TOTP and sync

I am using privacyIDEA 2.2 with Apache2 on Ubuntu 14.04. I followed the
installation instructions here:
http://privacyidea.readthedocs.org/en/latest/installation/#install-ubuntu

I set up a TOTP auth token with the following parameters:
{ “count_auth”: “10”, “hashlib”: “sha256”, “timeShift”: “0”, “timeStep”:
“30”, “timeWindow”: “180” }

The problem is that none of my TOTP tokens work, and I can’t figure out how
to make the DEBUG setting work. I tried to set the PI_LOGLEVEL = 10 in
/etc/privacyidea/pi.cfg, but all I get are WARNING messages. That is
definitely the config file referenced by the wsgi: application =
create_app(config_name=“production”, config_file="/etc/privacyidea/pi.cfg")

When I try to resync the token, it returns false.

I see this in the logs occasionally: [2015-04-14
20:34:36,217][6571][140152141510400][WARNING][privacyidea.lib.tokens.totptoken:495]
a previous OTP value was used again! tokencounter: 0, presented counter -1
[2015-04

Any ideas what I am doing wrong? I thought it was perhaps a time
synchronization issue, but I am running NTP, and my timezone is set to UTC
on the system.

Thanks,
Travis

Q29udGVudC1UeXBlOiBhcHBsaWNhdGlvbi9wZ3Atc2lnbmF0dXJlOyBuYW1lPSJzaWduYXR1cmUu
YXNjIg0KQ29udGVudC1EZXNjcmlwdGlvbjogT3BlblBHUCBkaWdpdGFsIHNpZ25hdHVyZQ0KQ29u
dGVudC1EaXNwb3NpdGlvbjogYXR0YWNobWVudDsgZmlsZW5hbWU9InNpZ25hdHVyZS5hc2MiDQoN
Ci0tLS0tQkVHSU4gUEdQIFNJR05BVFVSRS0tLS0tDQpWZXJzaW9uOiBHbnVQRyB2MQ0KDQppUUlj
QkFFQkFnQUdCUUpWTGVrTkFBb0pFQkJoWkZVdWpZRkpzTVVRQUpnNHlOYmFKU2NycXNHNnNUbVVG
WFJ5DQpBQ3pXbEVadmJWMTkvRnNPWFB6dld5aXN6OW01VXpNeTZRRER2ZUtwejV2L3JSUmI0STMx
MElCQjhvVmthNkp5DQpSVFYrTks3eGMrQURETVpRdmdsR2lOT2tyVjlvdGI2MHdqdnN2SDd2WlE4
MHJiS1krbHFpZkpjdnVNenJEaHkxDQoyT1R3d0NSQ1J0RThRZGU4MVNmL29mMElBNWxpaFk1V3Zh
SkRKUG1oR1BKUncweXp3cnBTcmhkWUJ3dTVLdlpHDQpCbytjKy9Wb04ydTVib0w1bkZvM3dRWHZF
ekRRMHpmWTc5SEwyZ1lCSmthTWhLQmlra3RweHVJRldFSHlHR0lZDQozRTNPL3F5VXNVT0pYazlh
VkYwaFA5MnVWaHBBVk82QVUvRnNxcGlnN0xHMC85YktXMWVsMnBUMjc1L29EWDlFDQpiaEVsdytB
ZjNGbEhQanlWRkJSakJ5QWNmamUzUmdyYzRSdkdpRHFIYWxkSTNRN1QxMk5oS0MveGQvY0NoM2tO
DQpucTdXV1c5Zzc3aGRhdFlFZ0VYd0RNblNjNjlFN1l0V0hrTnhKeUhLbHhxMEJhRHhSZzBuMFp5
OFJOUEt2WGJvDQpaRWU5RUhhR3I1cVV1blpSNW1JNHU4STU5TFgzN1dQeW5GYW05KzFlUzVzWXh3
YlJyaHUzTDJ6ZTNNRFNmYTVXDQovUTQ1R1RVSW1XN0lLdmRWS20zTjIxdXRQVXhLaWlzQWtRc3Ry
cjR3OTRsb0xDRXhjVFFDN2RRMVlZOU94NSttDQp3ajJHVlVTNGNGRkEwSnZWQzYvbjE1S2I1OThi
Q3pFS0RpTDJmR0xoOTJkeEIwWVNWbENJM3NTOHVOYW5sWkd6DQpxaXNTVWJTeEt5enVaTU5tY2cy
RA0KPWNxMk0NCi0tLS0tRU5EIFBHUCBTSUdOQVRVUkUtLS0tLQ0K

