Actions

Difference between revisions of "TwoFactorAdminLogin"

From LimeSurvey Manual

m
m
Line 5: Line 5:
  
  
2FA is a way to add additional security to your account. It is called "two-factor-authentication" because two verification methods are used to access your account. The first "factor" is your usual password that is standard for any account. The second "factor" is a verification code retrieved from a 2FA application either from your computer or mobile device. For more details about 2FA and its importance, please visit the following [https://en.wikipedia.org/wiki/Multi-factor_authentication article].
+
'''2-Factor-Authentication''' (2FA) is a way to add additional security to your account. It is called "two-factor-authentication" because two verification methods are used to access your account. The first "factor" is your usual password that is standard for any account. The second "factor" is a verification code retrieved from a 2FA application either from your computer or mobile device. For more details about 2FA and its importance, please visit the following [https://en.wikipedia.org/wiki/Multi-factor_authentication article].
  
  
=Activate 2FA=
+
=Activate the 2FA plugin=
  
  
To activate your 2FA plugin, access your LimeSurvey instance, and activate it from your Plugin Manager:  
+
To activate your 2FA plugin, access your LimeSurvey instance, and activate it from your [[Plugin manager|Plugin Manager]]:  
 +
 
  
 
<center>Screenshot</center>
 
<center>Screenshot</center>
Line 22: Line 23:
  
  
After you selected "Configure", the following page will be displayed:
+
The configuration page contains the following settings:
  
  
Line 43: Line 44:
  
  
=2FA - Personal Settings=
+
=2FA - settings
 +
 
 +
 
 +
==2FA - personal settings==
 +
 
  
  
Line 59: Line 64:
  
  
=2FA user management=
+
==2FA - user management==
  
 
Intro
 
Intro

Revision as of 11:38, 9 April 2019

Important.png
Under Construction


Introduction

2-Factor-Authentication (2FA) is a way to add additional security to your account. It is called "two-factor-authentication" because two verification methods are used to access your account. The first "factor" is your usual password that is standard for any account. The second "factor" is a verification code retrieved from a 2FA application either from your computer or mobile device. For more details about 2FA and its importance, please visit the following article.


Activate the 2FA plugin

To activate your 2FA plugin, access your LimeSurvey instance, and activate it from your Plugin Manager:


Screenshot


To check the default settings, please click on "Configure".


Plugin settings

The configuration page contains the following settings:


Screenshot


  • Issuer: The text typed in this box will be displayed in the app as issuer name.
  • Digits: The number of digits the resulting codes will be. Please leave it at 6 for Google Authenticator.
  • TimePeriod: The number of seconds a code will be valid. If you use Google Authenticator, please leave it to 30.
  • Discrepancy: The amount of discrepancy is allowed for the client after the TimePeriod expires (seconds)
  • Algorithm: The algorithm used to generate a hash:
    • SHA1 (Default)
    • SHA256
    • MD5
  • Force 2FA: If you enable it, all instance users have to create a 2FA token after they log in again into the LimeSurvey instance.

Don't forget to click on "Save" after updating your 2FA configuration.


=2FA - settings


2FA - personal settings

Screenshot


  • Unset 2FA: Confirm your action to delete the 2FA-token associated to your account.
Help.pngPlease note that you will need to re-authenticate again if "Force 2FA" is enabled from the plugin settings.
  • Reset 2FA: If this option is selected, you will be asked to scan the new QR-code and introduce the new confirmationKey.


Important.png
If you are superadmin explanation


2FA - user management

Intro

Condition


Screenshot


  • Action: A red trash button is displayed in this column next to the users that have enabled 2FA. If someone asks to get his 2FA reset because he/she cannot log in anymore into your instance, you can delete the 2FA-token associated with his/her account from here.
  • Username: All the instance users are listed under this column.
  • Full name:The full name typed in here by your users is displayed in this field.
  • Email: The email address corresponding to your users.
  • 2FA-Method: The 2FA-method chosen by each user.
  • 2FA enabled: If "1", it means that 2FA is enabled for the respective user.


Advanced

Add your own 2FA solution