<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
    xmlns:content="http://purl.org/rss/1.0/modules/content/"
    xmlns:dc="http://purl.org/dc/elements/1.1/"
    xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
        <title>General — multiOTP open source forum</title>
        <link>https://forum.multiotp.net/index.php?p=/</link>
        <pubDate>Tue, 10 Mar 2026 15:07:40 +0000</pubDate>
        <language>en</language>
            <description>General — multiOTP open source forum</description>
    <atom:link href="https://forum.multiotp.net/index.php?p=/categories/general/feed.rss" rel="self" type="application/rss+xml"/>
    <item>
        <title>Error starting Docker container: /boot/newvm.sh not found</title>
        <link>https://forum.multiotp.net/index.php?p=/discussion/108/error-starting-docker-container-boot-newvm-sh-not-found</link>
        <pubDate>Thu, 28 Aug 2025 08:52:12 +0000</pubDate>
        <category>General</category>
        <dc:creator>spacefly2020</dc:creator>
        <guid isPermaLink="false">108@/index.php?p=/discussions</guid>
        <description><![CDATA[Hello!&#13;
Error starting Docker container:&#13;
/bin/sh: 1: /boot/newvm.sh: not found&#13;
Tried on Linux distributions Debian-12 and Centos-8.&#13;
I installed docker according to the documentation:&#13;
<a href="https://docs.docker.com/engine/install/debian/" rel="nofollow">https://docs.docker.com/engine/install/debian/</a>&#13;
<a href="https://docs.docker.com/engine/install/centos/" rel="nofollow">https://docs.docker.com/engine/install/centos/</a>&#13;
Multiotp version 5.9.9.1 (similar error in versions 5.9.8.3 and 5.9.7.1)&#13;
&#13;
I build the image from the Dockerfile:&#13;
docker build -t multiotp/multiotp-open-source:latest .&#13;
The docker-image was build without errors.&#13;
&#13;
Check status image:&#13;
#docker images&#13;
REPOSITORY                      TAG       IMAGE ID       CREATED        SIZE&#13;
multiotp/multiotp-open-source   latest    d3c7e416572e   2 hours ago   982MB&#13;
&#13;
I created a shell script named ~/multiotp_docker.sh (see below):&#13;
&#13;
#!/bin/bash&#13;
&#13;
volume="/docker/multiotp"&#13;
&#13;
mkdir -p $volume&#13;
&#13;
docker run --name multiotp \&#13;
&#13;
-v $volume/data:/etc/multiotp \&#13;
&#13;
-v $volume/freeradius/config:/etc/freeradius \&#13;
&#13;
-v $volume/multiotp/log:/var/log/multiotp \&#13;
&#13;
-v $volume/freeradius/log:/var/log/freeradius \&#13;
&#13;
-p 8080:80 \&#13;
&#13;
-p 8443:443 \&#13;
&#13;
-p 1812:1812/udp \&#13;
&#13;
-p 1813:1813/udp \&#13;
&#13;
-d multiotp/multiotp-open-source&#13;
&#13;
&#13;
OK. Now run (from "root" account) this bash-script:&#13;
&#13;
chmod +x ~/multiotp_docker.sh &amp;&amp; ~/multiotp_docker.sh&#13;
&#13;
Check status container:&#13;
&#13;
# docker ps -a&#13;
&#13;
CONTAINER ID   IMAGE                           COMMAND                  CREATED        STATUS                      PORTS     NAMES&#13;
&#13;
3d1db2e0684b   multiotp/multiotp-open-source   "/bin/sh -c '/boot/n…"   42 hours ago   Exited (127) 42 hours ago             multiotp&#13;
&#13;
Check log status of container:&#13;
&#13;
#docker logs multiotp&#13;
&#13;
/bin/sh: 1: /boot/newvm.sh: not found&#13;
&#13;
&#13;
Thank you for your help.&#13;
Best regards,&#13;
Serge]]>
        </description>
    </item>
    <item>
        <title>Using multiOTP CredentialProvider with existing Radius</title>
        <link>https://forum.multiotp.net/index.php?p=/discussion/107/using-multiotp-credentialprovider-with-existing-radius</link>
        <pubDate>Mon, 18 Aug 2025 07:19:10 +0000</pubDate>
        <category>General</category>
        <dc:creator>steins</dc:creator>
        <guid isPermaLink="false">107@/index.php?p=/discussions</guid>
        <description><![CDATA[I would like to integrate the multiOTP CredentialProvider with my existing OTP system. In my current environment, I utilize PricvacyIdea for two-factor authentication on other systems. &#13;
Is it possible to connect the multiOTP CredentialProvider with this existing authorization source?]]>
        </description>
    </item>
    <item>
        <title>Install and use</title>
        <link>https://forum.multiotp.net/index.php?p=/discussion/102/install-and-use</link>
        <pubDate>Wed, 23 Apr 2025 14:59:36 +0000</pubDate>
        <category>General</category>
        <dc:creator>Alex</dc:creator>
        <guid isPermaLink="false">102@/index.php?p=/discussions</guid>
        <description><![CDATA[Hi. My question is I can't find a multitop installation on Linux. I use Debian. And the second question is it possible to use multitop for VPN. VPN(L2TP)+Freeradius+multiotp+LDAP(AD). Sending the password from the client via mschapv2]]>
        </description>
    </item>
    <item>
        <title>AD users of child domains are not synchronized</title>
