AWS - Microsoft ActiveDirectory // FreeRadius (Google MFA)

0

Hello,

I almost finish to setup my VPN with ActiveDirectory FreeRadius (MFA google authenticator), I have one issue .. I generated QR code for my Ad User and I scan it, when OpenVPN asking my OTP i have this following error

pam_winbind(google-authenticator:auth): request wbcLogonUser failed: WBC_ERR_AUTH_ERROR, PAM error: PAM_AUTH_ERR (7), NTSTATUS: NT_STATUS_LOGON_FAILURE, Error message was: The attempted logon is invalid. This is either due to a bad username or authentication information.

Enter image description here

So my password + otp isn't working

Inside/etc/pam.d/radiusd :

auth requisite /usr/lib/x86_64-linux-gnu/security/pam_google_authenticator.so forward_pass

auth required pam_unix.so use_first_pass

I am little bit lost... i double checked OTP code and its good, so why pam isn't connecting ?

Thanks

Alex
preguntada hace 4 meses149 visualizaciones
2 Respuestas
0

Does anyone have an idea ? I am completely stuck

Alex
respondido hace 3 meses
0

up ... I need help

Alex
respondido hace 3 meses

No has iniciado sesión. Iniciar sesión para publicar una respuesta.

Una buena respuesta responde claramente a la pregunta, proporciona comentarios constructivos y fomenta el crecimiento profesional en la persona que hace la pregunta.

Pautas para responder preguntas