Unable to change password with TOTP MFA in TPX
search cancel

Unable to change password with TOTP MFA in TPX

book

Article ID: 444054

calendar_today

Updated On:

Products

TPX - Session Management

Issue/Introduction

Users encounter an error message when attempting to change or set a new password while using IBM MFA with Time-based One-Time Password (TOTP) in TPX. The error displayed is:

'Credentials have been omitted or are incorrect. try again or hit 'clear' to cancel.'


Logon attempts with the initial password and MFA token succeed, but the password change process fails despite successful changes through TSO/ISPF logon panels.

Environment

*   TPX Session Management 5.4

*   IBM MFA

*   RACF

*   Compound In-band Authentication enabled

Cause

In TPX 5.4, the existing MFA payload cannot be re-authenticated by the Multi-Factor Authentication (MFA) system during the password change flow. The security system requires a fresh authentication event to authorize the password update.

Resolution

When the expired message is prompted in the TPX logon panel, perform the following steps at the same time to change the password for an MFA-enabled user:
 
- In the 'Passcode' field: re-enter the current password + fresh TOTP code.

and

- In the 'NewPassword' field: enter the new password  


Only then
submit the panel to verify and save the change.

Additional Information

To eliminate the requirement for a new MFA token during re-verification, consider upgrading to TPX 5.5 as it includes Identity Tokens (IDT) functionality designed to streamline this process.