MailWatch icon indicating copy to clipboard operation
MailWatch copied to clipboard

Security Enhancements -2FA

Open asuweb opened this issue 7 years ago • 7 comments

Is anybody interested in 2-factor-auth being implemented to provide an additional layer of security to the MailWatch login?

asuweb avatar Mar 30 '17 18:03 asuweb

✋ I am :)

shawniverson avatar Mar 30 '17 19:03 shawniverson

There was an idea of an exchangeable user management some time ago this would be a nice use case 😄 👍

But especially a good 2FA will need a lot of work

Skywalker-11 avatar Mar 30 '17 19:03 Skywalker-11

2FA for the win!

Which ideas do you have in mind? Time-based One-Time Passwords (TOTP) with Google Authenticator (and similar apps)? email with OTP?

endelwar avatar Apr 03 '17 14:04 endelwar

TOTP was what I had in mind. If I get the time in the next couple of weeks I'll put something together for testing / comments

asuweb avatar Apr 03 '17 16:04 asuweb

It would also be nice to have support of this additional authentication features:

  • ldap authentication: support fallback servers (if first server is not available try a second,third... server)
  • multiple authentication sources identified by username domain (eg. ldap1 for example.org, ldap2 for example.com)

Not authentication but still nice to have:

  • get additional mail addresses from ldap and use them as predefined filters for the user

Skywalker-11 avatar Jul 31 '17 08:07 Skywalker-11

@Skywalker-11

I am actively developing an AD/LDAP User Synchronization script for MailWatch. I started it over the weekend, and so far it looks good. One of the features is that it will pull additional proxyaddresses from LDAP to populate the filters when this field is in use. I am going to submit it to MailWatch for consideration once completed.

shawniverson avatar Jul 31 '17 10:07 shawniverson

@Skywalker-11 - I'm working on a domain management feature which could incorporate the per domain LDAP bits.

asuweb avatar Jul 31 '17 11:07 asuweb