Forum Discussion
JWhitesPro_1928
Cirrostratus
Jan 26, 2016OTP can be bypassed by refreshing on the OTP prompt page..
Has anyone ran into this issue?
On 11.6HF6
If you're at a step in your access policy of prompting for a OTP and the user just refreshes the browser, it bypasses everything else in the polic...
JWhitesPro_1928
Cirrostratus
Jan 26, 2016I think it may be a bug...as I said it doesn't happen on mobile devices--and in the logs I see this right before it goes on to allow the user through even though they typed nothing in.
modules/Authentication/OTP/OTPVerifyAgent.cpp func: "getOTPVerifyUserInput()" line: 149 Msg: 64d04990: OTP_VERIFY Agent: getOTPVerifyUserInput(): unable to decrypt user password due to invalid ciphertext
Michael_Koyfma1
Cirrus
Jan 26, 2016If you can please message me your ticket number with support, it would be great
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects