Forum / Devolutions Password Server - Support

2FA with Google Authenticator doesn't work if the code is already 'red'

  • Create an Issue
  • Cancel

If I login with Google Authenticator (GA) and the code turns red (last 5 seconds of validity) it no longer works to login. I tested this while typing in the code when it was still valid longer, waited for it to turn red and immediately submitted the code and confirmed that it stops accepting the code as soon as it turns red. I have no technical knowledge about GA but from a functional perspective I know other applications to still accept 'red' codes and even accept a code for a few seconds after it renewed so there's probably some way to detect if a code is 'old but still valid'. Maybe that's not handled correctly?

Not a huge problem, of course, because you can simply wait 5 seconds and use the next code but still annoying... smile

Clock3 yrs

Hi,
That something we could verify. Thank you for the information.

Regards

David Hervieux

signaturesignature

Clock3 yrs

Hello,

What version of RDM are you using and what data source type are you connected to?
If you use Devolutions Server, what version is installed?

Sometimes with Google Authenticator, we can experience an issue when the time on your device and the time of your computer are not perfectly synchonized.

Best regards,



Érica Poirier

signaturesignature

Clock3 yrs

Hi Erica,

I am using RDM 12.5.6 against a Devolutions Server 4.0.7. The GA 2FA is the server side 2FA used when logging in to the server, not the client side 2FA. This issue has been around for at least a year now so I don't think it's something introduced in a newer version.

I see a server upgrade to 4.5.0.0 is available, just to make sure I'll upgrade and post back.

Bas

Clock3 yrs

Ok, 4.5.0.0 no longer seems to have the problem. If I use a 'red' code in the last second it still fails but that might be due to the extra time lost in communicating with the server but if I have 2 or 3 seconds left it still validates.

Thanks!

Bas

Clock3 yrs