Two-factor authentication for user logins

Bug #1271808 reported by Leo Xiong
12
This bug affects 2 people
Affects Status Importance Assigned to Milestone
Mahara
Confirmed
Wishlist
Unassigned

Bug Description

Allow users to configure two-factor authentication for an extra layer of security when logging into their accounts.

Tags: wishlist
Leo Xiong (leoxiong)
Changed in mahara:
assignee: nobody → Leo Xiong (leoxiong)
Revision history for this message
Kristina Hoeppner (kris-hoeppner) wrote :

Will that only work with internal auth or also with external auth methods? Would it be needed for external auth methods?

Changed in mahara:
status: New → In Progress
importance: Undecided → Wishlist
Revision history for this message
Leo Xiong (leoxiong) wrote :

It will be for internal auth only. Having the external auth users enter another code after they have signed would defeat the purpose of SSO.

Revision history for this message
Ghada El-Zoghbi (ghada-z) wrote :

Hello Mahara Team,

Just wondering if this is something to target for this year?

I think it's an important feature considering the current security environment and challenges.

Revision history for this message
Kristina Hoeppner (kris-hoeppner) wrote :

Hi Ghada,

We haven't targeted this yet as there is no sponsoring institution. If someone wants to use Two-Factor right now, they could achieve that with their SAML. Keycloak had been set up successfully with Mahara, but I don't know if TFA was enabled.

Cheers
Kristina

Changed in mahara:
status: In Progress → Confirmed
assignee: Leo Xiong (leoxiong) → nobody
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.