Q29udGVudC1UeXBlOiBhcHBsaWNhdGlvbi9wZ3Atc2lnbmF0dXJlOyBuYW1lPSJzaWduYXR1cmUu
YXNjIg0KQ29udGVudC1EZXNjcmlwdGlvbjogT3BlblBHUCBkaWdpdGFsIHNpZ25hdHVyZQ0KQ29u
dGVudC1EaXNwb3NpdGlvbjogYXR0YWNobWVudDsgZmlsZW5hbWU9InNpZ25hdHVyZS5hc2MiDQoN
Ci0tLS0tQkVHSU4gUEdQIFNJR05BVFVSRS0tLS0tDQpWZXJzaW9uOiBHbnVQRyB2MQ0KDQppUUlj
QkFFQkFnQUdCUUpWTGxYN0FBb0pFQkJoWkZVdWpZRkoyWTRQL0E4REhHM0hRNStGdFprSHpBVDR5
QmRhDQp4L21qQkhoZy91UEM4emdBUE95cyt3WmJ0NXpqY21SczNoWnBoM2dBMVlYdEdJRjhTQ3Q3
UmgyZkh2Vkx3NXNJDQpaa1VjMkpOa3h5emlya0lpUkJvemdaQ0tlNXloZ3N4Mkx3TkVOWEpCeDNX
cHg1bXNjVm11V291OEoyN2MySFpUDQpFVjUyaklML29iYTBHYXNveDdHd1kwdnIyZTVsbU5LeW1j
TWFLQWFaYjh5akRkckRrenR0UDJqMC9xVCtSWkpTDQpsNzJ2R095bnZTVmNFQVd5OHNvWTgvRlFm
a045b1kvOTNQbUlud0hKTmJqdUprWDNtZXd6cGViWFE3ZFFHUDh1DQpGN1VsNE9rL1ZDbWtCUFRj
UGNYcnBPaklHRHZDZG5jWjk3Z3JQb2RFU3pYUFVIdEZYWjZjWjdBRjVQaTltVWdhDQowKzN5aFY2
MGVUdGtrTmZvUHVUVVFLei9KWE1QZFRIUzZQU3NZRFpTRVk1RXhEL05TRGFERm1keHhwZ09vcTFX
DQpKZG5PQ0h0ZExBQmdEcjRud2tYUEJTc2htMjZCcFpaUG1WSnc4akZxV2wydXYvWis4VVZQNXdC
Tkk1TDlGMHJrDQpnUWpmM1BWZmtvRUZ2djRWNXMxeXlIUVF1bFduR0l1N1Yvb1J1Z3orQnVZdFQ0
Z1RWZ0FaaTVmNjR4VU9tZnNNDQpUeFJqSEdlMVJvU3lNSHQ1T2x1Y0RZSm5YL0dyc1hpaWUrem0w
ZXlYZFViRnJWUDV0a0FBbTBwUUJVMmdLY25MDQo2Sm1kNHR4SVNwdkFDSWFSeFVYRG5Zc3dIMGNj
SUptTzdURXUxdnN5Wis5dFR4aHdDeE1ray93RVBQaHRLejUwDQpha0M1UTA2R2ZkU2pRQVphTkJJ
NA0KPWNmYlINCi0tLS0tRU5EIFBHUCBTSUdOQVRVUkUtLS0tLQ0K

Hi Cornelius,

I am using Google Authenticator on an iphone. Sure enough, the issue was with the wrong hash algorithm. SHA1 works great. Thank you very much for you time and a very nice software package!

