0 vote
We are using RCDevs OpenOTP as a 2FA Authentication Server.
I managed to integrate 2FA with DPS via the Radius function.
RCdevs OpenOTP sends a push request to my mobile, I approve, and it works fine.
However, I have to be very quick for that, otherwise Radius Authentication will fail.
I would like to define a timeout for the radius auth in DPS, so we can take this in production.
Hello,
This improvement request is already on our todo list. The internal ticke number is DPS-2690. We cannot say when this improvement will be implemented as our task list for 2019 is already fully booked. Once an update will be available, I will post it here.
Best regards,
Érica Poirier
Hello Erica,
Thank you for the Information. So we go with the google auth scan codes for now, as they intergrate seamlessly in rcdevs client app, too.
Hello,
Our engineering team has made a fix that allows DPS to support Radius with 2FA. As it's an internal version and we do not have such Radius 2FA environment, is it possible for you to test that internal build in a staging environment on your side? If so, I will then send you a download link in a private message. It will be important to not deploy that version in production as it hasn't been fully tested by our QA team.
Best regards,
Érica Poirier
Hello Erica , Yes of course I would like to test that version on a production clone. Awaiting your PM. Thank you !
Hello,
The private message has been sent. Will wait for your feedback about this version.
Best regards,
Érica Poirier
Hello,
Have you tested the DPS version I sent you in private message? If so, is it working in your test environment or not?
Best regards,
Érica Poirier
Hello Erica,
sorry, we first have to set up a staging server. No time so far, due to urgent projects.
One mor week please.
Hello,
No problem about that. Let me know if you cannot download the files I sent you as the link normally expire after a specific period of time.
Best regards,
Érica Poirier
Hi Erica
What is the state on this topic?
We want to integrate DPS with Radius Azure MFA Extension.
Thanks
Hi Jannis,
What DVLS version are you using?
It should be supported in the latest DVLS version 2020.3.17. If you're not using that version, could you please give it a try? Let us know if you need assistance to upgrade your DVLS to that version.
It is possible that the Radius MFA authentication delay is not long enough to be able to complete the whole process. An internal ticket is already opened to improve the Radius delay process. Once the fix will be implemented, we will update this thread.
Best regards,
Érica Poirier
Hi Jannis,
Our latest internal DVLS version 2021.1.3 contains a new parameter to extend the timeout value to a custom value.
Are you interested to test that version in a staging environment? If so, please let me know and I will send you a download link in a private message.
Best regards,
Érica Poirier
Hi Erica
I managed to get the Radius Integration running.
Maybe an How-To from Devolutions would be nice for others to integrate Windows NPS with Azure extension.
The extended timeout window is something we will need in the future. Right now it is working when you log in fast.
Unfortunately we do not have time to test this new version in a staging enviroment.
In the configuration I got right now the users need to fill in there passwords two times.
Is it possible to discard the second password request? Because this is actually the same password as we authenticate with LDAPS.
Thanks
Hi Jannis,
Thank you for your feedback.
I will discuss with our documentation team for your request on an How-to article and will get back to you.
About the other request to discard the second password, I will verify this with the engineering team.
Best regards,
Érica Poirier
Hi Erica
So in 2021.1.7.0 it is possible to extend Timeout delay up to 50 seconds.
As suggested by Microsoft it should be at least 60 seconds. (https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-mfa-nps-extension)
Now every time I enter username & password it prompts for my 2FA Code. This is again my LDAP Password. Is it possibel to skip this window as I already entered my password in the authentication window at the beginning?
Thanks!
Hi Jannis,
Thank you for your feedback.
I have added a comment in the original ticket to increase the timeout value to 60 seconds.
About skipping the Radius prompt for the user's domain password, a ticket already exist and I will ask to bump up the priority on this improvement. Once an update will be available, I will post it in this thread.
Best regards,
Érica Poirier
Hi Janis,
For your information, the latest DVLS version 2021.1.9 has been improved and it is possible now to set the Radius timeout value up to 60 seconds.
Best regards,
Érica Poirier