Welcome to Centmin Mod Community
Register Now

Security Sysadmin Google Authenticator

Discussion in 'System Administration' started by Jimmy, Feb 6, 2017.

  1. Jimmy

    Jimmy Premium Member Premium Member

    1,168
    256
    83
    Oct 24, 2015
    East Coast USA
    Ratings:
    +626
    Local Time:
    5:10 PM
    1.13.x
    MariaDB 10.1.x
    • Like Like x 1
  2. eva2000

    eva2000 Administrator Staff Member

    31,027
    6,928
    113
    May 24, 2014
    Brisbane, Australia
    Ratings:
    +10,434
    Local Time:
    8:10 AM
    Nginx 1.13.x
    MariaDB 5.5
    Yeah leave it to end users as once you loose your phone you'd be in trouble. I use 2 step but i have my GA codes sync'd to 3x phones + 3x tablets :)
     
  3. RB1

    RB1 Active Member

    281
    72
    28
    Nov 11, 2016
    California
    Ratings:
    +119
    Local Time:
    2:10 PM
    Nginx 1.13.x
    MariaDB 10.1.x
    Also an added bonus if GA is linked to your phone number with iMessage...you can also receive authentication codes via Messages app on OS X
     
    • Informative Informative x 1
  4. SFLC

    SFLC Active Member

    224
    59
    28
    Dec 4, 2016
    The Canadas
    Ratings:
    +112
    Local Time:
    12:10 AM
    1
    10
    Thats the issue with GA. I had issues when I got a new phone and wiped the old one after forgetting about GA. Took a while to regain access to my accounts. Authy handles this alot better.
     
    • Agree Agree x 1
  5. SFLC

    SFLC Active Member

    224
    59
    28
    Dec 4, 2016
    The Canadas
    Ratings:
    +112
    Local Time:
    12:10 AM
    1
    10
  6. SFLC

    SFLC Active Member

    224
    59
    28
    Dec 4, 2016
    The Canadas
    Ratings:
    +112
    Local Time:
    12:10 AM
    1
    10
    • Like Like x 2
  7. eva2000

    eva2000 Administrator Staff Member

    31,027
    6,928
    113
    May 24, 2014
    Brisbane, Australia
    Ratings:
    +10,434
    Local Time:
    8:10 AM
    Nginx 1.13.x
    MariaDB 5.5
    Yeah Authy does it better.

    This would be be something to look at it next dev release after 123.09beta01 goes stable :)
     
    • Like Like x 2
  8. SFLC

    SFLC Active Member

    224
    59
    28
    Dec 4, 2016
    The Canadas
    Ratings:
    +112
    Local Time:
    12:10 AM
    1
    10
    I think it's stable :), been using it for a few months now with no issues whatsoever on my end
     
    • Like Like x 1
  9. eva2000

    eva2000 Administrator Staff Member

    31,027
    6,928
    113
    May 24, 2014
    Brisbane, Australia
    Ratings:
    +10,434
    Local Time:
    8:10 AM
    Nginx 1.13.x
    MariaDB 5.5
  10. Jimmy

    Jimmy Premium Member Premium Member

    1,168
    256
    83
    Oct 24, 2015
    East Coast USA
    Ratings:
    +626
    Local Time:
    5:10 PM
    1.13.x
    MariaDB 10.1.x
    I'm unclear why people say about losing their phone and they'd be out of luck - heard that many places. I always copy the security key vs. scanning the qr code. I actually use GAuth Chrome Extension, never used my phone. Even if I delete the chrome extension, as long as I have the security key, I can just enter it again.

    Have to check out the other one posted here.
     
    • Informative Informative x 1
  11. SFLC

    SFLC Active Member

    224
    59
    28
    Dec 4, 2016
    The Canadas
    Ratings:
    +112
    Local Time:
    12:10 AM
    1
    10
    You're right, but most people including myself are either too lazy or couldn't be bothered to save the security key or backup codes. Google just needs to add a transfer phones or backup option.
     
  12. Jimmy

    Jimmy Premium Member Premium Member

    1,168
    256
    83
    Oct 24, 2015
    East Coast USA
    Ratings:
    +626
    Local Time:
    5:10 PM
    1.13.x
    MariaDB 10.1.x
    Yea. I did that once and got locked out. From then on, I always wrote it down. ;)
     
  13. Revenge

    Revenge Active Member

    291
    64
    28
    Feb 21, 2016
    Portugal
    Ratings:
    +228
    Local Time:
    10:10 PM
    1.9.x
    10.1.x
    [​IMG]

    You have 5 emergency codes. Its good even if you loose your phone.
     
    • Like Like x 1
    • Agree Agree x 1
  14. SFLC

    SFLC Active Member

    224
    59
    28
    Dec 4, 2016
    The Canadas
    Ratings:
    +112
    Local Time:
    12:10 AM
    1
    10
    nice what repo has google-authenticator in it for centos 7, can't seem to install it, i already have epel and remi
     
  15. eva2000

    eva2000 Administrator Staff Member

    31,027
    6,928
    113
    May 24, 2014
    Brisbane, Australia
    Ratings:
    +10,434
    Local Time:
    8:10 AM
    Nginx 1.13.x
    MariaDB 5.5
    yes there is but if you loose those emergency codes ?

    also by default GA on server is set for time based authentication so as that screenshot says, time skew between client and server :)
     
  16. eva2000

    eva2000 Administrator Staff Member

    31,027
    6,928
    113
    May 24, 2014
    Brisbane, Australia
    Ratings:
    +10,434
    Local Time:
    8:10 AM
    Nginx 1.13.x
    MariaDB 5.5
    have to manually install it

    work i did on this 4+ months ago outlined in a gist and tested on centmin mod 123.09beta01 centos 7 local server 2FA for centminmod · GitHub

    also some lines are for ntp test routines to ensure server clock doesn't time drift/skew - some code made it into 123.09beta01 already for ntp tests. Though still weighing up if ntpd is best way to manage time sync for server versus newer alternatives to ntpd like ntpsec and chrony

    could be problematic on openvz systems as ntp isn't used as openvz gets time from openvz host node so if they experiences time skew/drift !
     
  17. Jimmy

    Jimmy Premium Member Premium Member

    1,168
    256
    83
    Oct 24, 2015
    East Coast USA
    Ratings:
    +626
    Local Time:
    5:10 PM
    1.13.x
    MariaDB 10.1.x
    Good to see this thread peak some people's interests. :)

    Security is good.
     
    • Like Like x 2
  18. SFLC

    SFLC Active Member

    224
    59
    28
    Dec 4, 2016
    The Canadas
    Ratings:
    +112
    Local Time:
    12:10 AM
    1
    10
    ya if that't the case i'll hold off on installing it then, i wanted an easy way to remove it if things go sideways
     
  19. pamamolf

    pamamolf Well-Known Member

    2,842
    254
    83
    May 31, 2014
    Ratings:
    +450
    Local Time:
    12:10 AM
    Nginx-1.13.x
    MariaDB 10.1.x
    I like this one also :)
     
  20. Jimmy

    Jimmy Premium Member Premium Member

    1,168
    256
    83
    Oct 24, 2015
    East Coast USA
    Ratings:
    +626
    Local Time:
    5:10 PM
    1.13.x
    MariaDB 10.1.x