How to get sqlplus to work with radius, DUO and a yubikey?
We are having trouble diagnosing why one of our users, who uses a yubikey for MFA, to properly authenticate against radius. The user is using TOAD, but we have found that the problems persist in other clients including sqlplus. We want to get sqlplus to work first, and then move on to the GUIs.
The user can successfully authenticate with Radius (no duo) using TOAD and sqlplus. And the user can successfully use DUO with the yubikey in other applications (eg, our VPN has DUO, and that works fine). When we switch to a database that uses DUO radius, we start having problems. Initially, the problem was ora-1017 (invalid username/password). Then we tried using a comma and the yubikey string, which generated ora-28035 (cannot get a session key). We also tried a one-time "emergency" 6-digit duo code in place of the yubikey string, which worked. It would seem that sqlplus is unable to parse