CAS 6.6 RADIUS MFA集成认证失败问题求助
问题现象
输入正确OTP后,OTP页面提示:
Credentials are rejected/invalid and authentication attempt has failed.
核心日志信息
2023-11-24 00:36:51,382 WARN [org.apereo.cas.authentication.policy.AllAuthenticationHandlersSucceededAuthenticationPolicy] - <Number of successful authentications, [2], does not match the number of authentication handlers, [1].> 2023-11-24 00:36:51,382 WARN [org.apereo.cas.authentication.policy.AllAuthenticationHandlersSucceededAuthenticationPolicy] - <Number of successful authentications, [2], does not match the number of authentication handlers, [1].> 2023-11-24 00:36:51,383 ERROR [org.apereo.cas.authentication.DefaultAuthenticationManager] - <[AuthenticationException]: [Unable to satisfy authentication policy AllAuthenticationHandlersSucceededAuthenticationPolicy]> 2023-11-24 00:36:51,384 INFO [org.apereo.inspektr.audit.support.Slf4jLoggingAuditTrailManager] - <Audit trail record BEGIN WHO: 1234 WHAT: [RadiusTokenCredential] ACTION: AUTHENTICATION_FAILED APPLICATION: CAS WHEN: Fri Nov 24 00:36:51 AST 2023
当前配置
cas.authn.accept.enabled=false cas.authn.policy.all-handlers.enabled=true cas.authn.policy.all.enabled=true cas.authn.radius.client.inet-address=x.x.x.x cas.authn.radius.client.shared-secret=1234567890 cas.authn.radius.client.socket-timeout=30 cas.authn.radius.server.protocol=PAP cas.authn.radius.server.retries=1 cas.authn.mfa.radius.server.protocol=PAP cas.authn.mfa.radius.client.shared-secret=1234567890 cas.authn.mfa.radius.client.inet-address=x.x.x.x cas.authn.mfa.radius.allowed-authentication-attempts=10 cas.authn.mfa.radius.id=mfa-radius cas.authn.mfa.triggers.global.globalProviderId=mfa-radius cas.service-registry.core.init-from-json=false cas.service-registry.json.location=file:C:\etc\cas\services
问题分析
日志中的核心冲突来自AllAuthenticationHandlersSucceededAuthenticationPolicy:该策略要求所有配置的认证处理器必须同时成功完成认证,但双因素认证是分步流程(先第一因素RADIUS认证,再第二因素RADIUS OTP认证),并非同时触发多个处理器,导致成功认证数与处理器数不匹配,触发认证失败。
当前配置中cas.authn.policy.all-handlers.enabled=true和cas.authn.policy.all.enabled=true强制开启了这个全局策略,与分步认证的逻辑冲突。
解决步骤
禁用全局全处理器成功策略
修改配置文件,关闭冲突的认证策略:cas.authn.policy.all-handlers.enabled=false cas.authn.policy.all.enabled=false此配置允许CAS按照分步认证的逻辑判断,每一步认证通过即可进入下一个环节,无需同时满足所有处理器。
验证RADIUS服务器响应
检查RADIUS服务器日志,确认第一因素(账号密码)和第二因素(OTP)的认证请求均返回成功响应,排除RADIUS端的处理异常。确认双因素触发逻辑
当前全局触发mfa-radius的配置cas.authn.mfa.triggers.global.globalProviderId=mfa-radius是合理的,确保第一因素认证通过后,CAS能正确跳转至双因素认证页面。重启CAS服务
应用配置修改后,重启CAS服务,重新测试认证流程。
内容的提问来源于stack exchange,提问作者Saleem

