sec. webadm timeout is 60 sec.
To view this discussion visit https://groups.google.com/d/msgid/rcdevs-technical/f6b346b1-7168-4e29-b167-f0df6718c55bn%40googlegroups.com.
Den 21. nov. 2025 kl. 14.56 skrev 'Yoann Traut (RCDevs)' via RCDevs Security <rcdevs-t...@googlegroups.com>:
Ok, thank you for this info.
To view this discussion visit https://groups.google.com/d/msgid/rcdevs-technical/bc7da75d-998a-4820-a2ef-e8bcdb375bc5n%40googlegroups.com.
Hi,
This was the first attempt today.
We have a little luck when syncing the token time from the app to start with. So perhaps this is some to do with the time.
Carsten Rønne – Sysadmin TeamLead
Alipes Capital ApS
Orientkaj 4, 1. 2150 Nordhavn

To view this discussion visit https://groups.google.com/d/msgid/rcdevs-technical/7c7876bb-cc5e-48dd-bd63-1d9683e2c25fn%40googlegroups.com.
This was the first attempt today.
We have a little luck when syncing the token time from the app to start with. So perhaps this is some to do with the time.
seems it send 2:
New openotpSimpleLogin SOAP request
New openotpSimpleLogin SOAP request
Carsten Rønne – Sysadmin TeamLead
Alipes Capital ApS
Orientkaj 4, 1. 2150 Nordhavn

From: 'Spyridon Gouliarmis (RCDevs)' via RCDevs Security <rcdevs-t...@googlegroups.com>
Sent: 25. november 2025 10:26
To view this discussion visit https://groups.google.com/d/msgid/rcdevs-technical/7c7876bb-cc5e-48dd-bd63-1d9683e2c25fn%40googlegroups.com.
Den 25. nov. 2025 kl. 15.28 skrev carsten...@alipescapital.com:
This was the first attempt today.
We have a little luck when syncing the token time from the app to start with. So perhaps this is some to do with the time.
seems it send 2:
New openotpSimpleLogin SOAP requestNew openotpSimpleLogin SOAP request
Carsten Rønne – Sysadmin TeamLead
Alipes Capital ApS
Orientkaj 4, 1. 2150 Nordhavn
To view this discussion visit https://groups.google.com/d/msgid/rcdevs-technical/031e01dc5e0d%24f3ba2240%24db2e66c0%24%40alipescapital.com.
Den 26. nov. 2025 kl. 18.30 skrev Carsten Rønne <carsten...@alipescapital.com>:
Time was correct and latency / out of sync is very low.