[GH-ISSUE #1672] Wish: Propper 2FA and Application passwords #1316

Closed
opened 2026-02-27 11:16:29 +03:00 by kerem · 0 comments
Owner

Originally created by @NetworkJack2 on GitHub (Feb 11, 2019).
Original GitHub issue: https://github.com/modoboa/modoboa/issues/1672

Wishlist is modern authentication standards.

2FA support

  • TOTP - time based token on a phone app like Google Auth or RedHat's FreeOTP(better IMO).
  • U2F - like yubikey and clones

Backup passwords
In case you lose your Second Factor

Application Passwords
Randomly Generated passwords you can save in your phone/mail app and delete as needed. Read once.

This is becoming the new standard for security. To administer a user account you login with a second factor. All your devices have seperate passwords to log in automatically that can be revoked if they are lost/decommissioned/compromised.

Originally created by @NetworkJack2 on GitHub (Feb 11, 2019). Original GitHub issue: https://github.com/modoboa/modoboa/issues/1672 Wishlist is modern authentication standards. 2FA support * TOTP - time based token on a phone app like Google Auth or RedHat's FreeOTP(better IMO). * U2F - like yubikey and clones Backup passwords In case you lose your Second Factor Application Passwords Randomly Generated passwords you can save in your phone/mail app and delete as needed. Read once. This is becoming the new standard for security. To administer a user account you login with a second factor. All your devices have seperate passwords to log in automatically that can be revoked if they are lost/decommissioned/compromised.
kerem closed this issue 2026-02-27 11:16:29 +03:00
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
starred/modoboa-modoboa#1316
No description provided.