        <link>https://forum.multiotp.net/index.php?p=/discussion/99/ad-users-of-child-domains-are-not-synchronized</link>
        <pubDate>Tue, 11 Feb 2025 12:28:54 +0000</pubDate>
        <category>General</category>
        <dc:creator>Andrew</dc:creator>
        <guid isPermaLink="false">99@/index.php?p=/discussions</guid>
        <description><![CDATA[<h3 data-id="good-day">&#13;
Good day.&#13;
</h3>&#13;
<p>&#13;
The service is deployed on the MS hypervisor image multiOTP-open-source-hyperv-5.9.0.3. Updated to version 5.9.9.1 .&#13;
</p>&#13;
<p>&#13;
Synchronization is configured with the AD main domain zao-agrokomplex.ru. Everything works fine. Clients are synchronized. Users log in to RDP and locally with 2FA. Everything works fine.&#13;
</p>&#13;
<p>&#13;
But the problem is that there are subdomains RTL.zao-agrokomplex.ru and BRCH.zao-agrokomplex.ru.&#13;
And users are not synchronized from these child domains.&#13;
</p>&#13;
<p>&#13;
I tried adding them to one common universal security group of the parent domain. There are no new users during synchronization. I also tried specifying security groups of child domains. The problem with synchronization is still there are no new users.&#13;
</p>&#13;
<p>&#13;
I specified child DN addresses in "ldap_users_dn". Also to no avail.&#13;
The logs only show this:&#13;
</p>&#13;
<code spellcheck="false" tabindex="0"> info LDAP Info: No update for the 19 LDAP synced users, based on 22 LDAP entries (processed in 00:00:32) </code>&#13;
<p>&#13;
Please tell me how to correctly configure multiOTP in a Multi-Domain environment?&#13;
</p>&#13;
<p> Here is the multitop.ini setting</p>&#13;
<code spellcheck="false" tabindex="0"> ./multiotp.php -config multiple-groups=1&#13;
encryption_hash= XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX&#13;
log=1&#13;
actual_version=5.9.9.1&#13;
admin_password_hash:=XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX&#13;
anonymous_stat=1&#13;
anonymous_stat_last_update=1739180575&#13;
anonymous_stat_random_id=bf1a00eccdad7abc033240359cda6ba160263447&#13;
attributes_to_encrypt=&#13;
auto_resync=1&#13;
backend_encoding=UTF-8&#13;
backend_type=files&#13;
backend_type_validated=0&#13;
cache_data=0&#13;
cache_ldap_hash=1&#13;
case_sensitive_users=0&#13;
challenge_response_enabled=0&#13;
clear_otp_attribute=&#13;
console_authentication=0&#13;
create_host=multiotp&#13;
create_time=1739180574&#13;
debug=0&#13;
default_algorithm=totp&#13;
default _dialin_ip_mask=&#13;
default_user_group=&#13;
default_request_ldap_pwd=0&#13;
default_request_prefix_pin=0&#13;
demo_mode=0&#13;
developer_mode=0&#13;
display_log=0&#13;
domain_name=&#13;
email_admin_address=&#13;
email_code_allowed=0&#13;
email_code_timeout=600&#13;
email_digits=6&#13;
encode_file_id=0&#13;
encryption_key_full_path=&#13;
failure_delayed_time=300&#13;
group_attribute=Filter-Id&#13;
hash_salt_full_path=&#13;
issuer=multiOTP&#13;
language=en&#13;
last_failed_white_delay=60&#13;
last_sync_update=0&#13;
las t_sync_update_host=&#13;
last_update=1739257821&#13;
last_update_host=multiotp&#13;
ldap_expired_password_valid=1&#13;
ldap_account_suffix=@zao-agrokomplex.ru&#13;
ldap_activated=1&#13;
ldap_base_dn=DC=zao-agrokomplex,DC=ru&#13;
ldap_bind_dn=2FA-srv-motp&#13;
ldap_cache_folder=&#13;
ldap_cache_on=1&#13;
ldap_cn_identifier=sAMAccountName&#13;
ldap_default_algorithm=totp&#13;
ldap_domain_controllers=srv-dc01.zao-agrokomplex.ru,ldaps://10.10.10.10:636&#13;
ldap_group_attribute=memberO f&#13;
ldap_group_cn_identifier=sAMAccountName&#13;
ldap_users_dn=DC=zao-agrokomplex,DC=ru;DC=RTL,DC=zao-agrokomplex,DC=ru;DC=BRCH,DC=zao-agrokomplex,DC=ru&#13;
ldap_hash_cache_time=604800&#13;
ldap_in_group=gr-agr-2FA-mOTP,RETAIL-2FA-mOTP&#13;
ldap_language_attribute=preferredLanguage&#13;
ldap_network_timeout=60&#13;
ldap_port=636&#13;
ldap_recursive_cache_only=0&#13;
ldap_recursive_groups=3&#13;
ldap_server_password:=xxxxxxxxxxxxxxxxxxxxxxxxxxxx&#13;
ldap_server_type=1&#13;
ldap_ssl=1&#13;
ldap_synced_user_attribute=&#13;
ldap_time_limit=600&#13;
ldaptls_reqcert=&#13;
ldaptls_cipher_suite=&#13;
max_block_failures=6&#13;
max_delayed_failures=3&#13;
max_event_resync_window=10000&#13;
max_event_window=100&#13;
max_time_resync_window=90000&#13;
max_time_window=600&#13;
multiple_groups=0&#13;
ntp_server=10.0.200.80&#13;
overwrite_request_ldap_pwd=1&#13;
radius_error_reply_message=1&#13;
radius_reply_attributor= +=&#13;
radius_reply_separator_hex=2c&#13;
radius_tag_prefix=&#13;
scratch_passwords_digits=6&#13;
scratch_passwords_amount=10&#13;
self_registration=1&#13;
server_cache_level=1&#13;
server_cache_lifetime=15552000&#13;
server_secret:=XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX&#13;
server_timeout=10&#13;
server_type=&#13;
server_url=&#13;
sms_api_id:=&#13;
sms_basic_auth=0&#13;
