By: Junhwan An user 29 Oct 2017 at 9:45 p.m. CDT

3 Responses
Junhwan An gravatar
Hello, I want to use MFA(TOTP) with SSO(SAML). I'm using Gluu Server as a SAML IDP and a SAML SP. SSO works well without MFA. I can login through 'https://<Gluu Server Host Name>' or 'https://<Gluu Server Host Name>/idp/profile/SAML2/Unsolicited/SSO?providerId=urn:xxx:xxx' directly. But MFA doesn't work with SSO, it only works with Gluu Server itself. When I login through 'https://<Gluu Server Host Name>', Gluu Server shows me a OTP login page, but when I login through 'https://<Gluu Server Host Name>/idp/profile/SAML2/Unsolicited/SSO?providerId=urn:xxx:xxx', it only shows me a basic authentication page. Of course I can use the Service Site with the basic authentication. I followed 'https://gluu.org/docs/ce/authn-guide/otp/' to apply MFA to my Gluu Server. For sure, if I login to 'https://<Gluu Server Host Name>' with MFA, I can move to 'https://<Gluu Server Host Name>/idp/profile/SAML2/Unsolicited/SSO?providerId=urn:xxx:xxx' freely with that session. But if I login to 'https://<Gluu Server Host Name>/idp/profile/SAML2/Unsolicited/SSO?providerId=urn:xxx:xxx' without MFA, I can use Service Site but I can't use Gluu Server itself. It shows me error page below: --------------------- Oops Something wrong happened. Login failed, oxTrust wasn't allow to access user data Return to the application using below button. --------------------- Thank you for your help.

By Mohib Zico staff 30 Oct 2017 at 12:39 a.m. CDT

Mohib Zico gravatar
Something similar like [this](https://github.com/GluuFederation/oxAuth/issues/659)?

By Junhwan An user 30 Oct 2017 at 6:51 a.m. CDT

Junhwan An gravatar
It looks like same issue and I checked the issue fixed for CE 3.1.2 Should I close this post now? (because I realize that the bug will be fixed in next release) or wait for next release? Thank you for your help.

By William Lowe user 30 Oct 2017 at 8:44 a.m. CDT

William Lowe gravatar
I'm going to close this issue out. You can subscribe to our newsletter to receive notifications about new releases. Thanks! Will