Cheers,
TravisOn Apr 15, 2015, at 12:29 AM, Cornelius Kölbel <cornelius.koelbel@netknights.itmailto:cornelius.koelbel@netknights.it> wrote:

Hello Travis,

what kind of Tokens are you using? Keyfob or Smartphone?

There are two parameters, that can lead to problems:

hashlib: Most keyfob tokens and also Google Authenticator e. al. are using sha1 hash algorithm. Unfortunately you can not change (except in the database) the hash algo, so you need to reenroll the token.

timeStep: Some keyfob tokens are using 60 seconds, not 30.

So I assume you are running the wrong hash algo.

Kind regards
Cornelius

Am 14.04.2015 um 22:44 schrieb Travis Brown:
I am using privacyIDEA 2.2 with Apache2 on Ubuntu 14.04. I followed the installation instructions here: http://privacyidea.readthedocs.org/en/latest/installation/#install-ubuntu

I set up a TOTP auth token with the following parameters:
{ “count_auth”: “10”, “hashlib”: “sha256”, “timeShift”: “0”, “timeStep”: “30”, “timeWindow”: “180” }

The problem is that none of my TOTP tokens work, and I can’t figure out how to make the DEBUG setting work. I tried to set the PI_LOGLEVEL = 10 in /etc/privacyidea/pi.cfg, but all I get are WARNING messages. That is definitely the config file referenced by the wsgi: application = create_app(config_name=“production”, config_file="/etc/privacyidea/pi.cfg")

When I try to resync the token, it returns false.

I see this in the logs occasionally: [2015-04-14 20:34:36,217][6571][140152141510400][WARNING][privacyidea.lib.tokens.totptoken:495] a previous OTP value was used again! tokencounter: 0, presented counter -1
[2015-04

Any ideas what I am doing wrong? I thought it was perhaps a time synchronization issue, but I am running NTP, and my timezone is set to UTC on the system.

Thanks,
Travis


You received this message because you are subscribed to the Google Groups “privacyidea” group.
To unsubscribe from this group and stop receiving emails from it, send an email to privacyidea+unsubscribe@googlegroups.commailto:privacyidea+unsubscribe@googlegroups.com.
To post to this group, send email to privacyidea@googlegroups.commailto:privacyidea@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/privacyidea/6cd3a92f-0a38-4657-860f-da318ecf9f72%40googlegroups.comhttps://groups.google.com/d/msgid/privacyidea/6cd3a92f-0a38-4657-860f-da318ecf9f72%40googlegroups.com?utm_medium=email&utm_source=footer.
For more options, visit https://groups.google.com/d/optout.


Cornelius Kölbel
cornelius.koelbel@netknights.itmailto:cornelius.koelbel@netknights.it
+49 151 2960 1417

NetKnights GmbH
http://www.netknights.ithttp://www.netknights.it/
Landgraf-Karl-Str. 19, 34131 Kassel, Germany
Tel: +49 561 3166797, Fax: +49 561 3166798

Amtsgericht Kassel, HRB 16405
Geschäftsführer: Cornelius Kölbel


You received this message because you are subscribed to the Google Groups “privacyidea” group.
To unsubscribe from this group and stop receiving emails from it, send an email to privacyidea+unsubscribe@googlegroups.commailto:privacyidea+unsubscribe@googlegroups.com.
To post to this group, send email to privacyidea@googlegroups.commailto:privacyidea@googlegroups.com.
To view this discussion on the web visit https://groups.google.com/d/msgid/privacyidea/552DE90D.6030606%40netknights.ithttps://groups.google.com/d/msgid/privacyidea/552DE90D.6030606%40netknights.it?utm_medium=email&utm_source=footer.
For more options, visit https://groups.google.com/d/optout.