Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps | Demo | Docs | Install
  1. Cloudron Forum
  2. Ctfreak
  3. Disable Default Admin or Setup 2FA

Disable Default Admin or Setup 2FA

Scheduled Pinned Locked Moved Solved Ctfreak
8 Posts 4 Posters 1.1k Views 4 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • D Offline
      D Offline
      DualOSWinWiz
      wrote on last edited by
      #1

      is there is any way of either activate 2FA on default Admin user or could disable it?

      1 Reply Last reply
      0
      • nebulonN Offline
        nebulonN Offline
        nebulon
        Staff
        wrote on last edited by
        #2

        I am not sure ctfreak has any 2FA for internal users. Also it does require an admin account pre-setup. I guess the only way to secure this is to set a strong unique password for it at the moment.

        1 Reply Last reply
        1
        • girishG Offline
          girishG Offline
          girish
          Staff
          wrote on last edited by
          #3

          Maybe @jypelle (ctfreak's author) knows

          1 Reply Last reply
          0
          • jypelleJ Offline
            jypelleJ Offline
            jypelle
            wrote on last edited by
            #4

            Hello,

            Indeed, there must be at least one local admin account, with the purpose of ensuring access is still possible even if the OIDC server becomes unavailable.

            If the goal is to secure access, @nebulon 's suggestion (a strong unique password) is the right one.

            D 1 Reply Last reply
            2
            • nebulonN nebulon marked this topic as a question on
            • nebulonN nebulon has marked this topic as solved on
            • jypelleJ jypelle

              Hello,

              Indeed, there must be at least one local admin account, with the purpose of ensuring access is still possible even if the OIDC server becomes unavailable.

              If the goal is to secure access, @nebulon 's suggestion (a strong unique password) is the right one.

              D Offline
              D Offline
              DualOSWinWiz
              wrote on last edited by DualOSWinWiz
              #5

              @jypelle is their is autoblock account option exist after certain number of wrong password attempt??

              1 Reply Last reply
              0
              • jypelleJ Offline
                jypelleJ Offline
                jypelle
                wrote on last edited by
                #6

                No, but there is at least a one-second delay between each attempt.

                Let's imagine a bot attempting to log in with a different password every second. In 5 years, it would have time to test 5x365x24x3600 = 1.5x10^8 combinations.

                Now, if you choose a password of only 10 characters from [a-zA-Z0-9], that gives 8.4x10^17 combinations.

                Before the bot finds your password, you have at least a few million years ahead of you...

                1 Reply Last reply
                2
                • D Offline
                  D Offline
                  DualOSWinWiz
                  wrote on last edited by
                  #7

                  Lollzz thanks

                  1 Reply Last reply
                  0
                  • jypelleJ Offline
                    jypelleJ Offline
                    jypelle
                    wrote on last edited by
                    #8

                    @DualOSWinWiz With release 1.17.0, there is now a 5-second delay between failed login attempts.

                    1 Reply Last reply
                    3
                    Reply
                    • Reply as topic
                    Log in to reply
                    • Oldest to Newest
                    • Newest to Oldest
                    • Most Votes


                      • Login

                      • Don't have an account? Register

                      • Login or register to search.
                      • First post
                        Last post
                      0
                      • Categories
                      • Recent
                      • Tags
                      • Popular
                      • Bookmarks
                      • Search