Nike-Inc / gimme-aws-creds

A CLI that utilizes Okta IdP via SAML to acquire temporary AWS credentials
Apache License 2.0
919 stars 262 forks source link

"Must Enroll in MFA before using this tool" - Despite having MFA Enrolled #471

Open vennemp opened 2 months ago

vennemp commented 2 months ago

Try to use yubikey for auth. Also get this error while using Okta Push.

I get this error whether querying creds or trying running "--action-setup-fido-authenticator"

Challenge with security keys ... Please enter PIN:

Touch your authenticator device now...

Received WebAuthn token response You must enroll in MFA before using this tool.

But I have enrolled in MFA. It's enforced on my org for all authentication.