We are currently evaluating the Secure Login plugin (v1.2.2) on JIRA Server 7.1.1.
Most of the users are not able to confirm the initial PIN. Instead, right after entering the PIN and clicking the "Check PIN" button, they are again lead through the introductory popups and presented with a new QR image.
It seems as if the system is not accepting the PIN. We already verified that the system clock is synchronized, and the clock on the mobile device (with FreeOTP) is correct as well.
(We are testing the add-on for Confluence at the same time, and that works perfectly in that regard, with the same mobile device.)
The users who reported this have not been on that test system before, so this cannot be caused by old cached content or old cookies.
From the time when the user is presented a new QR code, an admin can see that a code is set for the user (by attempting to delete that code from the profile page), even before the user has entered a PIN for the first time.
However, the user's PIN is not accepted.
Is this a known issue?
Is there anything we can do to trace this down?