sms_code_allowed=1&#13;
sms_content_encoding=&#13;
sms_content_success=&#13;
sms_digits= 6&#13;
sms_encoding=&#13;
sms_header=&#13;
sms_international_format=0&#13;
sms_ip=&#13;
sms_message_prefix=&#13;
sms_method=&#13;
sms_no_double_zero=0&#13;
sms_originator=multiOTP&#13;
sms_password:=&#13;
sms_port=&#13;
sms_provider=&#13;
sms_send_template=&#13;
sms_status_success=&#13;
sms_timeout=180&#13;
sms_url=&#13;
sms_userkey:=&#13;
smtp_auth=0&#13;
smtp_password:=&#13;
smtp_port=25&#13;
smtp_sender=&#13;
smtp_sender_name=&#13;
smtp_server=&#13;
smtp_ssl=0&#13;
smtp_username=&#13;
sql_ser ver=&#13;
sql_username=&#13;
sql_password:=&#13;
sql_database=&#13;
sql_schema=&#13;
sql_config_table=multiotp_config&#13;
sql_cache_table=multiotp_cache&#13;
sql_ddns_table=multiotp_ddns&#13;
sql_devices_table=multiotp_devices&#13;
sql_groups_table=multiotp_groups&#13;
sql_log_table=multiotp_log&#13;
sql_stat_table=multiotp_stat&#13;
sql_tokens_table=multiotp_tokens&#13;
sql_users_table=multiotp_users&#13;
sync_delete_retention_days=30&#13;
sysl og_facility=7&#13;
syslog_level=5&#13;
syslog_port=514&#13;
syslog_server=&#13;
tel_default_country_code=&#13;
timezone=Europe/Zurich&#13;
token_serial_number_length=12&#13;
token_otp_list_of_length=6&#13;
verbose_log_prefix=&#13;
sms_challenge_enabled=0&#13;
text_sms_challenge=&#13;
text_token_challenge=&#13;
default_2fa_digits=6&#13;
default_pin_digits=4&#13;
ignore_no_prefix_cp=0&#13;
ldap_filter=&#13;
ldap_without2fa_in_group=&#13;
log_forced_in_file=0&#13;
</code>]]>
        </description>
    </item>
    <item>
        <title>MultiOTP Credential Provider - Stuck at Other User</title>
        <link>https://forum.multiotp.net/index.php?p=/discussion/98/multiotp-credential-provider-stuck-at-other-user</link>
        <pubDate>Tue, 07 Jan 2025 16:14:36 +0000</pubDate>
        <category>General</category>
        <dc:creator>abdulaleem</dc:creator>
        <guid isPermaLink="false">98@/index.php?p=/discussions</guid>
        <description><![CDATA[I have implemented multiotp credential provider (5.9.8.0) on windows server 2016 for RDP login. Normally, Its working OK but when a user is set to change password, then credential provider brings the password change prompt and the password is changed successfully but after that instead of initiating login processes, login screen gets stuck displaying "Other User" and nothing happens.]]>
        </description>
    </item>
    <item>
        <title>.ova and NIC types</title>
        <link>https://forum.multiotp.net/index.php?p=/discussion/95/ova-and-nic-types</link>
        <pubDate>Wed, 21 Aug 2024 11:43:18 +0000</pubDate>
        <category>General</category>
        <dc:creator>adb100</dc:creator>
        <guid isPermaLink="false">95@/index.php?p=/discussions</guid>
        <description><![CDATA[I've just replaced a couple of older ova-built VMs that I've been meaning to for a while as Stretch is EoL and I didn't have any success changing the repo on the VM.  Anyway, that's all now complete and I've built two new VMs from the 5.9.0.1 .ova, upgraded to the current 5.9.7.1 release and restored all the configuration and OS customisations and scripts.&#13;
One thing I typically do with most VMs built from .ova's is if they have E1000 vNICs, is to replace them with VMXNET3 vNICs.  What are the implications of this with the .ova built VMs?]]>
        </description>
    </item>
    <item>
        <title>Join this forum</title>
        <link>https://forum.multiotp.net/index.php?p=/discussion/94/join-this-forum</link>
        <pubDate>Tue, 20 Aug 2024 15:40:55 +0000</pubDate>
        <category>General</category>
        <dc:creator>adminf</dc:creator>
        <guid isPermaLink="false">94@/index.php?p=/discussions</guid>
        <description><![CDATA[ If you want to subscribe to this forum, send us an email to forum - at - multiotp - dot - net and we will send you back an invitation. ]]>
        </description>
    </item>
    <item>
        <title>QR code generation</title>
        <link>https://forum.multiotp.net/index.php?p=/discussion/93/qr-code-generation</link>
        <pubDate>Mon, 12 Aug 2024 09:54:38 +0000</pubDate>
        <category>General</category>
        <dc:creator>Armaggedon</dc:creator>
        <guid isPermaLink="false">93@/index.php?p=/discussions</guid>
        <description><![CDATA[Hello,<br />&#13;
How can users can get their token provisioning QR code without admin intervention? So far I've only been able to reach it by login on the web as admin and clicking "Print" for each of them. <br />&#13;
Many thanks!]]>
        </description>
    </item>
    <item>
        <title>Web</title>
        <link>https://forum.multiotp.net/index.php?p=/discussion/92/web</link>
        <pubDate>Mon, 22 Jul 2024 06:28:40 +0000</pubDate>
        <category>General</category>
