Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content

2FAuth

9 Topics 67 Posts
  • 2FAuth - Package Updates

    Pinned
    24
    0 Votes
    24 Posts
    6k Views
    Package UpdatesP
    [1.8.0] Update 2FAuth to 6.0.0 Full Changelog 2FAuth can now fetch icons from offline icon packs. Visit the new Icon documentation page to learn how to set them up (#203). The sort order of 2FA accounts is saved to user preferences when changed from the Manage mode. This allows the account list to be reordered automatically after a new account is registered. (#377). Groups can be reordered (manually, from the Group management view) (#419). A new filter is available to only show 2FA accounts that do not belong to any group (#430). The Import feature now supports Bitwarden export (#501). Group names now accept single quote (#465). Upon logging out, users are now redirected to the last login form they used: Password, SSO or Webauthn. (#478). Catchable errors that occur during the sending of a test email are now displayed in the UI to help you understand what's going on. issue #447 Unable to import Google Authenticator. issue #464 Import error not correctly reported in the GUI.
  • Chicken and egg - Onboarding 2FA mandatory cloudron user with 2FA app?

    9
    1 Votes
    9 Posts
    2k Views
    D
    @jdaviescoates said in Chicken and egg - Onboarding 2FA mandatory cloudron user with 2FA app?: @joseph said in Chicken and egg - Onboarding 2FA mandatory cloudron user with 2FA app?: vaultwarden is fine because it doesn't have Cloudron SSO Yet. Vaultwarden itself does now support OIDC. Or it looks like it will shortly - So would hope for Cloudron SSO to be integrated also! Yet in this case 2FA or the 2FA of Vaultwarden does not really matter, ultimately the issue is the same: How to setup Cloudron 2FA with a cloudron-installed 2FA application. @joseph said in Chicken and egg - Onboarding 2FA mandatory cloudron user with 2FA app?: Was discussing this with a friend yesteday and an analogy he gave me was this is like saving the password manager's password in the password manager itself This won't end well ultimately As mentioned, I get some of the security concerns of having the 2FA related application on a server requiring the same 2FA token to be usable, but there is also no denying the advantages: A central point to manage this app and related-mechanism rather than spreading thin over various servers / architecture / platform Especially on a product/service (Cloudron) that allow for user administrations, administration of the app itself and administration of the 2FA security setting on the same architecture In a limited context (single or small number of users), the resources cost related to on-boarding administering and supporting, often non or limited security-literate users, can be apprehended with a simpler concept, whatever this one might be (e.g. 2FA app of the user's choosing etc..). However, in a different scenario, where the number of user grows, SOPs make sense to be able to strike a reasonable balance between security, scalability and sustainability of the services. This is within this context that my original question fit in - chicken and egg? In the end, I would envisioned a situation where Cloudron admins have their 2FA hosted somewhere else (to mitigate security-related / lock up concerns), but end users would benefit from a 2FA Cloudron related app. Hopefully this make sense also - thank a lot for the inputs already!
  • 2FAuth- Leave user management to the app

    Solved
    6
    0 Votes
    6 Posts
    2k Views
    girishG
    Latest package as optional sso support. You have to reinstall 2FAuth and select it at installation time.
  • Unable to register/ create first user on account

    3
    1 Votes
    3 Posts
    698 Views
    J
    I think I could reproduce this . Sometimes, if you click login with OpenID it fails. But if you click again, it logs in.
  • OpenID is not timing out and cannot signin

    9
    0 Votes
    9 Posts
    2k Views
    nebulonN
    This is especially strange since you mentioned that other apps do work, so if you run that curl command from within a webterminal into that other app, it succeeds? Just in case if this is a hairpin issue maybe, checkout https://docs.cloudron.io/troubleshooting/#hairpin-nat
  • Sessions are not cleaned up

    3
    0 Votes
    3 Posts
    935 Views
    girishG
    I have moved the session files out of the data directory now. Maybe we should move to redis even later.
  • 3 Votes
    1 Posts
    297 Views
    No one has replied
  • Caution : cloudron portal in 2Fauth

    3
    2 Votes
    3 Posts
    1k Views
    timconsidineT
    @fbartels thanks for the clarification
  • 2FAuth - is a mystery...

    2fauth documentation how to
    9
    0 Votes
    9 Posts
    3k Views
    jdaviescoatesJ
    @LoudLemur said in 2FAuth - is a mystery...: Which Cloudron supported application could make use of 2Fauth? Any that support setting up 2FA, e.g. GitLab, probably loads of others. But it's not really the apps making use of it, it you using it to generate your 2FA codes to login to those apps.