duosecurity / duo_universal_atlassian

Duo two-factor authentication plugin for Jira or Confluence with the Duo Universal Prompt.
Other
3 stars 2 forks source link

Provide IP whitelisting option for application link support #4

Closed Nothing4You closed 7 months ago

Nothing4You commented 2 years ago

Now that https://github.com/duosecurity/duo_confluence/pull/7 is closed due to the repo being deprecated, let's continue this issue here.

I don't expect this to be ever resolved due to DUO apparently not caring enough about paying customers, considering that a solution for this issue has been presented almost 4 years ago and being rejected with

Every hole we purposely make in the plugin creates that much more of a vulnerability.

while at the same time suggesting to

bypass[es] Duo for all listed endpoints

in the official support article https://help.duo.com/s/article/1364, without the option of restricting that to IPs.

This is a crucial requirement to be able to use application links between applications securely without exposing endpoints without DUO to all other clients.

BenGreenGDIT commented 2 years ago

I'm at the same point with this issue. Confluence/Jira integration is broken. Is there a plan to support this with the Universal plugin, or should I discontinue using Duo for 2FA?

Thanks.

AaronAtDuo commented 7 months ago

Closing this issue due to repository deprecation and Atlassian end of support for its on-prem products.