I'm having an issue where users who were previously enrolled in OTP (and had it 
enforced) which then were removed from OTP and have no tokens are still 
prompted for "First Factor/Second Factor".  Up until recently this has been an 
inconvenience as a user could just leave the field blank and it would 
authenticate; they would only have to wait for IPA to process the non-existent 
OTP token.  

Recently I've ran across an application which doesnt support OTP prompting at 
all, and the fact that users are getting prompted for First/Second factor 
breaks the application.  While I do have a github issue in with the project to 
properly support OTP, there should be some way to disable the MFA prompt that 
users are getting (via PAM/SSSD?) given we're no longer using it.  Any thoughts 
as to where I should look?  There's a fair amount of documentation on how to 
enable it, less so on disabling it.  Thanks in advance!

Regards,
Mike
_______________________________________________
FreeIPA-users mailing list -- [email protected]
To unsubscribe send an email to [email protected]
Fedora Code of Conduct: 
https://docs.fedoraproject.org/en-US/project/code-of-conduct/
List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines
List Archives: 
https://lists.fedorahosted.org/archives/list/[email protected]

Reply via email to