I'm having an issue where users who were previously enrolled in OTP (and had it enforced) which then were removed from OTP and have no tokens are still prompted for "First Factor/Second Factor". Up until recently this has been an inconvenience as a user could just leave the field blank and it would authenticate; they would only have to wait for IPA to process the non-existent OTP token.
Recently I've ran across an application which doesnt support OTP prompting at all, and the fact that users are getting prompted for First/Second factor breaks the application. While I do have a github issue in with the project to properly support OTP, there should be some way to disable the MFA prompt that users are getting (via PAM/SSSD?) given we're no longer using it. Any thoughts as to where I should look? There's a fair amount of documentation on how to enable it, less so on disabling it. Thanks in advance! Regards, Mike _______________________________________________ FreeIPA-users mailing list -- [email protected] To unsubscribe send an email to [email protected] Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/ List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedorahosted.org/archives/list/[email protected]
