Unable to Login to Two Applications with Same Yubi Key

Overview

A user who registers a YubiKey in one application is unable to use the same device to log in to a second application. The user expects to use a YubiKey to log in to multiple applications after it is registered once. When attempting to log in to the second application, the following error message is displayed:

Security Key Verification Failed

This issue occurs in scenarios involving two applications with different domains configured (a canonical and a custom domain).

Applies To

  • Yubikey
  • Webauthn
  • Two applications with different domains configured

Cause

The issue is caused by a domain mismatch between the applications. While the YubiKey is associated with a user's profile, the association is tied to a single domain, either the custom domain or the tenant's canonical domain, but not both. The MFA registration succeeds on the original application because the domain is correct, but it fails on the second application due to a Relying Party mismatch.

Solution

To resolve the Multi-Factor Authentication (MFA) domain mismatch, switch both applications to use the same domain (either the custom domain or the canonical domain).

Recommended content

No recommended content found...