Mailcow-dockerized: Enable multiple 2FA

Created on 8 Jan 2019  路  13Comments  路  Source: mailcow/mailcow-dockerized

Is your feature request related to a problem? Please describe.

Currently only one 2FA mode can be selected. Either TOTP, U2F or Yubico 2FA

Describe the solution you'd like

It would be nice to enable e.g. U2F _and_ TOTP. I don't think this would compromise the security in any way.

enhancement

Most helpful comment

It does not violate anything. I talked to Yubi when we implemented it and they even sponsored some keys for a giveaway.

You can add multple keys without a problem, you just cannot mix with TOTP etc. - it is NO violation of anything to not being able to mix u2f with totp etc.

That's ridiculous, sorry. I don't know if that was just written to put pressure on us to work on something you want. :(

All 13 comments

Multiple TOTPs don't work either.

735

This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs. Thank you for your contributions.

What's your opinion on this, @andryyy

I think that would be a nice improvement, specially being able to use 2x U2F sticks (e.g. one for a fallback). However I think it doesn't have that kind of high priority, and also might require quite a lot of work to rework the current code.

Well you could create another Admin account and use a different key/totp

@Braintelligence This would be a quite ugly workaround, but no solution.

Definitely interested in this feature too.

it's not a nice to have and in my optionion not a feature request, but a bug(wrong implementation), only being able to to add one u2f key violates the authentication standard or at lest best practice.
Cause it's not possible to make backups of yubikey etc... it's a absolute must have.

It does not violate anything. I talked to Yubi when we implemented it and they even sponsored some keys for a giveaway.

You can add multple keys without a problem, you just cannot mix with TOTP etc. - it is NO violation of anything to not being able to mix u2f with totp etc.

That's ridiculous, sorry. I don't know if that was just written to put pressure on us to work on something you want. :(

well then my bad, i didn't test it correct with 2 different yubikey, works fine - sorry

Adding a second TOTP device is still a great idea
It would make administration much more handy if you have a password vault with TOTP feature and also will be able to get a TOTP on mobile if you are on the go.

You can have the same TOTP secret on multiple devices.

You saved my day! @Braintelligence

Was this page helpful?
0 / 5 - 0 ratings

Related issues

thannaske picture thannaske  路  3Comments

Braintelligence picture Braintelligence  路  3Comments

schoebelh picture schoebelh  路  3Comments

CrAazZyMaN21 picture CrAazZyMaN21  路  3Comments

zkryakgul picture zkryakgul  路  3Comments