Our FreeIPA instance allows a user to bypass OTP even with "passowrd+otp" (only) enabled when his OTP token has expired or is deleted.
When a user's OTP has expired, he can log in with a single factor even when the account is explicitly set to ONLY "password+otp"
The user should not be able to log in without a second factor until the validity end date is extended or a new valid token is issued.
Our IPA servers are pretty much vanilla with OTP enabled.
Metadata Update from @frenaud: - Custom field rhbz adjusted to https://bugzilla.redhat.com/show_bug.cgi?id=2142587
Issue linked to bug 2142587
Metadata Update from @mreynolds: - Issue assigned to mreynolds
Metadata Update from @mreynolds: - Custom field rhbz adjusted to https://issues.redhat.com/browse/RHEL-4915 (was: https://bugzilla.redhat.com/show_bug.cgi?id=2142587)
Jira:
https://issues.redhat.com/browse/RHEL-4915
master:
ipa-4-12:
Metadata Update from @frenaud: - Issue close_status updated to: fixed - Issue status updated to: Closed (was: Open)
Metadata Update from @frenaud: - Custom field rhbz adjusted to https://issues.redhat.com/browse/RHEL-4915, https://issues.redhat.com/browse/RHEL-63325 (was: https://issues.redhat.com/browse/RHEL-4915)