        <dc:creator>barfly</dc:creator>
        <guid isPermaLink="false">92@/index.php?p=/discussions</guid>
        <description><![CDATA[Hello.&#13;
MultiOTP is installed on windows 10 system.&#13;
In the morning, when a large number of employees log in, the service stops working; I only find out about this when checking the WEB interface or when employees contact me.&#13;
Multiotp services continue to work.&#13;
How to fix the situation with the service crash?]]>
        </description>
    </item>
    <item>
        <title>Authentication failed (wrong token length)</title>
        <link>https://forum.multiotp.net/index.php?p=/discussion/89/authentication-failed-wrong-token-length</link>
        <pubDate>Thu, 23 May 2024 15:33:00 +0000</pubDate>
        <category>General</category>
        <dc:creator>dozza</dc:creator>
        <guid isPermaLink="false">89@/index.php?p=/discussions</guid>
        <description><![CDATA[I have the multiOTP HyperV appliance v5.9.0.3 and multiOTPCredentialProvider v5.9.7.1. Using this to prompt for 6 digit MFA code when a person connects via Remote Desktop to a Windows Server. The multiOTP appliance pulls members of the "2FAUsers" AD user group to create the user accounts and QR codes. This works well for a few weeks, then suddenly stops working. This is my third start-over attempt and each time the problem reoccurs. The user supplies their username, then password, then 6 digit OTP at RDP logon, then after a pause the error "Wrong One Time PIN" is returned. If I run "multiotp -display-log -debug auser", I see the error "authentication typed by the user is 13 chars long instead of 6 chars" and "Authentication failed (wrong token length)". I am only typing in a 6 digit code when prompted, so I am puzzled where the additional 7 characters are coming from. Any ideas to steer me towards a resolution?]]>
        </description>
    </item>
    <item>
        <title>Hardware token</title>
        <link>https://forum.multiotp.net/index.php?p=/discussion/88/hardware-token</link>
        <pubDate>Thu, 02 May 2024 09:20:41 +0000</pubDate>
        <category>General</category>
        <dc:creator>dreamscape</dc:creator>
        <guid isPermaLink="false">88@/index.php?p=/discussions</guid>
        <description><![CDATA[Sorry quick question, if most of my AD sync'ed users are using MS Authenticator for TOTP, can i have one users which uses a hardware token, i.e. Feitian c200 for example?]]>
        </description>
    </item>
    <item>
        <title>connecting with RDS2022</title>
        <link>https://forum.multiotp.net/index.php?p=/discussion/87/connecting-with-rds2022</link>
        <pubDate>Mon, 25 Mar 2024 14:59:48 +0000</pubDate>
        <category>General</category>
        <dc:creator>fishtail</dc:creator>
        <guid isPermaLink="false">87@/index.php?p=/discussions</guid>
        <description><![CDATA[Hi, a newbie here. I have multiOTP running on docker. The credential provider is installed on the RD Host. When I tried to use it on RDS, it failed with "wrong one-time password" I can't find documentation (apologize if overlooked) regarding to 'ddns' folder. Here's what the log showed:&#13;
2024-03-18 03:00:59 warning System Error: Unable to create the missing devices folder /etc/multiotp/ddns/ 0 842c98edad03&#13;
2024-03-18 03:01:18 warning System Error: Unable to create the missing devices folder /etc/multiotp/ddns/ 0 842c98edad03 2024-03-18 03:01:18 notice XXX User OK: User XXX successfully logged in with TOTP token 0 842c98edad03&#13;
I have removed myself from the designated Windows AD group and tried RDP again, it still asks for 2FA code. I powered off the docker container, it still asks for 2FA code. I finally uninstalled Credential Provider from RD Host in order for me to get back in to my remote desktop&#13;
Everything is on-prem.&#13;
Any thoughts/suggestoins is greatly appreciated.&#13;
]]>
        </description>
    </item>
    <item>
        <title>Auhtenticator app is picking up Description of the user from AD</title>
        <link>https://forum.multiotp.net/index.php?p=/discussion/86/auhtenticator-app-is-picking-up-description-of-the-user-from-ad</link>
        <pubDate>Tue, 02 Jan 2024 07:39:51 +0000</pubDate>
        <category>General</category>
        <dc:creator>os_jonsson</dc:creator>
        <guid isPermaLink="false">86@/index.php?p=/discussions</guid>
        <description><![CDATA[Hi! &#13;
In the authenticator app it displays the description of the user from the AD. I would like it to display the username instead but haven't found anything regarding this in the documentation. Is it possible to change? &#13;
//Oscar]]>
        </description>
    </item>
    <item>
        <title>5.9.7.1 issue</title>
        <link>https://forum.multiotp.net/index.php?p=/discussion/85/5-9-7-1-issue</link>
