agdsn / pycroft

The AG DSN management system
Apache License 2.0
19 stars 9 forks source link

Two Factor Authentication #392

Open Paktosan opened 3 years ago

Paktosan commented 3 years ago

It would be a nice security feature to allow using TFA during Pycroft login. Web browsers support hardware tokens like the Yubikey or Apples Macbook Fingerprint Readers through https://webauthn.guide/

Lodifice commented 3 years ago

TFA as in "three factor authentication" (idm+ldap+hardware token) or as in "too fucking annoying"? :P

MarauderXtreme commented 3 years ago

TFA as in "three factor authentication" (idm+ldap+hardware token) or as in "too fucking annoying"? :P

Well. We could substitute Yubikeys OTPs or webauthn for passwords. Additionally the suggestion was to enable not to enforce TFA/MFA