Two Factor Authentication (2FA)
Two factor authentication is now available for local accounts from 1.9
Two factor authentication can be enforced for all local accounts with the given application property: system.security.local.account.2fa.enforced
There are no mechanisms to select specific local accounts to be enabled or disabled as of now.
User Setup
Upon the first login after 2FA activation, users will see the following page after successful user/password login:
Any authenticator app that is compatible with Google Authenticator specification can be used: Google Authenticator, Microsoft Authenticator, Authy …
Once the QR code has been scanned, you can enter the one time password generated by the authenticator app to verify your setup and login to the platform.
Managing authentication factors
Tracking
Factors are stored in the authentication factor table:
A verified factor means the factor has been successfully used to login at least once, unverified means the user has attempted to login since 2FA activation but hasn’t successfully setup their TOTP factor.
Deactivating factors
A factor can be deactivated, once deactivated a factor can not be reused. A new factor will created upon the next login.
Notes
- 2FA only affects login for local accounts through the UI, this won’t affect local accounts used to access apis
- Only one factor can be active at the time, meaning a user can not use several phones to login