Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Error message if no Azure MFA token is registered in Azure #505

Open
phavekes opened this issue Dec 1, 2024 · 0 comments
Open

Error message if no Azure MFA token is registered in Azure #505

phavekes opened this issue Dec 1, 2024 · 0 comments

Comments

@phavekes
Copy link
Member

phavekes commented Dec 1, 2024

This issue is imported from pivotal - Originaly created at Apr 9, 2020 by Peter Havekes

A user first needs to self-register a token in Azure, before connecting his Azure account to SSID. When he tries to connect his account when no token haf been self-registered in Azure, the ADFS responds with:

<samlp:Response 
    ID="_a8df6b1a-88ba-41ce-a398-7775eb7ce1fe" 
    Version="2.0" 
    IssueInstant="2020-04-09T07:12:49.256Z" 
    Destination="https://azuremfa.audit.surfsecureid.nl/saml/acs" 
    Consent="urn:oasis:names:tc:SAML:2.0:consent:unspecified" 
    InResponseTo="_853cf4762ded314cf4abbde8dcbe38406e7d432a0df074ea9ce111db9f36" 
    xmlns:samlp="urn:oasis:names:tc:SAML:2.0:protocol">
    <Issuer 
        xmlns="urn:oasis:names:tc:SAML:2.0:assertion">http://adfs.hartingcollege.nl/adfs/services/trust
    </Issuer>
    <ds:Signature 
        xmlns:ds="http://www.w3.org/2000/09/xmldsig#">
        <ds:SignedInfo>
            <ds:CanonicalizationMethod 
                Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#" />
            <ds:SignatureMethod 
                Algorithm="http://www.w3.org/2001/04/xmldsig-more#rsa-sha256" />
            <ds:Reference 
                URI="#_a8df6b1a-88ba-41ce-a398-7775eb7ce1fe">
                <ds:Transforms>
                    <ds:Transform 
                        Algorithm="http://www.w3.org/2000/09/xmldsig#enveloped-signature" />
                    <ds:Transform 
                        Algorithm="http://www.w3.org/2001/10/xml-exc-c14n#" />
                </ds:Transforms>
                <ds:DigestMethod 
                    Algorithm="http://www.w3.org/2001/04/xmlenc#sha256" />
                <ds:DigestValue>Yfx1cEdf2b4P4LlptQno/afjQK8jcCuasB/
                    2M9cega4=
                </ds:DigestValue>
            </ds:Reference>
        </ds:SignedInfo>
        <ds:SignatureValue>Ub2dPhTTM5gXjp46r7Ley27mJvSRRQzrj6q6hIXQtfN7wM4fLE+EBYQlT6yrq6hjCenatxh/sQRuxuErJRIL/ruvWgtcuLLw4jYO1cxTNyywqt+aYBcsK7KWFAzbNFyXZXF3/c2TnbKB+IS6Oo4cwb24LibBL86teMH0ol9Evfqa2QMpa9ZkGmt8dCBpdAC4dWKv49IY0ZHYjs/bLEdSpcd7m8ft/YPv+EvpvOq2nhefboLNC7b4pU0gEaT2/mGhHNi9gf1rBeNnvf1+
            TjmFxxlQq9yZLpWe8q7Ad1J2M0pZztjb4NoSRiOAvlju9kfszuUKBFgK3ouFT2MEWjObKQ==
        </ds:SignatureValue>
        <KeyInfo 
            xmlns="http://www.w3.org/2000/09/xmldsig#">
            <ds:X509Data>
                <ds:X509Certificate>MIIC6DCCAdCgAwIBAgIQO+pBPv/5hphJGrsG2mR3dzANBgkqhkiG9w0BAQsFADAwMS4wLAYDVQQDEyVBREZTIFNpZ25pbmcgLSBhZGZzLmhhcnRpbmdjb2xsZWdlLm5sMB4XDTE3MDcwNDEwMDA0NFoXDTIyMDcwMzEwMDA0NFowMDEuMCwGA1UEAxMlQURGUyBTaWduaW5nIC0gYWRmcy5oYXJ0aW5nY29sbGVnZS5ubDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAM+NoZ4mk887ocwuf25GUtoDMpkqvnqz5aq+BfV/+2DoEwZ6N+zUoLyzirQAok0tnx3wEY/1MNz0QdDtQYZCP7dn68+/Qgy25T+LljqI/O47qWqxLU9h/pL++kb7h0jMgqmzWz5prFvHQQgp1mPp1C++0+qY8LzPN70k749VRBDuvr3IAShNWgq8AHmvUP6uZnBFJ0hIhSsRhG3sbpYHsSW6OFPYDvn2in+kO6r6zUHXGd0WWdQkmahl2l/oA6EAAjuZ/ROkFJJ2zyDK+uLDHezB/QZv29y0q7GOZLCpC76nI0HuFUqUq+Y4QT4G3XG4qeTIEUUDtKYa369LiOrn9rECAwEAATANBgkqhkiG9w0BAQsFAAOCAQEAftNvegr05K3j6ypnmx9DB/ZiE8ddH9L96XwQUOl+qKdXhwwDJ0NgIPnyk+TMmdTZUKAOK90K1dYaJqZkuZGv++gqv4Gz5S3LCaTjNfe87ivVZjbFZ9/Cxngt69DMV9Eh7TD6mS2E9DiFM8BJt1m9SXmV9Yn5QWpeY+6shj7pAvdVufrPOPjoHepsYK1XbHsH/sAszFcA7m1ijAYsWHPxbOYQtPwcXf2F5fo2yRHUZDTHxKTSjySLhGBp+6pH2116R8+ECvIDf9E6yKPZI7arjzBfNkt+nvbxo33tudL7oy6a7bQKh/AoJA1IVSIkfmEQc+
                    QhehWw9jXjvOIIYHXYSQ==
                </ds:X509Certificate>
            </ds:X509Data>
        </KeyInfo>
    </ds:Signature>
    <samlp:Status>
        <samlp:StatusCode 
            Value="urn:oasis:names:tc:SAML:2.0:status:Responder" />
    </samlp:Status>
</samlp:Response>

And the gssp shows :

stepup.error.precondition_not_met.description
Foutcode	22037

If this occurs the user should be informed he first needs to self-register his token at Azure, before he can use it in SSID, This can be done on : https://aka.ms/MFASetup

@phavekes phavekes self-assigned this Dec 1, 2024
@phavekes phavekes added this to Stepup Dec 1, 2024
@github-project-automation github-project-automation bot moved this to New in Stepup Dec 1, 2024
@phavekes phavekes removed their assignment Dec 1, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
Status: New
Development

No branches or pull requests

1 participant