Google Authenticator with user PIN

3,411 views
Skip to first unread message

Sagi Bar-Or

unread,
Dec 21, 2017, 9:09:47 AM12/21/17
to RCDevs Security Solutions - Technical
Does anybody know if I can accomplish a local PIN with Google Authenticator? I don't see this option in in the client, but maybe something like that can be accomplished with  the OpenOTP server. 

Explanation about the local PIN feature:  
It is a feature of RSA SecurID. 
The user defines a PIN code (typically 4 digits). 
The password is compounded of user (static) PIN plus the time-based OTP.
This feature makes the local pwd generator two-factor authentication. The user PIN is something you know, and the time based pwd is the something you have. 

francois...@rcdevs.com

unread,
Dec 22, 2017, 2:43:37 AM12/22/17
to RCDevs Security Solutions - Technical
Hi Sagi

For Google Authenticator I don't know, but with OpenOTP app yes you can protect it with a PIN.

francois...@rcdevs.com

unread,
Dec 22, 2017, 2:58:41 AM12/22/17
to RCDevs Security Solutions - Technical
The PIN with openOTP app is only for opening the app and access to the OTP password, but you can also define a different PIN on the server :
webadm > select the user > webadm settings configure > openotp > openotp pin prefix :yes ( you can define it per group, per client policy or globally) 
webadm > select the user > MFA authentication server > Manage OTP PIN Prefix > set the PIN
This PIN should be concatenate each time with the OTP password and works also with Google Authenticator

Sagi Bar-Or

unread,
Dec 24, 2017, 10:33:18 AM12/24/17
to rcdevs-t...@googlegroups.com
Thank you Francois for the gr8 and informative response

--
You received this message because you are subscribed to a topic in the Google Groups "RCDevs Security Solutions - Technical" group.
To unsubscribe from this topic, visit https://groups.google.com/d/topic/rcdevs-technical/Vf35iTq-grM/unsubscribe.
To unsubscribe from this group and all its topics, send an email to rcdevs-technical+unsubscribe@googlegroups.com.
To post to this group, send email to rcdevs-technical@googlegroups.com.
Visit this group at https://groups.google.com/group/rcdevs-technical.
For more options, visit https://groups.google.com/d/optout.

Reply all
Reply to author
Forward
0 new messages