Cloudron makes it easy to run web apps like WordPress, Nextcloud, GitLab on your server. Find out more or install now.


Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • Bookmarks
  • Search
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

Cloudron Forum

Apps - Status | Demo | Docs | Install
  1. Cloudron Forum
  2. Ctfreak
  3. Disable Default Admin or Setup 2FA

Disable Default Admin or Setup 2FA

Scheduled Pinned Locked Moved Solved Ctfreak
12 Posts 5 Posters 2.3k Views 5 Watching
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • nebulonN Offline
    nebulonN Offline
    nebulon
    Staff
    wrote on last edited by
    #2

    I am not sure ctfreak has any 2FA for internal users. Also it does require an admin account pre-setup. I guess the only way to secure this is to set a strong unique password for it at the moment.

    1 Reply Last reply
    1
    • girishG Offline
      girishG Offline
      girish
      Staff
      wrote on last edited by
      #3

      Maybe @jypelle (ctfreak's author) knows

      1 Reply Last reply
      0
      • jypelleJ Offline
        jypelleJ Offline
        jypelle
        wrote on last edited by
        #4

        Hello,

        Indeed, there must be at least one local admin account, with the purpose of ensuring access is still possible even if the OIDC server becomes unavailable.

        If the goal is to secure access, @nebulon 's suggestion (a strong unique password) is the right one.

        D 1 Reply Last reply
        2
        • nebulonN nebulon marked this topic as a question on
        • nebulonN nebulon has marked this topic as solved on
        • jypelleJ jypelle

          Hello,

          Indeed, there must be at least one local admin account, with the purpose of ensuring access is still possible even if the OIDC server becomes unavailable.

          If the goal is to secure access, @nebulon 's suggestion (a strong unique password) is the right one.

          D Offline
          D Offline
          DualOSWinWiz
          wrote on last edited by DualOSWinWiz
          #5

          @jypelle is their is autoblock account option exist after certain number of wrong password attempt??

          1 Reply Last reply
          0
          • jypelleJ Offline
            jypelleJ Offline
            jypelle
            wrote on last edited by
            #6

            No, but there is at least a one-second delay between each attempt.

            Let's imagine a bot attempting to log in with a different password every second. In 5 years, it would have time to test 5x365x24x3600 = 1.5x10^8 combinations.

            Now, if you choose a password of only 10 characters from [a-zA-Z0-9], that gives 8.4x10^17 combinations.

            Before the bot finds your password, you have at least a few million years ahead of you...

            1 Reply Last reply
            2
            • D Offline
              D Offline
              DualOSWinWiz
              wrote on last edited by
              #7

              Lollzz thanks

              1 Reply Last reply
              0
              • jypelleJ Offline
                jypelleJ Offline
                jypelle
                wrote on last edited by
                #8

                @DualOSWinWiz With release 1.17.0, there is now a 5-second delay between failed login attempts.

                1 Reply Last reply
                3
                • D Offline
                  D Offline
                  DualOSWinWiz
                  wrote last edited by
                  #9

                  @jypelle I am planning for Sovereign / Business license due to AES Secret encryption for credentials before purchasing can i apply that on a cloudron application instance?

                  1 Reply Last reply
                  0
                  • jypelleJ Offline
                    jypelleJ Offline
                    jypelle
                    wrote last edited by
                    #10

                    Hi @dualoswinwiz

                    AES secret encryption requires two things that aren't possible on a Cloudron instance: direct access to the configuration file to set up the encryption key, and the ability to stop and restart the instance during the encryption process. For this reason, you'll need a manual installation to use this feature.

                    Let me know if you have any questions about the setup!

                    robiR 1 Reply Last reply
                    0
                    • D Offline
                      D Offline
                      DualOSWinWiz
                      wrote last edited by
                      #11

                      Please check my DM

                      1 Reply Last reply
                      0
                      • jypelleJ jypelle

                        Hi @dualoswinwiz

                        AES secret encryption requires two things that aren't possible on a Cloudron instance: direct access to the configuration file to set up the encryption key, and the ability to stop and restart the instance during the encryption process. For this reason, you'll need a manual installation to use this feature.

                        Let me know if you have any questions about the setup!

                        robiR Offline
                        robiR Offline
                        robi
                        wrote last edited by
                        #12

                        @jypelle this is possible if the package is adjusted to have the config file available in /app/data and a script to restart/reload the relevant service.

                        Conscious tech

                        1 Reply Last reply
                        0

                        Hello! It looks like you're interested in this conversation, but you don't have an account yet.

                        Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.

                        With your input, this post could be even better 💗

                        Register Login
                        Reply
                        • Reply as topic
                        Log in to reply
                        • Oldest to Newest
                        • Newest to Oldest
                        • Most Votes


                        • Login

                        • Don't have an account? Register

                        • Login or register to search.
                        • First post
                          Last post
                        0
                        • Categories
                        • Recent
                        • Tags
                        • Popular
                        • Bookmarks
                        • Search