whitelist issue on open otp credential provider windows setup

29 views
Skip to first unread message

Imani Uerlings

unread,
Sep 15, 2025, 3:48:31 AMSep 15
to RCDevs Security
Hi Guys,

We have the solution working with active directory integration, but come across 2 issues.

1 is whilst installing open otp credential provider on a windows VM, and having administrator group / administrators "whitelisted" from OTP, and having these administrator not "activated" in webadm, its impossible to login:

[2025-09-14 17:21:36] [192.168.255.211:49869] [OpenOTP:34KTB7RC] New openotpSimpleLogin SOAP request
[2025-09-14 17:21:36] [192.168.255.211:49869] [OpenOTP:34KTB7RC] > Username: pi...@majorlynx.com
[2025-09-14 17:21:36] [192.168.255.211:49869] [OpenOTP:34KTB7RC] > Password: xxxxxxxxxxxxxxxx
[2025-09-14 17:21:36] [192.168.255.211:49869] [OpenOTP:34KTB7RC] > Source IP: fe80:0000:0000:0000:785a:ea7f:77ef:ba0b
[2025-09-14 17:21:36] [192.168.255.211:49869] [OpenOTP:34KTB7RC] > Context: pSTzkb5GJIvfkIgIEhuMHOU74FtgIdzl
[2025-09-14 17:21:36] [192.168.255.211:49869] [OpenOTP:34KTB7RC] > Options: NOVOICE,RECORD,REGURL
[2025-09-14 17:21:36] [192.168.255.211:49869] [OpenOTP:34KTB7RC] > Virtual: preferredLanguage=EN
[2025-09-14 17:21:36] [192.168.255.211:49869] [OpenOTP:34KTB7RC] Registered openotpSimpleLogin request
[2025-09-14 17:21:36] [192.168.255.211:49869] [OpenOTP:34KTB7RC] User invalid or not found
[2025-09-14 17:21:36] [192.168.255.211:49869] [OpenOTP:34KTB7RC] Sent failure response

when the user is activated (domain admin)  in webadm then login works, but I guess since it's whitelisted it shouldn't have to activate the domain admin user in webadm right? because every "activated" used must also be paid license wise?


Spyridon Gouliarmis (RCDevs)

unread,
Sep 15, 2025, 3:51:52 AMSep 15
to RCDevs Security

Hello Imani,

if WebADM is receiving the request at all, it means the whitelisting has not worked. Either it's a bug, or you haven't put the right SID(s) in the white list.

Have you tried adding the exact SID of the user, not just one of its groups?
Reply all
Reply to author
Forward
0 new messages