Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-30588

[RFE] allows plugins to log multi-factor authentication notification

    • Icon: Story Story
    • Resolution: Done-Errata
    • Icon: Undefined Undefined
    • rhel-9.4.z
    • rhel-9.4
    • 389-ds-base
    • None
    • 389-ds-base-2.4.5-6.el9_4
    • Medium
    • 0day
    • Customer Escalated
    • rhel-sst-idm-ds
    • ssg_idm
    • 0
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None

      Goals

      • allows a plugin to log, in access and security logs, the fact that an operation (bind) is done with multi-factor authentication

      Acceptance Criteria

      A list of verification conditions, successful functional tests, or expected outcomes in order to declare this story/task successfully completed.

      • The expected behavior is described in this design
      • When a user entry requires OTP token and OTP plugin (IDM) is properly configured (EnforceLDAPOTP)
        • if access logs are enabled, then a BIND result contains
          notes=M details="Multi-factor Authentication"
        • if security logs are enabled the BIND_METHOD contains
          "SIMPLE\/MFA"

              spichugi@redhat.com Simon Pichugin
              tbordaz@redhat.com Thierry Bordaz
              IdM DS Dev IdM DS Dev
              IdM DS QE IdM DS QE
              Votes:
              0 Vote for this issue
              Watchers:
              6 Start watching this issue

                Created:
                Updated:
                Resolved: