<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[2FA enforcement issue on Cloudron 9.0.13]]></title><description><![CDATA[<p dir="auto">Hi,</p>
<p dir="auto">I have been facing issues with 2FA and 2FA enforcement since migrating to 9.0.x (not sure if this came with 9.0 or the later minor updates).</p>
<ol>
<li>(minor issue - arguably more of a discussion topic) Resetting 2FA for a user.<br />
At the moment, to reset 2FA for a user, you need to edit the user profile and click on the "Reset 2FA" button.<br />
The Reset 2FA button then disappear, but you remain on the user profile, with for only further action the "Cancel" button (the "Save" button remain greyed out / inactive).<br />
I found that this leaves doubt as to whether the "reset 2FA" action has been taken into account / has worked.<br />
(Only testing reveals that is has)</li>
</ol>
<p dir="auto">An option would be to make the save button active once the "Reset 2FA" button has been pressed.<br />
An alternative would be to display a validation message confirming that the 2FA has been reset for the user</p>
<ol start="2">
<li>(major issue) 2FA enforcement does not work.<br />
Consider this: my server has the User &gt; Settings &gt; "Require users to set up 2FA" turned on (it was already on prior to V9 upgrade).<br />
Problem: at the moment, there is no enforcement of 2FA registration for the end user, either for a brand new created user or when resetting 2FA for an existing user.<br />
Upon the related user login, there no prompt to the user to register for 2FA. The only way to do so, is voluntarily: by going into the user profile and clicking "enable 2FA". So anything but a enforcement/requirement.</li>
</ol>
<p dir="auto">Turning the server setting off/on has no incidence on the situation - I have also tested this connecting from multiple device/browser with no differences in the result.<br />
I see no relevant log entries and the server appears to be healthy.</p>
<p dir="auto">This is of course an important issue, and create a security hole.<br />
The question is whether I am the only one experiencing this on our servers or if some other fellow cloudronians are too?</p>
<p dir="auto">I am also unsure where to look further to trouble shoot this, so any help is appreciated.</p>
<p dir="auto">Thanks,</p>
]]></description><link>https://forum.cloudron.io/topic/14654/2fa-enforcement-issue-on-cloudron-9.0.13</link><generator>RSS for Node</generator><lastBuildDate>Wed, 15 Jul 2026 11:13:13 GMT</lastBuildDate><atom:link href="https://forum.cloudron.io/topic/14654.rss" rel="self" type="application/rss+xml"/><pubDate>Mon, 01 Dec 2025 15:31:08 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to 2FA enforcement issue on Cloudron 9.0.13 on Mon, 01 Dec 2025 19:57:06 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/teiluj" aria-label="Profile: Teiluj">@<bdi>Teiluj</bdi></a> said in <a href="/post/116298">2FA enforcement issue on Cloudron 9.0.13</a>:</p>
<blockquote>
<p dir="auto">(major issue) 2FA enforcement does not work.</p>
</blockquote>
<p dir="auto">Fixed in <a href="https://git.cloudron.io/platform/box/-/commit/76f2c5f9fc7ea673ddbe02e5aed9e691c85cd5c6" target="_blank" rel="noopener noreferrer nofollow ugc">https://git.cloudron.io/platform/box/-/commit/76f2c5f9fc7ea673ddbe02e5aed9e691c85cd5c6</a></p>
<p dir="auto">Thanks for reporting!</p>
]]></description><link>https://forum.cloudron.io/post/116306</link><guid isPermaLink="true">https://forum.cloudron.io/post/116306</guid><dc:creator><![CDATA[girish]]></dc:creator><pubDate>Mon, 01 Dec 2025 19:57:06 GMT</pubDate></item><item><title><![CDATA[Reply to 2FA enforcement issue on Cloudron 9.0.13 on Mon, 01 Dec 2025 18:21:32 GMT]]></title><description><![CDATA[<p dir="auto"><a class="plugin-mentions-user plugin-mentions-a" href="/user/teiluj" aria-label="Profile: Teiluj">@<bdi>Teiluj</bdi></a> said in <a href="/post/116298">2FA enforcement issue on Cloudron 9.0.13</a>:</p>
<blockquote>
<p dir="auto">(minor issue - arguably more of a discussion topic) Resetting 2FA for a user.</p>
</blockquote>
<p dir="auto">That makes sense. I have made disabling 2FA a separate action now, and it's not part of the user edit dialog. <a href="https://git.cloudron.io/platform/box/-/commit/6432851a783c0016fdd34e9f700b5aacf9971170" target="_blank" rel="noopener noreferrer nofollow ugc">https://git.cloudron.io/platform/box/-/commit/6432851a783c0016fdd34e9f700b5aacf9971170</a></p>
]]></description><link>https://forum.cloudron.io/post/116302</link><guid isPermaLink="true">https://forum.cloudron.io/post/116302</guid><dc:creator><![CDATA[girish]]></dc:creator><pubDate>Mon, 01 Dec 2025 18:21:32 GMT</pubDate></item></channel></rss>