Rocket.chat: Require Two Factor Auth for external authenticators

Created on 21 Apr 2017  Â·  14Comments  Â·  Source: RocketChat/Rocket.Chat

Rocket.Chat Version: 0.55.1
Running Instances: 1
DB Replicaset OpLog: off
Node Version: 4.7.3

Hello Devs.

I have an issue with 2FA. After enabling it i can still login without entering a 2FA code. Is that a known issue?

thanks and cheers

2fa accounts bug

All 14 comments

I just found similar behaviour. We let SAML handle the authentication and just wanted to try out 2FA. But after enabling it, I still get immediately logged in without any 2FA check.

Or is this a feature from your point of view? One could argue that 2FA should also happen on the SAML authentication layer …

Same Issue here with Active Directory as LDAP backend.

We'll look into requering 2FA for any authentication method.

Thanks for looking into this! Is there a timeline for this? We use AD as the LDAP backend and have a hard requirement for 2FA which is preventing us from rolling out a large scale deployment.

We're also interested in activating 2FA for our RocketChat Setup which currently uses LDAP authentication.

Any news regarding this issue?

Any progress on that matter?

Hello

Any news ?

Possible to sponsor this one? Maybe via Bountysource?

@shakalandy it was already implemented and will be included in one of the next releases.

In which release are you plan to add it? We want to use it ASAP.

Any news regarding this issue? 2 FA Authentication is bypassed when using LDAP auth.

👀

Tested this in 1.0.0-rc.2 and 0.74.3 and 2FA is bypassed when using LDAP still.

Was this page helpful?
0 / 5 - 0 ratings

Related issues

Buzzele picture Buzzele  Â·  3Comments

Buzzele picture Buzzele  Â·  3Comments

mddvul22 picture mddvul22  Â·  3Comments

karlprieb picture karlprieb  Â·  3Comments

mattlin picture mattlin  Â·  3Comments