Skip to content
English

Two-factor authentication

A one-time code on top of the password. Users can turn it on themselves, and an administrator can use policy to require it of everyone or of administrators. Someone required to enroll goes straight into enrollment once the password passes, and enters the system when it is done, without signing in again.

The two-factor step of signing in

An authenticator application that supports TOTP.

On the two-step verification card of the Profile page:

  1. Press “Generate secret”.
  2. Scan the QR code with the authenticator. The QR code is generated locally in the browser. When scanning is not possible, the page also offers the secret string and the otpauth address to enter by hand.
  3. Enter the 6-digit code the authenticator shows and press “Enable MFA”.

Turning it off yourself requires the current password.

On the Security Policies page, change “two-factor authentication scope” from off to administrators only or all users; it ships off. Someone under the requirement who has not enrolled sees the enrollment step on the login page once the password passes: scan, enter the code, finish enrollment, and sign in. The temporary credential used for enrollment is valid for 15 minutes and works only for enrollment. It reaches no other API and opens no connection.

For an account that has it on, the code step follows the password. The temporary credential in this stage is valid for 5 minutes and works only for verification. A code that has been used cannot be used again, and a replay is blocked. A wrong code and a wrong password share one lockout counter.

When a user has changed phones and has no recovery code, an administrator disables two-factor authentication for that account on the Users page, and the user can enroll again. This action leaves a record carrying the administrator’s identity.

  • Enrollment, self-service removal, and administrator rescue each leave a record, and the rescue one carries the administrator who performed it.
  • A failed code verification leaves a record.
  • A refused code replay leaves a record.
  • An already enrolled account refused when it tries to re-enroll with an enrollment credential leaves a record as well.