Nike-Inc / gimme-aws-creds

A CLI that utilizes Okta IdP via SAML to acquire temporary AWS credentials
Apache License 2.0
925 stars 263 forks source link

MFA issue #52

Closed satssin closed 6 years ago

satssin commented 6 years ago

Hi Team, I have user he got MFA setup for this account in OKTA, however when he run gimme-aws-creds command to generate credentials it doesn't ask for MFA and after selecting the AWS roles it just through this exception screen shot 2018-04-19 at 4 28 40 pm

epierce commented 6 years ago

My guess on the first issue would be that there's an issue with the sign-on policy in Okta. Does the user get prompted for MFA when they access the AWS console with a browser?

The error message you're seeing is because you've got an invalid region in your AWS configuration (~/.aws/config). From the URL in the error message, you have the default region set to us-east instead of us-east-1 or us-east-2

satssin commented 6 years ago

Thank you, Eric , we figured it out, it was the problem with the ~/.aws/config file.

Satish Kumar|Manager, DevOps Solutions | GTS|MCSE,RHCA,ITIL,OCWA,SCSA,AWS,CCNA Email:satish.kumar1@mheducation.com|Cell:9732896721

From: Eric Pierce notifications@github.com Reply-To: Nike-Inc/gimme-aws-creds reply@reply.github.com Date: Friday, April 20, 2018 at 3:58 PM To: Nike-Inc/gimme-aws-creds gimme-aws-creds@noreply.github.com Cc: "Kumar, Satish" satish.kumar1@mheducation.com, Author author@noreply.github.com Subject: Re: [Nike-Inc/gimme-aws-creds] MFA issue (#52)

My guess on the first issue would be that there's an issue with the sign-on policy in Okta. Does the user get prompted for MFA when they access the AWS console with a browser?

The error message you're seeing is because you've got an invalid region in your AWS configuration (~/.aws/config). From the URL in the error message, you have the default region set to us-east instead of us-east-1 or us-east-2

— You are receiving this because you authored the thread. Reply to this email directly, view it on GitHubhttps://na01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgithub.com%2FNike-Inc%2Fgimme-aws-creds%2Fissues%2F52%23issuecomment-383205704&data=01%7C01%7Csatish.kumar1%40mheducation.com%7C96942bf9689d478e71e608d5a6f90431%7Cf919b1efc0c347358fca0928ec39d8d5%7C0&sdata=du4heIjbVOWtlkR%2BjuHkOQz1zkw9w80fn%2FZjYuTef3E%3D&reserved=0, or mute the threadhttps://na01.safelinks.protection.outlook.com/?url=https%3A%2F%2Fgithub.com%2Fnotifications%2Funsubscribe-auth%2FAEQLelKRrWBOmwa2L0hJIbzyWpki5AWBks5tqj3GgaJpZM4Tccq1&data=01%7C01%7Csatish.kumar1%40mheducation.com%7C96942bf9689d478e71e608d5a6f90431%7Cf919b1efc0c347358fca0928ec39d8d5%7C0&sdata=8qj9s1KGbkh88TLTj1cYxURBtic72N7P7AWn93HSbkc%3D&reserved=0.

The information contained in this message may be confidential and/or constitute a privileged attorney-client document. If the reader of this message is not the intended recipient, or an employee or agent responsible for delivering this message to the intended recipient, you are hereby notified that any dissemination, distribution or copying of this communication is strictly prohibited. If you have received this communication in error, please notify McGraw-Hill Education immediately by replying to the message and deleting it from your computer. Thank you.