        <pubDate>Mon, 04 Dec 2023 09:00:24 +0000</pubDate>
        <category>General</category>
        <dc:creator>dreamscape</dc:creator>
        <guid isPermaLink="false">85@/index.php?p=/discussions</guid>
        <description><![CDATA[Morning All, I've upgraded to 5.9.7.1 to test the new pin functionally (thanks for adding this btw) but unfortunately it no longer works for me? I cannot auth and it doesn't generate a log? If i revert back to 5.9.7.0 it starts working again....]]>
        </description>
    </item>
    <item>
        <title>MsChap2 Debug in log</title>
        <link>https://forum.multiotp.net/index.php?p=/discussion/83/mschap2-debug-in-log</link>
        <pubDate>Fri, 01 Dec 2023 09:14:30 +0000</pubDate>
        <category>General</category>
        <dc:creator>dreamscape</dc:creator>
        <guid isPermaLink="false">83@/index.php?p=/discussions</guid>
        <description><![CDATA[Hi all,&#13;
How do i turn off this debug in the log, its showing the users pin? 1522&#13;
&#13;
2023-12-01 08:59:56	info		Debug	Debug: *CalculateMsChap2Response(user, 1522112582) for totp: 0101d3222aa706d9fd0fe0cd8cf4be27ee920000000000000000af6427f4ee9b0781414e1855b25f0690203a7bee6ed340f1 from 192.168.1.*	0	MACHINE&#13;
Thanks&#13;
Nick]]>
        </description>
    </item>
    <item>
        <title>Pin length</title>
        <link>https://forum.multiotp.net/index.php?p=/discussion/84/pin-length</link>
        <pubDate>Fri, 01 Dec 2023 09:17:56 +0000</pubDate>
        <category>General</category>
        <dc:creator>dreamscape</dc:creator>
        <guid isPermaLink="false">84@/index.php?p=/discussions</guid>
        <description><![CDATA[How do i change the length of the prefix pin, its currently 4, would like to make it bigger?]]>
        </description>
    </item>
    <item>
        <title>Windows Azure AD setting default domain</title>
        <link>https://forum.multiotp.net/index.php?p=/discussion/81/windows-azure-ad-setting-default-domain</link>
        <pubDate>Fri, 10 Nov 2023 15:06:50 +0000</pubDate>
        <category>General</category>
        <dc:creator>MariusS</dc:creator>
        <guid isPermaLink="false">81@/index.php?p=/discussions</guid>
        <description><![CDATA[Hi,&#13;
  I am trying out multiOTP Credential Provider v5.9.5.6 on a single machine which is a member of our Azure AD.&#13;
  The machine has two active user accounts, both Azure domain members,  and both of which are used by multiple people. The login process must therefore be as simple and intuitive as possible.&#13;
Manually entering AzureAD\[username] into the login dialog, followed by domain password and OTP works correctly, but if  I tried add "AzureAD" (without the quotes) as the value of the "multiOTPDefaultPrefix" registry key nothing is populated into the login dialog, and authentication fails unless I manually prefix the user name.&#13;
Can anyone help resolve?]]>
        </description>
    </item>
    <item>
        <title>roadmap</title>
        <link>https://forum.multiotp.net/index.php?p=/discussion/79/roadmap</link>
        <pubDate>Tue, 31 May 2022 08:50:07 +0000</pubDate>
        <category>General</category>
        <dc:creator>burghy</dc:creator>
        <guid isPermaLink="false">79@/index.php?p=/discussions</guid>
        <description><![CDATA[I really wanted to thank the multiotp developers, they are doing a great job. I wanted to understand if there is a roadmap of the things that will be done on multiotp community.&#13;
from what I understood:&#13;
&#13;
the sending of the qrcode via e-mail to the created users will be implemented/&#13;
&#13;
automatic synchronization with ad will remain on commercial product/&#13;
&#13;
Email account recovery/&#13;
&#13;
Multiple hardware tokens support for one account/&#13;
&#13;
VueJS frontend/&#13;
&#13;
Radius gateway support/&#13;
&#13;
YubiCloud support/&#13;
&#13;
FIDO support (SOAP service)/&#13;
&#13;
Doxygen documentation format/&#13;
&#13;
Users CSV impor/&#13;
&#13;
&#13;
could I propose to have the web page of the configuration file? the file are simple parameters, having a screen to manage them via the web would be great. &#13;
&#13;
&#13;
same thing to have on the browser the log file / radius log to check what happens under the hood. &#13;
&#13;
&#13;
]]>
        </description>
    </item>
    <item>
        <title>update ova image</title>
        <link>https://forum.multiotp.net/index.php?p=/discussion/76/update-ova-image</link>
        <pubDate>Thu, 17 Feb 2022 10:43:26 +0000</pubDate>
        <category>General</category>
        <dc:creator>burghy</dc:creator>
        <guid isPermaLink="false">76@/index.php?p=/discussions</guid>
        <description><![CDATA[Please update multiotp upload image. it little old. is a version 2019&#13;
multiotp-open-source-vm-009-5.6.1.5.ova]]>
