Bobcares

WeSupport

Call Us! 1-800-383-5193
Call Us! 1-800-383-5193
Call Us! 1-800-383-5193

Need Help?

Emergency Response Time custom

Our experts have had an average response time of 11.06 minutes in March 2021 to fix urgent issues.

We will keep your servers stable, secure and fast at all times for one fixed price.

Unable To Login Using Two Factor Authentication in Nagios

by | Apr 25, 2021

Unable To Login Using Two Factor Authentication in Nagios? We can help you.

Two-factor authentication requires the end-user to provide a token after initially logging into Nagios XI. We will receive the token as a email and if we don’t use it, it will expire after a set amount of time.

As part of our Server Management Services, we assist our customers with several Nagios queries.

Today, let us see how to resolve issues with two-factor authentication.

 

Unable To Login Using Two Factor Authentication in Nagios

Moving ahead, let us discuss things we need to do to make it work.

Enable Two Factor Authentication

Initially, login as an administrative account and navigate to Admin > System Config > System Settings. On the Security tab, we will find the two-factor authentication settings.

  • Enable Two Factor Auth: We need to check this box to enable the functionality
  • TwoFactor Token Timeout: This setting defines how long the token will remain active before it expires.
  • Two Factor Cookie: It allows the end-user to store a cookie on their computer that will not prompt them for the two-factor token when they log in.
  • Two Factor Cookie Timeout: This setting defines how long the cookie remains valid before it expires.

After making these selections, we click the Update Settings button.

Once done, we will see the below prompt after logging into Nagios XI:

Unable To Login Using Two Factor Authentication in Nagios

Here, the “Remember this browser” checkbox will only appear if the “Two Factor Cookie” setting is enabled.

Confirm Correct Email Address

If we do not receive the emails, then the first step is to confirm the email address is correct via Admin > Users > Manage Users.

Cannot Login As nagiosadmin

If the only administrative account we have is the nagiosadmin account, it can lock us out of Nagios XI.

If we configure the nagiosadmin account with the default root@localhost email address, this can happen.

However, we can retrieve the token by looking at the /var/spool/mail/root mailbox on the Nagios XI server:

grep -A2 ‘token below’ /var/spool/mail/root
To continue logging in, please enter the token below:

16616
—
To continue logging in, please enter the token below:<br />
<br />
16616<br />

The output shows the token is 16616. We can use this to log in to the Nagios XI system as the nagiosadmin account. Then, we can change the nagiosadmin account to the correct email address.

If we fail to retrieve the token from the /var/spool/mail/root mailbox, then it is likely that the nagiosadmin account has an email address we are unaware of. In this scenario, we have to reset the nagiosadmin account which also disables two-factor authentication.

To reset nagiosadmin password, we open an SSH or direct console session to Nagios XI host and run:

/usr/local/nagiosxi/scripts/reset_nagiosadmin_password.php –password=newpassword

If we want to add special characters in the password, we should escape them with “\”.

For example, suppose, we want it to be “$new password#”:

/usr/local/nagiosxi/scripts/reset_nagiosadmin_password.php –password=\$new\ password\#

[Need help with the solution? We can help you]

 

Conclusion

To conclude, today, we saw how our Support Techs resolve Two Factor Authentication error in Nagios.

PREVENT YOUR SERVER FROM CRASHING!

Never again lose customers to poor server speed! Let us help you.

Our server experts will monitor & maintain your server 24/7 so that it remains lightning fast and secure.

GET STARTED

var google_conversion_label = "owonCMyG5nEQ0aD71QM";

0 Comments

Submit a Comment

Your email address will not be published. Required fields are marked *

Privacy Preference Center

Necessary

Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.

PHPSESSID - Preserves user session state across page requests.

gdpr[consent_types] - Used to store user consents.

gdpr[allowed_cookies] - Used to store user allowed cookies.

PHPSESSID, gdpr[consent_types], gdpr[allowed_cookies]
PHPSESSID
WHMCSpKDlPzh2chML

Statistics

Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.

_ga - Preserves user session state across page requests.

_gat - Used by Google Analytics to throttle request rate

_gid - Registers a unique ID that is used to generate statistical data on how you use the website.

smartlookCookie - Used to collect user device and location information of the site visitors to improve the websites User Experience.

_ga, _gat, _gid
_ga, _gat, _gid
smartlookCookie

Marketing

Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.

IDE - Used by Google DoubleClick to register and report the website user's actions after viewing or clicking one of the advertiser's ads with the purpose of measuring the efficacy of an ad and to present targeted ads to the user.

test_cookie - Used to check if the user's browser supports cookies.

1P_JAR - Google cookie. These cookies are used to collect website statistics and track conversion rates.

NID - Registers a unique ID that identifies a returning user's device. The ID is used for serving ads that are most relevant to the user.

DV - Google ad personalisation

IDE, test_cookie, 1P_JAR, NID, DV, NID
IDE, test_cookie
1P_JAR, NID, DV
NID
hblid

Security

These are essential site cookies, used by the google reCAPTCHA. These cookies use an unique identifier to verify if a visitor is human or a bot.

SID, APISID, HSID, NID, PREF
SID, APISID, HSID, NID, PREF