Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps - Status | Demo | Docs | Install
  1. Cloudron Forum
  2. Ctfreak
  3. Disable Default Admin or Setup 2FA

Disable Default Admin or Setup 2FA

Scheduled Pinned Locked Moved Solved Ctfreak
12 Posts 5 Posters 2.3k Views 5 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • D Offline
    D Offline
    DualOSWinWiz
    wrote on last edited by
    #1

    is there is any way of either activate 2FA on default Admin user or could disable it?

    1 Reply Last reply
    0
    • nebulonN Offline
      nebulonN Offline
      nebulon
      Staff
      wrote on last edited by
      #2

      I am not sure ctfreak has any 2FA for internal users. Also it does require an admin account pre-setup. I guess the only way to secure this is to set a strong unique password for it at the moment.

      1 Reply Last reply
      1
      • girishG Offline
        girishG Offline
        girish
        Staff
        wrote on last edited by
        #3

        Maybe @jypelle (ctfreak's author) knows

        1 Reply Last reply
        0
        • jypelleJ Offline
          jypelleJ Offline
          jypelle
          wrote on last edited by
          #4

          Hello,

          Indeed, there must be at least one local admin account, with the purpose of ensuring access is still possible even if the OIDC server becomes unavailable.

          If the goal is to secure access, @nebulon 's suggestion (a strong unique password) is the right one.

          D 1 Reply Last reply
          2
          • nebulonN nebulon marked this topic as a question on
          • nebulonN nebulon has marked this topic as solved on
          • jypelleJ jypelle

            Hello,

            Indeed, there must be at least one local admin account, with the purpose of ensuring access is still possible even if the OIDC server becomes unavailable.

            If the goal is to secure access, @nebulon 's suggestion (a strong unique password) is the right one.

            D Offline
            D Offline
            DualOSWinWiz
            wrote on last edited by DualOSWinWiz
            #5

            @jypelle is their is autoblock account option exist after certain number of wrong password attempt??

            1 Reply Last reply
            0
            • jypelleJ Offline
              jypelleJ Offline
              jypelle
              wrote on last edited by
              #6

              No, but there is at least a one-second delay between each attempt.

              Let's imagine a bot attempting to log in with a different password every second. In 5 years, it would have time to test 5x365x24x3600 = 1.5x10^8 combinations.

              Now, if you choose a password of only 10 characters from [a-zA-Z0-9], that gives 8.4x10^17 combinations.

              Before the bot finds your password, you have at least a few million years ahead of you...

              1 Reply Last reply
              2
              • D Offline
                D Offline
                DualOSWinWiz
                wrote on last edited by
                #7

                Lollzz thanks

                1 Reply Last reply
                0
                • jypelleJ Offline
                  jypelleJ Offline
                  jypelle
                  wrote on last edited by
                  #8

                  @DualOSWinWiz With release 1.17.0, there is now a 5-second delay between failed login attempts.

                  1 Reply Last reply
                  3
                  • D Offline
                    D Offline
                    DualOSWinWiz
                    wrote last edited by
                    #9

                    @jypelle I am planning for Sovereign / Business license due to AES Secret encryption for credentials before purchasing can i apply that on a cloudron application instance?

                    1 Reply Last reply
                    0
                    • jypelleJ Offline
                      jypelleJ Offline
                      jypelle
                      wrote last edited by
                      #10

                      Hi @dualoswinwiz

                      AES secret encryption requires two things that aren't possible on a Cloudron instance: direct access to the configuration file to set up the encryption key, and the ability to stop and restart the instance during the encryption process. For this reason, you'll need a manual installation to use this feature.

                      Let me know if you have any questions about the setup!

                      robiR 1 Reply Last reply
                      0
                      • D Offline
                        D Offline
                        DualOSWinWiz
                        wrote last edited by
                        #11

                        Please check my DM

                        1 Reply Last reply
                        0
                        • jypelleJ jypelle

                          Hi @dualoswinwiz

                          AES secret encryption requires two things that aren't possible on a Cloudron instance: direct access to the configuration file to set up the encryption key, and the ability to stop and restart the instance during the encryption process. For this reason, you'll need a manual installation to use this feature.

                          Let me know if you have any questions about the setup!

                          robiR Offline
                          robiR Offline
                          robi
                          wrote last edited by
                          #12

                          @jypelle this is possible if the package is adjusted to have the config file available in /app/data and a script to restart/reload the relevant service.

                          Conscious tech

                          1 Reply Last reply
                          0

                          Hello! It looks like you're interested in this conversation, but you don't have an account yet.

                          Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

                          With your input, this post could be even better 💗

                          Register Login
                          Reply
                          • Reply as topic
                          Log in to reply
                          • Oldest to Newest
                          • Newest to Oldest
                          • Most Votes


                          • Login

                          • Don't have an account? Register

                          • Login or register to search.
                          • First post
                            Last post
                          0
                          • Categories
                          • Recent
                          • Tags
                          • Popular
                          • Bookmarks
                          • Search