Skip to content

Question: google-authenticator PAM module is not returning valid error codes #258

@raviteja-b

Description

@raviteja-b

pam_google_authenticator identifies different error cases but returns generic PAM_AUTH_ERR

when totp token is not passed then I noticed this trace and I see PAM_AUTH_ERR
pam_google_authenticator: Did not receive verification code from user

when invalid totp token is passed, I noticed this trace which says invalid token but still PAM_AUTH_ERR error returned.
pam_google_authenticator: Invalid verification code for testmfaadmin

pam_authenticate() should return PAM_CRED_INSUFFICIENT, If there is no token is provided

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions