The Community Forums

Interact with an entire community of cPanel & WHM users!
  1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Two-Factor Authentication Plugin on GitHub...Trustworthy?

Discussion in 'Security' started by markb14391, Jun 14, 2014.

  1. markb14391

    markb14391 Well-Known Member

    Joined:
    Jun 9, 2008
    Messages:
    305
    Likes Received:
    2
    Trophy Points:
    18
    Hi,

    We are disappointed that cPanel still doesn't have two-factor authentication.

    There is now a beta project on GitHub that implements it.

    /https://github.com/steadramon/cpanel_addon-twostepauth

    However, I'm always hesitant to trust third-party products from public sources. I'm wondering if anyone else has found this and has had time to analyze the code and see if it's legit? I took a brief look but haven't had time to do more yet.

    Thanks,

    Mark
     
  2. panacheweb

    panacheweb Registered

    Joined:
    Nov 11, 2010
    Messages:
    2
    Likes Received:
    0
    Trophy Points:
    1
    Greetings,

    I saw the same system, and have not found an answer to this either..

    I would love to see two factor in cpanel/whm/ssh and the ability to bypass 2 factor from certain ip's such as my server host would not need to use two factor.

    Cheers,

    MJ
     
  3. cPanelMichael

    cPanelMichael Forums Analyst
    Staff Member

    Joined:
    Apr 11, 2011
    Messages:
    30,678
    Likes Received:
    653
    Trophy Points:
    113
    cPanel Access Level:
    Root Administrator
    Hello :)

    I've not reviewed or attempted to use that third-party plugin, but I wanted to make note of the official URL to this feature request:

    Two-factor Authentication | cPanel Feature Requests

    Please ensure you vote and add your input to the official feature request.

    Thank you.
     
  4. markb14391

    markb14391 Well-Known Member

    Joined:
    Jun 9, 2008
    Messages:
    305
    Likes Received:
    2
    Trophy Points:
    18
    I do hope that cPanel implements 2FA. However, the facts we are faced with today are that it isn't implemented and it is a highly sought-after feature that we want to provide to our cllents. I am surprised that it's not in cPanel yet, especially with security being so important now.

    So for now, we have to look at what's available today, not what might be implemented in cPanel down the road. So it would be great if someone can vet this...maybe lots of us can start offering 2FA now, then possibly replace it when (if) cPanel adds it.

    I've also looked at RV2Factor, but it seems complicated for end users to set up. And, unless i'm mistaken, it looks like it costs $3 per month per cPanel user...which is simply cost-prohibitive for most hosting providers. I guess they think we'll offer it to our clients as an optional add-on they can buy, but I'd much rather have a user-friendly system in place that allows our users to implement 2FA easily. Thus the interest in the solution on GitHub.

    Thanks!
     
  5. markb14391

    markb14391 Well-Known Member

    Joined:
    Jun 9, 2008
    Messages:
    305
    Likes Received:
    2
    Trophy Points:
    18
    Too bad, this might be a good (and free!) 2FA implementation for cPanel.
     
  6. ThinIce

    ThinIce Well-Known Member

    Joined:
    Apr 27, 2006
    Messages:
    346
    Likes Received:
    7
    Trophy Points:
    18
    Location:
    Disillusioned in England
    cPanel Access Level:
    Root Administrator
    There is a thread over on web hosting talk by the author of the plugin https://www.webhostingtalk.com/showthread.php?t=1377255

    Might be an idea to post your interest there in his work, the higher interest the thread gets the higher the likelihood someone like Rack911 will have a poke at the plugin I'd wager...
     
  7. markb14391

    markb14391 Well-Known Member

    Joined:
    Jun 9, 2008
    Messages:
    305
    Likes Received:
    2
    Trophy Points:
    18
    Ah, good thinking! :)
     
  8. dto123

    dto123 Member

    Joined:
    Jun 28, 2014
    Messages:
    7
    Likes Received:
    0
    Trophy Points:
    1
    Location:
    Toronto
    cPanel Access Level:
    Website Owner
    Having 2FA would be great on cpanel. I have it set up on as many accounts as I can, the funny thing I find though is that most my customers have no idea what it is and don't use it for any accounts.
     
  9. saurabhnsonar

    saurabhnsonar Member

    Joined:
    Nov 29, 2010
    Messages:
    5
    Likes Received:
    0
    Trophy Points:
    1
    We too waiting for cPanel to add those feature legally. For now anyone using this third party plugin? Is it secure?
     
  10. allpar

    allpar Active Member

    Joined:
    Sep 16, 2005
    Messages:
    43
    Likes Received:
    0
    Trophy Points:
    6
    Not to rouse a dead thread, but ... is it secure? It’s actively maintained, that’s obvious, but has anyone looked at the code? It only applies to the CPanel accounts and not WHM itself, so I'm not inclined anyway, I want increased security for WHM whether it’s via a dongle, code generator, or TFA...
     
Loading...

Share This Page