issue with M2F authentication action box

80 views
Skip to first unread message

Gaice Prince

unread,
May 17, 2024, 1:59:50 AMMay 17
to RCDevs Security
Dears,
I am testing OpenOTP with for M2F for VPN SSL .
After installation, Active Directory Server and  MF2 Authentication server registration , i am still missing the "M2F authentication action" box for Token registration .
Someone can help ?

Version : WebADM Freeware Edition v2.3.15


Capture d'écran 2024-05-16 150953.png
Capture d'écran 2024-05-16 151053.png

Benoît Jager (RCDevs)

unread,
May 17, 2024, 2:14:44 AMMay 17
to RCDevs Security
Hello,

You activated a group, so you will not get the MFA authentication action. For group, you will only get access to the Secure Password Reset and User Self-Registration.

Gaice Prince

unread,
May 17, 2024, 6:46:02 AMMay 17
to RCDevs Security
Hi Benoit,
thank for the reply, so what is the process to have  MFA authentication action ?

Benoît Jager (RCDevs)

unread,
May 17, 2024, 6:55:19 AMMay 17
to RCDevs Security
Hello,
MFA authentication action is available on user account. So just activate one of your user account (either of person and/or user objectclass). You can try with yours.

Here are our documentation on how to activate users:

Gaice Prince

unread,
May 17, 2024, 9:39:48 AMMay 17
to RCDevs Security
Hi ,
yes you are right , now i have "application action" box .
I will continue the config and test . 

Gaice Prince

unread,
May 20, 2024, 5:17:58 AMMay 20
to RCDevs Security
Hello ,
I'm still stuck in the configuration.
After clicking on register a token, I get an error message: "Could not find any user domain ."
 After some research on google this is caused to the lack of adding a domain name.
So i tried to add a domain but at each attempt i got in log "invalid domain ... (invalid LDAPDN setting)" 
below my config :
Container: OU=webadms,DC=ad,DC=supdeco,DC=local
User search base : CN=Users,DC=ad,DC=supdeco,DC=local

Someone can help please ?
DN1.png
DN2.png

Yoann Traut (RCDevs)

unread,
May 20, 2024, 5:20:35 AMMay 20
to RCDevs Security
Hello, 

Are you able to see your created domain from the WebADM GUI > Admin > Users Domains?
If no, can you try to clear the WebADM System caches from Admin tab and check again? 

Regards

Gaice Prince

unread,
May 21, 2024, 5:38:22 AMMay 21
to RCDevs Security
Hi ,
yes i can see the domain   from the WebADM GUI > Admin > Users Domains" .
It is also available in AD schema , in OU webadms  > Domains.
You can find all evidences in attach files .
weblog.png
DN4.png
DN3.png
DN5.png

Yoann Traut (RCDevs)

unread,
May 21, 2024, 5:51:27 AMMay 21
to RCDevs Security
Hello, 

Does the proxy_user (service account) defined in /opt/webadm/conf/webadm.conf has enough permissions to read the WebADM configuration container and sub containers? 
If you want to easily try our solutions with AD, the easiest way is to use a domain admin account for proxy_user and super_admin accounts. That way you don't have any permissions issue and you can test all features. 
If this is not possible, you have to setup AD ACLs according to what you want to do. ACLs are available here:

WebADM Super Administrators:
These permissions are involved when your are authenticated on the WebADM Admin Portal.

WebADM Proxy Account (service account)
These permissions are involved when your are authenticated on a Web Application or when using a Web Service like OpenOTP.  

Regards 

Gaice Prince

unread,
May 22, 2024, 4:04:11 AMMay 22
to RCDevs Security
Hello,
i am using a admin domain as proxy user .
Thank to note also after creation of domain i lost connection to WebADM till the deletion of the domain created early . 

in attach my config file . 

webadm.conf
DN6.png

Yoann Traut (RCDevs)

unread,
May 22, 2024, 5:09:01 AMMay 22
to RCDevs Security
Strange... your config seems to be fine and we are not able to reproduce your issue. 
Could we have a look remotely through Anydesk or Teamviewer to check what is wrong? 

Regards

Gaice Prince

unread,
May 24, 2024, 2:16:08 AMMay 24
to RCDevs Security
hello,
I just rebooted all the servers, and it works fine now. I'll continue the test.
Thanks

Reply all
Reply to author
Forward
0 new messages