        </description>
    </item>
    <item>
        <title>docker image error</title>
        <link>https://forum.multiotp.net/index.php?p=/discussion/74/docker-image-error</link>
        <pubDate>Thu, 17 Feb 2022 09:05:35 +0000</pubDate>
        <category>General</category>
        <dc:creator>burghy</dc:creator>
        <guid isPermaLink="false">74@/index.php?p=/discussions</guid>
        <description><![CDATA[hello.i trying to install multiotp on docker installed on a synology. there are various problems. &#13;
What we discovered it's that, first of all, the docker image it's a little bit old so would be great to have a new one.&#13;
port 80 is not working.&#13;
Also, the first start/install didn't place the certificates under /etc/multiotp folder mapped on the docker host. So also the SSL contection was not working.&#13;
The I tried to install the credential provider on a Windows 10 PC and test it. User unknown&#13;
A little more documentation and logs would be great to understand where is the problem.&#13;
and not a standard documentation would need the docker documentation.&#13;
or someone who has managed to install it successfully &#13;
&#13;
]]>
        </description>
    </item>
    <item>
        <title>raspberry image</title>
        <link>https://forum.multiotp.net/index.php?p=/discussion/75/raspberry-image</link>
        <pubDate>Thu, 17 Feb 2022 10:36:20 +0000</pubDate>
        <category>General</category>
        <dc:creator>burghy</dc:creator>
        <guid isPermaLink="false">75@/index.php?p=/discussions</guid>
        <description><![CDATA[i read in the change log:&#13;
&#13;
WHAT'S NEW IN THE RELEASES&#13;
==========================&#13;
# What's new in 5.8 releases&#13;
- Raspberry Pi 4B support&#13;
&#13;
HOW TO BUILD A RASPBERRY PI STRONG AUTHENTICATION SERVER ?&#13;
==========================================================&#13;
0) If you want to download a multiOTP Raspberry Pi image ready to use, follow this URL:  &#13;
   <a href="https://download.multiOTP.net/raspberry/" rel="nofollow">https://download.multiOTP.net/raspberry/</a>&#13;
&#13;
but in a link:&#13;
<a href="https://download.multiotp.net/raspberry/" rel="nofollow">https://download.multiotp.net/raspberry/</a>&#13;
i don't find anythink]]>
        </description>
    </item>
    <item>
        <title>multiotp as Auithenticator for nginx</title>
        <link>https://forum.multiotp.net/index.php?p=/discussion/73/multiotp-as-auithenticator-for-nginx</link>
        <pubDate>Wed, 09 Feb 2022 09:47:01 +0000</pubDate>
        <category>General</category>
        <dc:creator>mth9977</dc:creator>
        <guid isPermaLink="false">73@/index.php?p=/discussions</guid>
        <description><![CDATA[Hi there,&#13;
i'm really a newbie on multiotp and nginx. therefor my question might be a little dumb.&#13;
i'd like to have a reverse proxy which pre-authenticates users using mfa (with multiotp as source)&#13;
in my current plan i need nginx as reverse-proxy, mutliotp for mfa and an apache as interface for authentication between the reverse-Proxy (nginx) and multiotp (because nginx does not speak radius)&#13;
Is there a way to omit apache and have multiotp to do its work? Or will there be an easier way to solve this?&#13;
&#13;
Kind regards, mth9977&#13;
]]>
        </description>
    </item>
    <item>
        <title>RD Gateway</title>
        <link>https://forum.multiotp.net/index.php?p=/discussion/66/rd-gateway</link>
        <pubDate>Wed, 26 Aug 2020 18:58:37 +0000</pubDate>
        <category>General</category>
        <dc:creator>idoch</dc:creator>
        <guid isPermaLink="false">66@/index.php?p=/discussions</guid>
        <description><![CDATA[We have tried to implement MultiOTP with the RD Gateway, but with MultiOTP protecting just the RDP part you get a second "logon" screen. Is there any way to make this process smoother? Perhaps just a screen that asks for the 2FA code (not username, password (again) and the code?&#13;
&#13;
Maybe a way to pre-fill the username and password with the info already submitted?&#13;
&#13;
Maybe better RD Gateway integration?]]>
        </description>
    </item>
    <item>
        <title>LDAP sync with eDirectory</title>
        <link>https://forum.multiotp.net/index.php?p=/discussion/64/ldap-sync-with-edirectory</link>
        <pubDate>Fri, 20 Mar 2020 14:41:31 +0000</pubDate>
        <category>General</category>
        <dc:creator>dkenny</dc:creator>
        <guid isPermaLink="false">64@/index.php?p=/discussions</guid>
        <description><![CDATA[Hi there.  I hoping someone can help with this sync problem I'm having.&#13;
&#13;
I'm connecting to eDirectory, which originally started with Novell, but is now with Micro Focus.  We use several ldap clients which interact ok, but I'm having an error with multiotp when I try to do a users-sync or users-list.  In looking at a wireshark trace, I can see a successful bind, but then an error "invalidDNSyntax".&#13;
