By: Tomas Liljebergh user 14 Feb 2022 at 9:16 a.m. CST

6 Responses
Tomas Liljebergh gravatar
Using supergluu for MFA no longer work after update on supergluu. We have been using Gluu and supergluu for some time and its been working without problem but after the update on supergluu last week we cant use mfa to log in. If we use mfa/supergluu on an old enrollment we get "Fido U2F token response is invalid". If i remove the old enrollment and make a new it works to log in after doing the enrollment and scanning the qr-code but when i try the next time i get the same error, "Fido U2F token response is invalid". Since the update of supergluu we dont get any push notifications on the phone either. This problem is only on Android phones on different versions of Android and different brands of phones, ios/apple is working. I can see that the enrollment works as it is present on the account in gluu. ID Nickname Modality Date Added Remove 1644846882381 - Super-Gluu Device 14 Feb 2022 13:54:42 GMT We are using a group to decide who will get the MFA prompt. Any clue on where i should start my search for errors? As i mentioned above this worked until the update of supergluu last week. Regards Tomas

By Mohib Zico staff 14 Feb 2022 at 9:35 a.m. CST

Mohib Zico gravatar
Ok, looking into it.

By Tomas Liljebergh user 15 Feb 2022 at 4:24 a.m. CST

Tomas Liljebergh gravatar
I can add one comment, i found another phone that was not updated to supergluu 3.1.3 and with that phone mfa works fine. Actually the phone says it has version 3.1.4 ... but the one in google play store is 3.1.3 Sounds strange ..... /Tomas

By Justin Smith named 15 Feb 2022 at 9:51 a.m. CST

Justin Smith gravatar
@Mohib.Zico this is also happening to me. Just upgraded the app on android and I am getting this issue. App V3.1.3 I am having other users also experience the same issue.

By Christos Natsis user 15 Feb 2022 at 11:17 a.m. CST

Christos Natsis gravatar
We can confirm the issue too. All our Android devices were affected since yesterday.

By Tomas Liljebergh user 16 Feb 2022 at 6:18 a.m. CST

Tomas Liljebergh gravatar
New version downloaded. 4.3.2. Things works better. Users can now enroll and use MFA A few users dont get pushnotifications thou. And we cant have more then one key for an IDP per username, not a big problem but it worked in earlier verision of SuperGluu We can also see that keys stored in SuperGluu dont get any timestimes anymore. Anyhow, this was an improvement and most of it works.

By Justin Smith named 17 Feb 2022 at 12:12 p.m. CST

Justin Smith gravatar
My Keys are not being saved upon new registration within superglu. @Mohib.Zico