You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

CAS 6.6 RADIUS MFA集成认证失败问题求助

CAS 6.6集成RADIUS双因素认证失败排查与解决

问题现象

输入正确OTP后,OTP页面提示:

Credentials are rejected/invalid and authentication attempt has failed.

核心日志信息

2023-11-24 00:36:51,382 WARN [org.apereo.cas.authentication.policy.AllAuthenticationHandlersSucceededAuthenticationPolicy] - <Number of successful authentications, [2], does not match the number of authentication handlers, [1].>
2023-11-24 00:36:51,382 WARN [org.apereo.cas.authentication.policy.AllAuthenticationHandlersSucceededAuthenticationPolicy] - <Number of successful authentications, [2], does not match the number of authentication handlers, [1].>
2023-11-24 00:36:51,383 ERROR [org.apereo.cas.authentication.DefaultAuthenticationManager] - <[AuthenticationException]: [Unable to satisfy authentication policy AllAuthenticationHandlersSucceededAuthenticationPolicy]>
2023-11-24 00:36:51,384 INFO [org.apereo.inspektr.audit.support.Slf4jLoggingAuditTrailManager] - <Audit trail record BEGIN
WHO: 1234
WHAT: [RadiusTokenCredential]
ACTION: AUTHENTICATION_FAILED
APPLICATION: CAS
WHEN: Fri Nov 24 00:36:51 AST 2023

当前配置

cas.authn.accept.enabled=false
cas.authn.policy.all-handlers.enabled=true
cas.authn.policy.all.enabled=true
cas.authn.radius.client.inet-address=x.x.x.x
cas.authn.radius.client.shared-secret=1234567890
cas.authn.radius.client.socket-timeout=30
cas.authn.radius.server.protocol=PAP
cas.authn.radius.server.retries=1

cas.authn.mfa.radius.server.protocol=PAP
cas.authn.mfa.radius.client.shared-secret=1234567890
cas.authn.mfa.radius.client.inet-address=x.x.x.x
cas.authn.mfa.radius.allowed-authentication-attempts=10
cas.authn.mfa.radius.id=mfa-radius
cas.authn.mfa.triggers.global.globalProviderId=mfa-radius


cas.service-registry.core.init-from-json=false
cas.service-registry.json.location=file:C:\etc\cas\services

问题分析

日志中的核心冲突来自AllAuthenticationHandlersSucceededAuthenticationPolicy:该策略要求所有配置的认证处理器必须同时成功完成认证,但双因素认证是分步流程(先第一因素RADIUS认证,再第二因素RADIUS OTP认证),并非同时触发多个处理器,导致成功认证数与处理器数不匹配,触发认证失败。

当前配置中cas.authn.policy.all-handlers.enabled=true和cas.authn.policy.all.enabled=true强制开启了这个全局策略,与分步认证的逻辑冲突。

解决步骤

  1. 禁用全局全处理器成功策略
    修改配置文件,关闭冲突的认证策略:

    cas.authn.policy.all-handlers.enabled=false
    cas.authn.policy.all.enabled=false
    

    此配置允许CAS按照分步认证的逻辑判断,每一步认证通过即可进入下一个环节,无需同时满足所有处理器。

  2. 验证RADIUS服务器响应
    检查RADIUS服务器日志,确认第一因素(账号密码)和第二因素(OTP)的认证请求均返回成功响应,排除RADIUS端的处理异常。

  3. 确认双因素触发逻辑
    当前全局触发mfa-radius的配置cas.authn.mfa.triggers.global.globalProviderId=mfa-radius是合理的,确保第一因素认证通过后,CAS能正确跳转至双因素认证页面。

  4. 重启CAS服务
    应用配置修改后,重启CAS服务,重新测试认证流程。

内容的提问来源于stack exchange,提问作者Saleem

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.05 10:12:18