Support Forum
The Forums are a place to find answers on a range of Fortinet products from peers and product experts.
razel0
New Contributor

Yubico Authenticator App for Forticloud log in

Set up Forticloud MFA through Yubico app in the usual way by scanning the QR code and thought that it worked but when I tried to sign in today the actual code in the authenticator app is grayed out. Is anyone else using this method and how did you get it to work?

3 REPLIES 3
Stephen_G
Community Manager
Community Manager

Hello razel0,

 

Thank you for using the Community Forum. I will seek to get you an answer or help. We will reply to this thread with an update as soon as possible. 

Regards,
Stephen - Fortinet Community Team
Stephen_G
Community Manager
Community Manager

Hi again,

 

We are still trying to get you an answer or help. We will reply as soon as we are able.

 

If anyone else has any advice, please feel free to contribute!

Stephen - Fortinet Community Team
Jean-Philippe_P
Community Manager
Community Manager

Hello razel0,

 

I found this solution. Can you tell us if it helps?

 

Your situation with FortiCloud MFA and the Yubico Authenticator app showing a grayed-out code is unusual but not unheard of. Here’s a detailed breakdown of what might be happening and how to resolve it:

 

Why is the code grayed out in Yubico Authenticator?

  • Grayed-out codes usually indicate the code is expired or the app is not properly syncing the time. MFA apps rely on time-based one-time passwords (TOTP), so if the device’s clock is off, it can cause codes to be invalid or appear inactive.
  • Another possibility is the Yubico app might not fully support the FortiCloud MFA token format or the QR code parameters.

 

Steps to troubleshoot and fix:

  1. Check Device Time Settings:

    • Ensure your phone’s time is set to automatic and synchronized with the network time.
    • On iOS or Android, confirm the time zone and clock are accurate.
    • If possible, toggle automatic time off and on again to force resync.
  2. Re-scan the QR Code:

    • Delete the existing FortiCloud MFA entry in the Yubico app.
    • Re-scan the QR code from FortiCloud MFA setup.
    • Make sure you are scanning the correct QR code for TOTP (not a different type of MFA).

  3. Try Another Authenticator App:

    • FortiCloud supports standard TOTP apps like Google Authenticator, Microsoft Authenticator, or Authy.
    • Try setting up MFA with one of these apps to verify if the issue is specific to Yubico Authenticator.
    • If it works on another app, the problem is likely compatibility with Yubico.

  4. Check FortiCloud MFA Setup:

    • Confirm that FortiCloud is expecting a TOTP-based MFA and not a different method like push or hardware token.
    • Sometimes, FortiCloud MFA QR codes might include extra parameters that some authenticators don’t handle correctly.

  5. Update Yubico Authenticator:

    • Ensure the app is updated to the latest version.
    • Older versions might have bugs or incomplete TOTP support.

  6. Contact Fortinet Support or Community Forums:

    • Fortinet’s user forums and support channels often have specific guidance for MFA issues.
    • Other users may have reported similar issues with Yubico.

Summary:

  • The grayed-out code usually means the code is expired or the app time is out of sync.
  • Sync your phone’s time, re-scan the QR code, or try a different authenticator app.
  • FortiCloud MFA is standard TOTP, so Google Authenticator or Authy often work seamlessly.
  • If you want to keep using Yubico, verify app updates and compatibility.
Regards,
Jean-Philippe - Fortinet Community Team
Announcements
Check out our Community Chatter Blog! Click here to get involved
Labels
Top Kudoed Authors