Skip to content
This repository has been archived by the owner on Jun 23, 2021. It is now read-only.

View Login Attempts #44

Open
Grunticus03 opened this issue Jun 26, 2020 · 3 comments
Open

View Login Attempts #44

Grunticus03 opened this issue Jun 26, 2020 · 3 comments
Assignees

Comments

@Grunticus03
Copy link

Is there a way to configure the provider to log login attempts somewhere. I'd like to be able to see success/fail login attempts and the reason for the failure.

I'm currently running Server 2012 R2 with ADFS Auditing enabled and ADFSProvider 1.3.4.0, but in my testing, if I incorrectly enter my PIN+OTP combination after successfully authenticating with my username/password, I don't see a log of it anywhere. No entries in PrivacyIDEA Audit logs(3.2), no entries in PrivacyIDEA server logs (/var/log/privacyidea), and no entries in Windows Event Logs anywhere.

@sbidy sbidy self-assigned this Jun 28, 2020
@sbidy
Copy link
Owner

sbidy commented Jun 28, 2020

The provider normally doesn't log any action regarding the login flow. Normally the privacyIDEA log should show a "login fails" or "wrong token". But please have a look I to the docs.

I onyl log failure regarding the provider itself to lower the log overhead and for security reasons.

@Grunticus03
Copy link
Author

I asked about logging config over on the privacyIDEA forums and got a similar response, at least if I am understanding what @cornelinux said. It seems PrivacyIDEA doesn't necessarily log those events. Which, again if I'm understanding correctly, PrivacyIDEA-ADFS authentication attempts are flying under the radar.

What security concerns do you have about logging the request and result? If you enable ADFS Auditing, ADFS generates a massive amount of information regarding authentication attempts and their result. In fact, in regards to authentications that use PrivacyIDEA, log entries show ADFS passing the authentication off to an external authenticator.

@cornelinux
Copy link
Contributor

@wwalker0307 if the plugins sends a correctly formatted authentication request to privacyIDEA, privacyIDEA will log this request in the audit log and in the log file.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Projects
None yet
Development

No branches or pull requests

3 participants