Duo and 1Password integration issues.

24

Comments

  • wkleem
    wkleem
    Community Member

    I've looked at Duo Security in my ongoing issue with Duo and 1Password and discovered that Duo has a Windows Logon Client that can be integrated with Microsoft Windows Logon. After installation, use push to sign in instead of the fingerprint.

    I haven't tried, with my issues ongoing, but I thought I would let the forum know about it since there was interest in the past about 1Password's support for a fingerprint reader.

    https://duo.com/docs/rdp


    1Password Version: Not Provided
    Extension Version: Not Provided
    OS Version: Not Provided
    Sync Type: Not Provided

  • Frank
    edited April 2017

    Hi @wkleem - Did you find the link to Live Chat support helpful? :+1:

  • wkleem
    wkleem
    Community Member
    edited April 2017

    @Frank,

    I haven't tried the Live Chat. I am still waiting for their reply to the email first. I'll give them more time to respond. I'll send a reminder later.

  • wkleem
    wkleem
    Community Member

    After 7 days of this issue so far and still unresolved, I disabled Duo Security from Duo.com and check back sometime tomorrow.

  • wkleem
    wkleem
    Community Member
    edited April 2017

    I googled my issue and the search came up with this support page:
    https://help.duo.com/s/article/ka070000000fzBmAAI/1159?language=en_US

    Common issues:
    https://guide.duo.com/common-issues

    But I don't have any experience with SSH. And it's not my server.

    "How do I resolve the error “Server’s time may be out of sync”?
    The "Server's time may be out of sync" error message is most commonly resolved by SSHing into the server hosting your Duo-protected application or service and using Network Time Protocol (NTP) to set the correct time."

    I will check the time on my devices.

  • wkleem
    wkleem
    Community Member

    I completely forgot about my Emergency Kit. I am unceratain if the EK will help here? Also, about Duo Mobile Authenticator, If I add a site singly and not in bulk, will the TOTP codes change at different times.

    For example, if I have an iPhone and an iPad. If I add Dropbox for iPhone first and for iPad 6 months later will the codes be indentical months apart or do I have to redo the 2FA each time a add a new device to Duo Mobile to accomodate new devices? If I have 5 devices, then do 5 devices in bulk or do 5 times one at at time at different times?

  • AGAlumB
    AGAlumB
    1Password Alumni

    I completely forgot about my Emergency Kit. I am unceratain if the EK will help here? Also, about Duo Mobile Authenticator, If I add a site singly and not in bulk, will the TOTP codes change at different times.

    @wkleem: The Emergency Kit only helps if you've forgotten your Master Password, Secret Key, etc. Since you're using Duo second factor, you'd still need access to that to login to the web interface after a period of time (or logging in from a new location).

    For example, if I have an iPhone and an iPad. If I add Dropbox for iPhone first and for iPad 6 months later will the codes be indentical months apart or do I have to redo the 2FA each time a add a new device to Duo Mobile to accomodate new devices? If I have 5 devices, then do 5 devices in bulk or do 5 times one at at time at different times?

    I don't see how Dropbox is involved here. Duo should be sending you a push notification on one of your authorized devices to complete the login to 1Password.com, not a code, so there's nothing to match. Certainly you can get into code mismatch issues with TOTP if the device generating it is sufficiently out of sync with the server requesting it with regard to date/time/zone/etc.

  • wkleem
    wkleem
    Community Member

    Two things. Firstly, is the license transferable in the event that I cannot resolve my issue and would want to start a new Teams Pro account with the promo deal?

    Secondly what I am referring to is the TOTP that Duo supports.
    https://duo.com/docs/dropbox

    "Duo offers a variety of methods for adding two-factor authentication and flexible security policies to Dropbox SSO logins, complete with inline self-service enrollment and authentication prompt."

    Duo also supports 1Password, Evernote, and more.

  • wkleem
    wkleem
    Community Member

    The Duo pricing page lists support for paid versions:
    https://duo.com/pricing

    "Email, chat & telephone support
    9-6 ET, 9-5 PT, M-F. 24x7x365 support for critical issues (Premium available)"

  • wkleem
    wkleem
    Community Member
    edited April 2017

    Further research show that Private Internet Access VPN, among other things, can interfere with Duo.

    https://help.duo.com/s/article/ka170000000kHgmAAE/2051?language=en_US

    "Pull-to-refresh does not work:

    This occurs because something has happened on the device that has caused the Duo account to be unlinked from our servers.

    First, we should make sure the system time is set automatically and that the timezone is correct on the phone via Settings > General > Date & Time.

    If that doesn't appear to help, we recommend re-activating the affected Duo Mobile account. Here's how to do that:

    Activating Duo Mobile for a user account.
    Activating Duo Mobile for an admin account.
    

    Other installed applications on iOS:"

    I have already tried re-activating Duo Mobile for both User and Admin accounts.

    I am not using PIA but it's something to be aware of.

    "We've received reports from customers that when PIA-VPN is installed on an iOS device, the device is unable to receive push notifications over WiFi. If you have PIA-VPN installed and need to use Push for authentications over WiFi, F-Secure Freedome is an alternative that has been confirmed to work with Push notifications regardless of cellular network settings.

    If none of the above steps resolve your issue, and you receive an error message, please gather this message and send it to support@duosecurity.com along with what happened right before the message appeared, and we'll help troubleshoot."

  • wkleem
    wkleem
    Community Member
    edited April 2017

    I have good news. My case has been escalated. But I was asked if client has access to time server? I thought I would post here as well.

    "Hello WK Lee,

    Thanks for your reply, we have opened a ticket with our engineering team.The issue has been escalated.
    Regarding the issue with the timesync could you make sure your client is using an NTP server and that the time is correctly synced ?"

  • AGAlumB
    AGAlumB
    1Password Alumni

    @wkleem: I suspect they just mean the time settings on your devices. OSes automate time synchronization, but vendors often use different servers, and issues with network, hardware, and software can also play a role.

  • wkleem
    wkleem
    Community Member

    Thanks. I will check my Mac. Windows time is synchronized.

  • AGAlumB
    AGAlumB
    1Password Alumni

    I've only run into this once or twice myself, but I hear from other users now and then especially with regard to TOTP. Time synchronization is dead-simple when everything is working as expected, but there are so many factors involved that a lot can go wrong too.

  • wkleem
    wkleem
    Community Member

    On my Mac, time is synchronised as well.

  • AGAlumB
    AGAlumB
    1Password Alumni

    What I'm saying is that if everything is not synchronized the same (or are unable to maintain synchronization for some reason), it can cause issues for anything time-based, especially with multiple moving parts involved.

  • wkleem
    wkleem
    Community Member

    @brenty,

    It's up to Duo now. None of us are able to resolve things at our end.

  • AGAlumB
    AGAlumB
    1Password Alumni

    Indeed. :blush:

  • wkleem
    wkleem
    Community Member
    edited April 2017

    Hi

    I wonder, in situations like mine, what happens when the connectivity resumes from an offline state. And, because I am on subscription, due to a lack of connectivity, what happens to the account?

    It should be interesting to find out the extent of the "outage". I am currently at 2 weeks and counting. I am not seeing any issues from iOS or Mac/Windows as yet.

  • AGAlumB
    AGAlumB
    1Password Alumni

    @wkleem: I'm not sure what you mean by "outage". I thought you were just unable to access the admin interface on 1Password.com because you lost access to your second factor. This doesn't prevent you from using the apps to access your data. And even if you were offline, the data is cached locally. Let me know if that helps!

  • wkleem
    wkleem
    Community Member
    edited April 2017

    I'm not sure what you mean by "outage". I thought you were just unable to access the admin interface on 1Password.com because you lost access to your second factor. This doesn't prevent you from using the apps to access your data. And even if you were offline, the data is cached locally. Let me know if that helps!

    Thanks for the clarification @brenty. I just wasn't sure what I was missing from being unable to access 1Password.com. You are right, but I cannot create, modify or delete vaults and create/access to Groups I haven't set up yet.

    Is there a 1Password Teams Pro reference manual from Agilebits?

  • AGAlumB
    AGAlumB
    1Password Alumni

    @wkleem: We don't have a "manual" per se, but you can find many guides for specific features/tasks in our knowlegebase:

    1Password Teams Admin Guide: Getting Started

    And if you have any questions just let us know. Cheers! :)

  • wkleem
    wkleem
    Community Member
    edited April 2017

    While I am waiting for Duo to solve my present issue between 1Password and Duo, I have noticed the Device Insight stopped tracking Mac/PC and only mobile devices now? I am using Duo Free.

  • AGAlumB
    AGAlumB
    1Password Alumni

    I don't know what to tell you. Not my area of expertise. :)

  • wkleem
    wkleem
    Community Member
    edited April 2017

    Hi

    Just keeping Agilebits posted. You have a terrific community here! :)

    I hope you have had a happy Easter.

  • AGAlumB
    AGAlumB
    1Password Alumni

    Thank you! It was peaceful. I'll take it. Likewise, I hope yours was great, and the skies blue for you! :chuffed:

  • wkleem
    wkleem
    Community Member

    Torrential rain yesterday, the day after Easter! Parts of my country, Singapore, were flooded.

  • AGAlumB
    AGAlumB
    1Password Alumni

    Oh dear. Hopefully nothing dangerous. Take care!

  • wkleem
    wkleem
    Community Member

    I'm good, thank you. I can't speak for everyone else! :(

  • Stay safe out there wkleem :+1:

This discussion has been closed.