apache / apache/cloudstack

DUO Authenticator returns a different number than Google and Microsoft for CloudStack's TOTP.

Aberta
#11,776 3 comentários 0 reações 0 responsáveis Ver no GitHub
status:needs-functional-definition
Linguagem predominante
Java
Estrelas
3.1k
Forks
1.4k
Merge médio
7d 14h
PRs com merge (30d)
31

Descrição

### problem

The title mentions DUO Authenticator because I want to stay consistent with the issue I already reported in DUO Security’s GitHub.

The problem occurs when setting up TOTP 2FA for a user in CloudStack. The QR code and seed work correctly in Google Authenticator, Microsoft Authenticator, and my password manager. However, DUO Authenticator generates the wrong rolling PIN (it looks out of sync).

Since the same QR code/seed works in four other apps, I believe this is a bug in DUO Authenticator. Still, since DUO is widely used as an enterprise-grade app, I wonder if CloudStack might be missing some information DUO needs when generating the TOTP.

Below are some sample TOTPs for a test user.

Revealing the Seed : LGV3KCWF3AFZKYB4MWSZBH3R6YWBINJI
QRCode content: otpauth://totp/Company:username?secret=LGV3KCWF3AFZKYB4MWSZBH3R6YWBINJI&issuer=Company

Revealing the Seed : 3JLPXCKBHYR3CHE73T7FNGBS5CDMQRBG
QRCode content: otpauth://totp/Company:username?secret=3JLPXCKBHYR3CHE73T7FNGBS5CDMQRBG&issuer=Company

### versions

ACS 4.20.1

### The steps to reproduce the bug

Setup TOTP on DUO and another app and compare the rolling PIN.

### What to do about it?

Maybe there are optional parameters that can be provided to the Authenticator app while scanning the QRCode that would inform some missing parameters that it fails to assume.

Guia de contribuição

Abrir o guia de contribuição

Direção de pesquisa

Comece reproduzindo a divergência com o conteúdo otpauth do QR code fornecido e a versão 4.20.1 do ACS listada, comparando o DUO com os outros autenticadores. Em seguida, rastreie a configuração de TOTP e a geração do QR code do CloudStack para determinar se há parâmetros obrigatórios ausentes ou se a incompatibilidade está no DUO. O trabalho estará concluído quando o lado responsável for identificado e o comportamento confirmado for documentado ou testado.

Escrita pelo modelo de indexação a partir do texto da issue.

Avaliação

Stack de tecnologia
java
Domínio
authentication
Tipo de issue
Bug
Dificuldade
4/5
Tempo estimado
3-5 dias
Status de atividade
Pouca atividade
Clareza
Precisa de esclarecimento
Facilidade para iniciantes
35/100

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.