<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: /auth endpoint always returns stat OK regardless of passcode value? in APIs</title>
    <link>https://community.cisco.com/t5/apis/auth-endpoint-always-returns-stat-ok-regardless-of-passcode/m-p/4883852#M548</link>
    <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;&lt;CODE&gt;OK&lt;/CODE&gt; means the auth request was successfully sent. Look at the &lt;CODE&gt;result&lt;/CODE&gt; value and you shouls see it is &lt;CODE&gt;deny&lt;/CODE&gt;. Please review the “Response Formats” table at &lt;A href="https://duo.com/docs/authapi#/auth" class="inline-onebox" rel="nofollow noopener"&gt;Auth API | Duo Security&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;If your post to /auth used &lt;CODE&gt;async&lt;/CODE&gt; then you need to poll &lt;CODE&gt;auth_status&lt;/CODE&gt; using the &lt;CODE&gt;txid&lt;/CODE&gt; returned by /auth to see that &lt;CODE&gt;deny&lt;/CODE&gt; result.&lt;/P&gt;&lt;/DIV&gt;</description>
    <pubDate>Thu, 12 Sep 2019 13:34:59 GMT</pubDate>
    <dc:creator>DuoKristina</dc:creator>
    <dc:date>2019-09-12T13:34:59Z</dc:date>
    <item>
      <title>/auth endpoint always returns stat OK regardless of passcode value?</title>
      <link>https://community.cisco.com/t5/apis/auth-endpoint-always-returns-stat-ok-regardless-of-passcode/m-p/4883851#M547</link>
      <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;I am using /auth/v2/auth endpoint for my API to do 2FA.&lt;/P&gt;
&lt;P&gt;I am doing a HTTP POST&lt;BR /&gt;
&lt;A href="http://api-somenumber.duosecurity.com/auth/v2/auth" class="onebox" target="_blank" rel="nofollow noopener"&gt;■■■■■■■■■■■■■■■■■■■■■■■■■■■■■■/auth/v2/auth&lt;/A&gt;&lt;BR /&gt;
factor=passcode&amp;amp;passcode=123456&amp;amp;username=someuser&lt;/P&gt;
&lt;P&gt;I get stat=Ok in the response regardless the value of passcode.&lt;BR /&gt;
But from my Duo2FA mobile, the passcode for this user is clearly no 123456&lt;/P&gt;
&lt;P&gt;But when I look at the administation log form Duo admin webpage it says:&lt;BR /&gt;
Denied&lt;BR /&gt;
Invalid passcode&lt;/P&gt;
&lt;P&gt;Is the usage correct or there is something wrong on the Duo side?&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Wed, 11 Sep 2019 16:49:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/apis/auth-endpoint-always-returns-stat-ok-regardless-of-passcode/m-p/4883851#M547</guid>
      <dc:creator>sc_admin_admin</dc:creator>
      <dc:date>2019-09-11T16:49:45Z</dc:date>
    </item>
    <item>
      <title>Re: /auth endpoint always returns stat OK regardless of passcode value?</title>
      <link>https://community.cisco.com/t5/apis/auth-endpoint-always-returns-stat-ok-regardless-of-passcode/m-p/4883852#M548</link>
      <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;&lt;CODE&gt;OK&lt;/CODE&gt; means the auth request was successfully sent. Look at the &lt;CODE&gt;result&lt;/CODE&gt; value and you shouls see it is &lt;CODE&gt;deny&lt;/CODE&gt;. Please review the “Response Formats” table at &lt;A href="https://duo.com/docs/authapi#/auth" class="inline-onebox" rel="nofollow noopener"&gt;Auth API | Duo Security&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;If your post to /auth used &lt;CODE&gt;async&lt;/CODE&gt; then you need to poll &lt;CODE&gt;auth_status&lt;/CODE&gt; using the &lt;CODE&gt;txid&lt;/CODE&gt; returned by /auth to see that &lt;CODE&gt;deny&lt;/CODE&gt; result.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 12 Sep 2019 13:34:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/apis/auth-endpoint-always-returns-stat-ok-regardless-of-passcode/m-p/4883852#M548</guid>
      <dc:creator>DuoKristina</dc:creator>
      <dc:date>2019-09-12T13:34:59Z</dc:date>
    </item>
  </channel>
</rss>

