Skip to content

[v12] fix: Verify MFA device locks during authentication#36629

Merged
codingllama merged 3 commits intobranch/v12from
codingllama/backport/36471-v12
Jan 15, 2024
Merged

[v12] fix: Verify MFA device locks during authentication#36629
codingllama merged 3 commits intobranch/v12from
codingllama/backport/36471-v12

Conversation

@codingllama
Copy link
Copy Markdown
Contributor

Backport #36471 to branch/v12.

Fix an oversight on authentication where locked MFA devices could still be used. Applies to password changes as well.

https://github.com/gravitational/security-findings/issues/81

Changelog: Verify MFA device locks during user authentication

* Test authn and password change with a locked user

* Verify MFA device locks during authentication

* Configure a LockWatcher in the passwordSuite setup

* Appease linter
@codingllama
Copy link
Copy Markdown
Contributor Author

Same remarks as #36627 (comment). Commits with v12-exclusive changes are a520ae2 and f9c93ad.

@codingllama codingllama added this pull request to the merge queue Jan 15, 2024
@github-merge-queue github-merge-queue Bot removed this pull request from the merge queue due to failed status checks Jan 15, 2024
@codingllama codingllama added this pull request to the merge queue Jan 15, 2024
Merged via the queue into branch/v12 with commit 150d090 Jan 15, 2024
@codingllama codingllama deleted the codingllama/backport/36471-v12 branch January 15, 2024 14:06
@camscale camscale mentioned this pull request Feb 6, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants