IBM Security Z Security

 View Only
  • 1.  Using MFA on z/OS - problems with external bits.

    IBM Champion
    Posted Sun January 07, 2024 12:08 PM

    I'm trying to get MFA (2.2) on z/OS working (on zPDT).
    If I use the IBM Security Verify  app - it works.   If I use Google Authenticator or  Duo  Mobile apps the generated code is not accepted.  Is this a known problem or is it a set up problem?

    I purchased a Yubikey 5 NFC because some of the Yubico web pages says it supports OTP.  The key only seems to have FIDO2 support, and I cannot get it to work and produce One Time Passwords.   Is there a recommended Yubico key which works?  I'm running on Ubuntu Linux.

    Colin



    ------------------------------
    Colin Paice
    ------------------------------


  • 2.  RE: Using MFA on z/OS - problems with external bits.

    Posted Mon January 15, 2024 01:56 AM

    Hi Colin.

    I have experienced something similar when I was testing zMFA and the TOTP factor in combination with various apps. The QR code generated by zMFA contains information that is derived from either the default factor settings or the users factor settings. This includes the digest algorithm, the token code length and the token period. An app may not have implemented support for these settings, and may choose to override the information in the QR code and simply use defaults set by the app. In that case, you may experience that token codes generated from one app are working, whereas token codes generated by other apps are not.
    Something similar may be the case with other types of one time passwords.

    Best regards
    Mikael Rasmussen



    ------------------------------
    Mikael Rasmussen
    Senior Mainframe Security Engineer
    Danske Bank
    Brabrand
    +4540766221
    ------------------------------



  • 3.  RE: Using MFA on z/OS - problems with external bits.

    IBM Champion
    Posted Mon January 15, 2024 10:52 AM

    Thank you ...I found a combination which worked!



    ------------------------------
    Colin Paice
    ------------------------------