2020-08-17
05:49 AM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
ODA - Anyconnect auth works with initial PIN
Dear All,
Found an interesting issue during testing ODA authentication. We enabled ODA authentication for a user, configured inital PIN and we tested the auth.
The application that we used for testing is Anyconnect.
The issue that I found is that by replacing the initial pin with the one that the user configured, the authentication will be accepted and the Anyconnect connection will establish only using the PIN. This is does not work next time as it will send the SMS with the passcode.
Can we somehow limit that the PIN replacement/initial PIN change won't result in a successfully authentication?
Thank you in advance.
Best Regards,
Erik Molnar
- Tags:
- Community Thread
- Discussion
- Forum Thread
- Integration
- Integrations
- oda
- RSA SecurID
- RSA SecurID Access
- RSA SecurID Integration
- SecurID
0 Replies
