IBM Security Z Security

 View Only
  • 1.  zMFA Totp error .....incomprhensible

    Posted Mon December 20, 2021 11:10 AM
    During the first Generic OTP user enrollement using App Verify I receive this error:

    AZF5040I Entered preflight (ic=1XID114EYCPCE9EJMAEWJJGDT5LECHUA, tc=877299)
    AZF5042E Preflight failed to match the provided token code
    AZF5043I If using a short PERIOD value, try increasing WINDOW to reduce clock skew effects

    The user has the following tags:
    MULTIFACTOR AUTHENTICATION INFORMATION:
    ---------------------------------------
    PASSWORD FALLBACK IS NOT ALLOWED
    FACTOR = AZFTOTP1
    STATUS = INACTIVE
    FACTOR TAGS =
    REGSTATE:OPEN
    PERIOD:60


    Any idea ?

    ------------------------------
    Luigi Perrone
    ------------------------------


  • 2.  RE: zMFA Totp error .....incomprhensible

    Posted Tue December 21, 2021 09:34 AM

    There are two possibilities:

    1. The issues described in this article:

    https://labanskoller.se/blog/2019/07/11/many-common-mobile-authenticator-apps-accept-qr-codes-for-modes-they-dont-support/

    1. The clock on the demo system and/or the client device is significantly off.


    ------------------------------
    ANTON NIEMAND
    ------------------------------



  • 3.  RE: zMFA Totp error .....incomprhensible

    Posted Tue December 21, 2021 10:50 AM
    Tks Anton.
    The first point is excluded, because I've tried with different client Apps (Google, Verify, DUO) using different ALG settings
    In the second point, there is a difference of 1 minute between the two values

    ------------------------------
    Luigi Perrone
    ------------------------------