&#13;
Multiotp reports the error as:&#13;
     warning LDAP Error: FATAL: AD/LDAP bind failed. The BaseDN  is not accepted&#13;
I'm using  here since I need to start the search from the very top of the tree. I've also tried more specific values, like ou=accounting,o=alberta.  Regardless of what I tried, I got the same error.&#13;
&#13;
Looking further at the wireshark trace, I see that there's a dn value of 'test-connection' that is being sent.  I wonder if that is what may be causing this error since that object does not exist in the directory.&#13;
&#13;
Has anybody seen this kind of problem before or maybe some thoughts on where I should focus my efforts?&#13;
&#13;
Thanks!!]]>
        </description>
    </item>
    <item>
        <title>LDAP (AD) Sync and PINs?</title>
        <link>https://forum.multiotp.net/index.php?p=/discussion/69/ldap-ad-sync-and-pins</link>
        <pubDate>Thu, 18 Mar 2021 19:53:53 +0000</pubDate>
        <category>General</category>
        <dc:creator>adb100</dc:creator>
        <guid isPermaLink="false">69@/index.php?p=/discussions</guid>
        <description><![CDATA[I have setup LDAP sync and a daily cron task to sync the users.  I have been using this for a while and PINs are not required.  I just checked the configuration file and I think it is set to request the LDAP Password &amp; a prefix PIN by default:&#13;
&#13;
default_request_ldap_pwd=1&#13;
default_request_prefix_pin=1&#13;
&#13;
However none of the users have this set in their configuration files:&#13;
&#13;
request_ldap_pwd=1&#13;
request_prefix_pin=0&#13;
&#13;
This is a fairly vanilla setup, built from the 5.0.4.7 .OVA file and upgraded to the latest 5.8.1.1 release.  Just wondering why my users don't have PINs?&#13;
&#13;
Andy]]>
        </description>
    </item>
    <item>
        <title>Upgraded to 5.8.1 and authentication now fails for all users?</title>
        <link>https://forum.multiotp.net/index.php?p=/discussion/68/upgraded-to-5-8-1-and-authentication-now-fails-for-all-users</link>
        <pubDate>Mon, 15 Mar 2021 20:11:33 +0000</pubDate>
        <category>General</category>
        <dc:creator>adb100</dc:creator>
        <guid isPermaLink="false">68@/index.php?p=/discussions</guid>
        <description><![CDATA[Upgraded to 5.8.1 on the VM version by copying the new files over the original and its stopped working...&#13;
All users are failing authentication.  If I test locally from the GUI I get 'failed (99 ERROR: Authentication failed (and other possible unknown errors)).&#13;
Not sure how to debug it?]]>
        </description>
    </item>
    <item>
        <title>Setting to make LOCAL COMPUTER default rather than DOMAIN on RDP login screen</title>
        <link>https://forum.multiotp.net/index.php?p=/discussion/61/setting-to-make-local-computer-default-rather-than-domain-on-rdp-login-screen</link>
        <pubDate>Thu, 12 Sep 2019 19:09:51 +0000</pubDate>
        <category>General</category>
        <dc:creator>idoch</dc:creator>
        <guid isPermaLink="false">61@/index.php?p=/discussions</guid>
        <description><![CDATA[We are using an RD Gateway and we have some machines that we would like to default to the LOCAL computer for authentication (even though they may or may not have a domain available). It seems to default to the domain on the login screen.&#13;
&#13;
Example for a computer named PC: &#13;
&#13;
PC\Username   &lt;-- this is what we WANT and we can login to the local PC is we type this&#13;
 &#13;
Domain\Username  &lt;-- this appears to be the default for all domain joined computers &#13;
&#13;
It appears that (if you are using a RD Gateway) the domain setting is not passed to the RDP login screen nor is it passed if you specify the username with the PC\Username format (PC\Username WILL be used to authenticate to the RD Gateway though). With the default Credential provider you CAN pass the domain from the RDP file as &#13;
&#13;
domain:s:DOMAIN or with the username&#13;
username:s:PC\Username&#13;
&#13;
We tried to set the MOTP config option:   domain_name=PC    but that didn't seem to do anything&#13;
We set the computer's default domain via GPO -- but that did not seem to change anything&#13;
We tried to set:&#13;
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\DefaultDomainName\PC&#13;
and&#13;
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\AltDefaultDomainName\PC&#13;
&#13;
The MOTP Credential Provider seems to be grabbing the domain name for the logon screen from:&#13;
&#13;
HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Domain&#13;
&#13;
