{"id":2845,"date":"2017-04-24T00:00:05","date_gmt":"2017-04-24T07:00:05","guid":{"rendered":"http:\/\/192.168.3.4\/?p=2845"},"modified":"2018-01-09T06:51:26","modified_gmt":"2018-01-09T14:51:26","slug":"2845","status":"publish","type":"post","link":"https:\/\/www.cloudacm.com\/?p=2845","title":{"rendered":"Two Factor Authentication"},"content":{"rendered":"<p>Internet facing services are under constant attack.\u00a0 They are a coveted resource that provide footing when exploited.\u00a0 It&#8217;s prudent to not loose control of your services to abuse.\u00a0 One way to do this is to enable two factor authentication, commonly known as 2FA.<\/p>\n<p>Traditional authentication is based on what you know, a user name and a password.\u00a0 With 2FA, the second factor of authentication is what you have, a number token.\u00a0 In this post I&#8217;ll be covering how to setup 2FA support for WordPress and Webmin using the Google Authenticator app.<\/p>\n<p>First, install the Google Authenticator app on a smartphone or table running IOS or Android.<\/p>\n<p><a href=\"https:\/\/play.google.com\/store\/apps\/details?id=com.google.android.apps.authenticator2\">Android<\/a><\/p>\n<p><a href=\"https:\/\/itunes.apple.com\/us\/app\/google-authenticator\/id388497605?mt=8\">IOS<\/a><\/p>\n<p>You&#8217;ll need this before we enable 2FA support in WordPress and Webmin.\u00a0 Once installed, the app will provide 2 methods to create a token, QR code scan or manual entry of the API code.\u00a0 We&#8217;ll get this information when we enable 2FA on WordPress and Webmin.<\/p>\n<p>This video provides details on how to enable support in WordPress.<\/p>\n<p><iframe loading=\"lazy\" title=\"How to Secure WordPress with 2-Step Verification\" width=\"640\" height=\"360\" src=\"https:\/\/www.youtube.com\/embed\/RlzuMV5F6uk?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe><\/p>\n<p>There are several Google Authenticator plugins available.\u00a0 Once you choose one and it is installed and enabled, you can go to the users section of your WP site.\u00a0 Selecting a user will bring you to the properties of that user.\u00a0 Here you will see a section called Google Authenticator Settings.\u00a0 When it is activated, a secret API code should be available.\u00a0 With it you should also see a QR code.\u00a0 These are what you enter into your smartphone\/tablet Google Authenticator app.\u00a0 That is it.\u00a0 When you logout and log back into your WP admin site, you&#8217;ll be prompted for a username, password, and token.<\/p>\n<p>Enabling 2FA on webmin is slightly different.\u00a0 Sign in on webmin and under webmin \/ webmin configuration, click Two-Factor Authentication.\u00a0 From the pulldown menu, select Google Authenticator as the authentication provider then click save.\u00a0 I often got error messages with a link to use the perl modules page to install it, click that link.\u00a0 Wait for the process to complete, do not close your page.\u00a0 When complete, return to the webmin configurations page and click the 2FA link.\u00a0 Choose Google Authenticator again and click save.\u00a0 This will reload the webmin services, wait for it to complete. You will get a message You can now enroll for two-factor authentication in the webmin users module<\/p>\n<p>From the webmin users link, click enroll and you should get the API code along with the QR code.\u00a0 Enter this into you smartphone or tablet. Make a record of the codes, you might need them again if you loose your smartphone or tablet.\u00a0 Now 2FA is enabled for the webmin site.<\/p>\n<p>Another form of 2FA is RSA public-private key pairs.\u00a0 I&#8217;ve used this for my ssh services for years.\u00a0 This service is a favorite for attackers, since it will essentially provide system wide access if exploited.<\/p>\n<p>This site provides steps on how to generate and use RSA public-private key pairs.<\/p>\n<p>Windows &#8211; <a href=\"https:\/\/support.rackspace.com\/how-to\/generating-rsa-keys-with-ssh-puttygen\/\">https:\/\/support.rackspace.com\/how-to\/generating-rsa-keys-with-ssh-puttygen\/<\/a><br \/>\nMac \/ Linux &#8211; <a href=\"https:\/\/support.rackspace.com\/how-to\/connecting-to-a-server-using-ssh-on-linux-or-mac-os\/\">https:\/\/support.rackspace.com\/how-to\/connecting-to-a-server-using-ssh-on-linux-or-mac-os\/<\/a><\/p>\n<p>Instead of using a smartphone or tablet that displays a token, you would use the keys generated to successfully access the ssh service.\u00a0 This method is especially useful for automated systems regularly connect.\u00a0 Pairing the systems with RSA key pairs ensures that secure connections are established with less compromise.<\/p>\n<p>If you have an internet facing service that prompts for authentication, I strongly suggest enabling 2FA.\u00a0 This will increase the availability of that service for its intended purpose.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Internet facing services are under constant attack.\u00a0 They are a coveted resource that provide footing when exploited.\u00a0 It&#8217;s prudent to not loose control of your services to abuse.\u00a0 One way to do this is to enable two factor authentication, commonly known as 2FA. Traditional authentication is based on what you know, a user name and a password.\u00a0 With 2FA, the second factor of authentication is what you have, a number token.\u00a0 In this post I&#8217;ll be covering how to setup&#8230;<\/p>\n<p class=\"read-more\"><a class=\"btn btn-default\" href=\"https:\/\/www.cloudacm.com\/?p=2845\"> Read More<span class=\"screen-reader-text\">  Read More<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4,5,6],"tags":[],"class_list":["post-2845","post","type-post","status-publish","format-standard","hentry","category-android","category-iphone","category-raspberry-pi"],"_links":{"self":[{"href":"https:\/\/www.cloudacm.com\/index.php?rest_route=\/wp\/v2\/posts\/2845","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.cloudacm.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.cloudacm.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.cloudacm.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.cloudacm.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2845"}],"version-history":[{"count":10,"href":"https:\/\/www.cloudacm.com\/index.php?rest_route=\/wp\/v2\/posts\/2845\/revisions"}],"predecessor-version":[{"id":2849,"href":"https:\/\/www.cloudacm.com\/index.php?rest_route=\/wp\/v2\/posts\/2845\/revisions\/2849"}],"wp:attachment":[{"href":"https:\/\/www.cloudacm.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2845"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.cloudacm.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2845"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.cloudacm.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2845"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}