Open schemen opened 3 years ago
fyi @andryyy as seen @ telegram
I am new to mailcow. But yes, these will be two very solid features to have.
I think this can be great to add @DerLinkman
+1 It would be great to have a set of one-time-use backup codes to store somewhere safe in case my Yubikey breaks
It would be fantastic to also register my 2 backup YubiKeys.
Summary
The implementation is already great! I think it can be expanded by a little bit to enhance the experience greatly though!
Multi-Factor You can add Webauthn/FIDO2 and a single second factor. Multifactor would allow for any method to be added to an account. If you lose your key, and your secondary, you can access with TOTP. If your TOTP is somehow inaccessible, you can use your keys or ->
Enhancement: 2FA Recovery codes Currently, if you lose access to you need to log into the server and remove the 2fa from an account, one time recovery codes would be a great enhancement though
Motivation
Enjoy greater security as well as reliable ways to recover an account.