Does anyone have any ideas as to how to set MOTP to default to the local PC name 9such as %computername%) rather than the domain? I see that there is a plugin for pGina called the pGina Local Machine Plugin, but I'm not sure how that might relate to this situation.&#13;
&#13;
Anybody have any guidance?&#13;
&#13;
The default behavior (without MOTP) passes the parameters for domain (or domain\username) to the RD Gateway AND the RDP login. Is there a way to accomplish this?&#13;
&#13;
If not, is there a way to set the logon screen to use the local PC as default (rather than the domain)?&#13;
&#13;
Edit: Sorry about the formatting. I don't seem to have any formatting controls available. It looks better before I post.]]>
        </description>
    </item>
    <item>
        <title>Time changed on OTP server</title>
        <link>https://forum.multiotp.net/index.php?p=/discussion/65/time-changed-on-otp-server</link>
        <pubDate>Wed, 17 Jun 2020 02:16:53 +0000</pubDate>
        <category>General</category>
        <dc:creator>elnino54</dc:creator>
        <guid isPermaLink="false">65@/index.php?p=/discussions</guid>
        <description><![CDATA[Hi all, We had a time skew issue on our OTP server - Somehow it was still working with ~10 min skew but we had some minor issues with users logging in to windows offline with Credential provider that lead me to the issue of the time being out on the OTP server.&#13;
&#13;
I fixed the time skew issue but now I am having to resync users.  Is there some way to just automatically resync all users?]]>
        </description>
    </item>
    <item>
        <title>SMS exec script</title>
        <link>https://forum.multiotp.net/index.php?p=/discussion/63/sms-exec-script</link>
        <pubDate>Mon, 10 Feb 2020 13:28:19 +0000</pubDate>
        <category>General</category>
        <dc:creator>glassen</dc:creator>
        <guid isPermaLink="false">63@/index.php?p=/discussions</guid>
        <description><![CDATA[Good day,&#13;
&#13;
I'm trying to use the <code spellcheck="false" tabindex="0">exec</code> feature of sms with a non numerical identifier by setting the following<p>&#13;
<code spellcheck="false" tabindex="0">multiotp -config sms-provider=exec&#13;
multiotp -config sms-api-id='/opt/multiotp/sms.sh %from %to %msg'</code>&#13;
</p>&#13;
I have also created a user with the following commands<p>&#13;
<code spellcheck="false" tabindex="0">multiotp -fastcreate username&#13;
multiotp -set username sms='nonNumericalIdentifier'</code>&#13;
</p>&#13;
the sms.sh script is currently only for testing and contains the following:&#13;
<p>&#13;
<code spellcheck="false" tabindex="0">#!/bin/bash&#13;
&#13;
echo $1 &gt;&gt; /etc/multiotp/smstext.log&#13;
echo $2 &gt;&gt; /etc/multiotp/smstext.log&#13;
echo $3 &gt;&gt; /etc/multiotp/smstext.log</code>&#13;
</p>&#13;
&#13;
But when i try to request a SMS by <code spellcheck="false" tabindex="0">multiotp.php -debug -display-log -requiresms username</code>&#13;
it throws an error:<p>&#13;
<code spellcheck="false" tabindex="0">PHP Notice:  Undefined variable: real_user in /opt/multiotp/multiotp.php on line 16209&#13;
PHP Notice:  Undefined variable: real_user in /opt/multiotp/multiotp.php on line 16209&#13;
&#13;
LOG 2020-02-10 11:08:15 warning SMS Error: no information on where to send SMS code for&#13;
60 *ERROR: No information on where to send SMS code&#13;
&#13;
LOG 2020-02-10 11:08:15 debug Debug Debug: *Attributes sent to the RADIUS server: Reply-Message := "ERROR: No information on where to send SMS code"&#13;
Reply-Message := "ERROR: No information on where to send SMS code"</code></p>&#13;
&#13;
This is all worked around by removing the references to the <code spellcheck="false" tabindex="0">CleanPhoneNumber()</code> function in a few places.<p> My question is how the "special all-in-one-file multiotp.exe executable created using Enigma Virtual Box" is configured? <br />Since my ultimate goal is to use the Credential Provider with my currently modified multiphp.php to send the OTP via the exec function with a non numerical SMS "number".</p>]]>
        </description>
    </item>
    <item>
        <title>Resilient MultiOTP devices?</title>
        <link>https://forum.multiotp.net/index.php?p=/discussion/62/resilient-multiotp-devices</link>
        <pubDate>Wed, 09 Oct 2019 09:32:35 +0000</pubDate>
        <category>General</category>
        <dc:creator>adb100</dc:creator>
        <guid isPermaLink="false">62@/index.php?p=/discussions</guid>
        <description><![CDATA[I have a single MultiOTP VM that is synchronising users from AD LDAP via a CRON job.&#13;
Its all working OK, however I am looking to have a 2nd MultiOTP VM with the same configuration in 2nd location.&#13;
Is it possible to just backup and restore the configuration to a 2nd VM replicating all the users?&#13;
]]>
        </description>
    </item>
   </channel>
</rss>
