#9825 2FA tokens not recognised on server
Closed: Fixed 3 years ago by mgrabovs. Opened 3 years ago by mgrabovs.

I've been having trouble with authentication on retrace03.rdu-cc.fedoraproject.org for the past week or so (at least). Specifically, I'm unable to use sudo for anything, e.g.

[mgrabovs@retrace03 ~][PROD]$ sudo -i
[sudo] password for mgrabovs:
Sorry, try again.
[sudo] password for mgrabovs:

I've tried entering the password + OTP several times over and over with the same result. I'm 100% sure the password is correct (it works everywhere where OTP is not required) so it must be the 2FA acting up.

I've also tried re-syncing the token via https://accounts.fedoraproject.org/otp/sync/ but with no luck. I just realised the Fedora Accounts OTP tokens are probably unrelated to the Fedora Infra 2FA (https://admin.fedoraproject.org/totpcgiprovision/) so scratch this.

I'm using the Google Authenticator app on an Android device. Other services (GitHub, GitLab, banking, etc.) work fine with the OTPs generated from the same app on the very same device, so it appears be an issue on the Fedora side.


All 2 factor was reset when we moved to the new account system. The old totpcgiprovision is no longer valid. Please try sudo without your 2 factor and see if that works. If it does you need to set up a new token on accounts.fedoraproject.org

Metadata Update from @smooge:
- Issue priority set to: Waiting on Assignee (was: Needs Review)
- Issue tagged with: authentication, medium-gain, medium-trouble, ops

3 years ago

Ah, sorry, I somehow missed the news. My mistake.

All seems to be working fine. Thanks for the update.

Metadata Update from @mgrabovs:
- Issue close_status updated to: Fixed
- Issue status updated to: Closed (was: Open)

3 years ago

Log in to comment on this ticket.

Metadata
Boards 1
ops Status: Done