apache / apache/cloudstack

DUO Authenticator returns a different number than Google and Microsoft for CloudStack's TOTP.

Aperta
#11,776 3 commenti 0 reazioni 0 assegnatari Vedi su GitHub
status:needs-functional-definition
Lingua principale
Java
Stelle
3.1k
Fork
1.4k
Merge medio
6g 19h
PR unite (30g)
32

Descrizione

### problem

The title mentions DUO Authenticator because I want to stay consistent with the issue I already reported in DUO Security’s GitHub.

The problem occurs when setting up TOTP 2FA for a user in CloudStack. The QR code and seed work correctly in Google Authenticator, Microsoft Authenticator, and my password manager. However, DUO Authenticator generates the wrong rolling PIN (it looks out of sync).

Since the same QR code/seed works in four other apps, I believe this is a bug in DUO Authenticator. Still, since DUO is widely used as an enterprise-grade app, I wonder if CloudStack might be missing some information DUO needs when generating the TOTP.

Below are some sample TOTPs for a test user.

Revealing the Seed : LGV3KCWF3AFZKYB4MWSZBH3R6YWBINJI
QRCode content: otpauth://totp/Company:username?secret=LGV3KCWF3AFZKYB4MWSZBH3R6YWBINJI&issuer=Company

Revealing the Seed : 3JLPXCKBHYR3CHE73T7FNGBS5CDMQRBG
QRCode content: otpauth://totp/Company:username?secret=3JLPXCKBHYR3CHE73T7FNGBS5CDMQRBG&issuer=Company

### versions

ACS 4.20.1

### The steps to reproduce the bug

Setup TOTP on DUO and another app and compare the rolling PIN.

### What to do about it?

Maybe there are optional parameters that can be provided to the Authenticator app while scanning the QRCode that would inform some missing parameters that it fails to assume.

Guida per i contributori

Apri la guida per i contributori

Direzione di ricerca

Inizia riproducendo la discrepanza con il contenuto otpauth del codice QR fornito e la versione 4.20.1 di ACS indicata, confrontando DUO con gli altri autenticati. Quindi analizza la configurazione TOTP e la generazione del codice QR di CloudStack per determinare se mancano parametri obbligatori o se l’incompatibilità è in DUO. Il lavoro è completato quando è stata identificata la parte responsabile e il comportamento confermato è stato documentato o testato.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Stack tecnologico
java
Ambito
authentication
Tipo di issue
Bug
Difficoltà
4/5
Tempo stimato
3-5 giorni
Stato di attività
Tranquilla
Chiarezza
Da chiarire
Idoneità per principianti
35/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.