<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Search Results for &#8220;U2F&#8221; &#8211; privacyID3A</title>
	<atom:link href="https://www.privacyidea.org/search/U2F/feed/rss2/" rel="self" type="application/rss+xml" />
	<link>https://www.privacyidea.org</link>
	<description>flexible, Open Source Multi Factor Authentication (2FA)</description>
	<lastBuildDate>Fri, 10 Apr 2020 17:30:58 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://www.privacyidea.org/wp-content/uploads/2016/06/cropped-only-logo-white-background-32x32.png</url>
	<title>Search Results for &#8220;U2F&#8221; &#8211; privacyID3A</title>
	<link>https://www.privacyidea.org</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>privacyIDEA 3.3 Released</title>
		<link>https://www.privacyidea.org/privacyidea-3-3-with-webauthn/</link>
					<comments>https://www.privacyidea.org/privacyidea-3-3-with-webauthn/#comments</comments>
		
		<dc:creator><![CDATA[Henning Hollermann]]></dc:creator>
		<pubDate>Mon, 06 Apr 2020 05:29:49 +0000</pubDate>
				<category><![CDATA[release]]></category>
		<category><![CDATA[Indexed Secret]]></category>
		<category><![CDATA[Release]]></category>
		<category><![CDATA[WebAuthn]]></category>
		<guid isPermaLink="false">https://www.privacyidea.org/?p=1896</guid>

					<description><![CDATA[WebAuthn token support, event-based logging and more privacyIDEA 3.3 is out. The new version introduces a new Event Handler Module to enable custom event-driven logging. Also new in 3.3 is the support of WebAuthn tokens which come to privacyIDEA initially as a second-factor for WebUI login. WebAuthn Everybody speaks about WebAuthn becoming the global standard [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p>WebAuthn token support, event-based logging and more</p>



<figure class="wp-block-image size-large"><img fetchpriority="high" decoding="async" width="910" height="500" src="https://www.privacyidea.org/wp-content/uploads/2020/04/privacy3.3_webauthn2-1.png" alt="" class="wp-image-2005" srcset="https://www.privacyidea.org/wp-content/uploads/2020/04/privacy3.3_webauthn2-1.png 910w, https://www.privacyidea.org/wp-content/uploads/2020/04/privacy3.3_webauthn2-1-300x165.png 300w, https://www.privacyidea.org/wp-content/uploads/2020/04/privacy3.3_webauthn2-1-768x422.png 768w" sizes="(max-width: 910px) 100vw, 910px" /></figure>



<p><em>privacyIDEA 3.3 is out. The new version introduces a new Event Handler Module to enable custom event-driven logging. Also new in 3.3 is the support of WebAuthn tokens which come to privacyIDEA initially as a second-factor for WebUI login.</em></p>



<h3 class="wp-block-heading">WebAuthn</h3>



<p>Everybody speaks about WebAuthn becoming the global standard for web-based authentication to overcome phishing and man-in-the-middle attack scenarios. Indeed, <a href="https://www.w3.org/TR/webauthn/">WebAuthn, as specified by the W3C</a>, is a very flexible JavaScript-based API for user authentication. It is the successor of the U2F standard of the FIDO alliance and is, like its predecessor, phishing-resistant by using public-private key encryption in a TLS-secured challenge-response communication. However, WebAuthn has a far more general scope, as it is designed to work not only with U2F tokens but also with any other hardware which supports the API interface. WebAuthn will greatly extend the set of usable token devices e.g. to hardware crypto-chips which can be unlocked by a fingerprint-scanner. For the end user, this example case will result in a unique authentication experience with the fingerprint as apparent key-device. During the authentication process, the browser acts as relay between the WebAuthn security device (<em>authenticator)</em> and the service (<em>relying party)</em>.</p>



<h3 class="wp-block-heading">WebAuthn comes to privacyIDEA</h3>



<p>privacyIDEA initially implements WebAuthn to support WebAuthn/FIDO2 Hardware Token as second factors. You can configure privacyIDEA as your relying party, enroll WebAuthn Tokens with privacyIDEA and use them as a second factor to login to the WebUI. The following gallery shows the enrollment process.</p>



<figure class="wp-block-gallery columns-6 is-cropped wp-block-gallery-1 is-layout-flex wp-block-gallery-is-layout-flex"><ul class="blocks-gallery-grid"><li class="blocks-gallery-item"><figure><a href="https://www.privacyidea.org/wp-content/uploads/2020/04/WebAuthn_00_Config-1024x554.png"><img decoding="async" width="1024" height="554" src="https://www.privacyidea.org/wp-content/uploads/2020/04/WebAuthn_00_Config-1024x554.png" alt="" data-id="1987" data-link="https://www.privacyidea.org/?attachment_id=1987" class="wp-image-1987" srcset="https://www.privacyidea.org/wp-content/uploads/2020/04/WebAuthn_00_Config-1024x554.png 1024w, https://www.privacyidea.org/wp-content/uploads/2020/04/WebAuthn_00_Config-300x162.png 300w, https://www.privacyidea.org/wp-content/uploads/2020/04/WebAuthn_00_Config-768x416.png 768w, https://www.privacyidea.org/wp-content/uploads/2020/04/WebAuthn_00_Config.png 1140w" sizes="(max-width: 1024px) 100vw, 1024px" /></a></figure></li><li class="blocks-gallery-item"><figure><a href="https://www.privacyidea.org/wp-content/uploads/2020/04/WebAuthn_01_EnrollmentPolicy-1024x503.png"><img decoding="async" width="1024" height="503" src="https://www.privacyidea.org/wp-content/uploads/2020/04/WebAuthn_01_EnrollmentPolicy-1024x503.png" alt="" data-id="1988" data-link="https://www.privacyidea.org/?attachment_id=1988" class="wp-image-1988" srcset="https://www.privacyidea.org/wp-content/uploads/2020/04/WebAuthn_01_EnrollmentPolicy-1024x503.png 1024w, https://www.privacyidea.org/wp-content/uploads/2020/04/WebAuthn_01_EnrollmentPolicy-300x147.png 300w, https://www.privacyidea.org/wp-content/uploads/2020/04/WebAuthn_01_EnrollmentPolicy-768x378.png 768w, https://www.privacyidea.org/wp-content/uploads/2020/04/WebAuthn_01_EnrollmentPolicy-1536x755.png 1536w, https://www.privacyidea.org/wp-content/uploads/2020/04/WebAuthn_01_EnrollmentPolicy.png 1851w" sizes="(max-width: 1024px) 100vw, 1024px" /></a></figure></li><li class="blocks-gallery-item"><figure><a href="https://www.privacyidea.org/wp-content/uploads/2020/04/WebAuthn_02_Enroll-Token-1024x519.png"><img loading="lazy" decoding="async" width="1024" height="519" src="https://www.privacyidea.org/wp-content/uploads/2020/04/WebAuthn_02_Enroll-Token-1024x519.png" alt="" data-id="1989" data-link="https://www.privacyidea.org/?attachment_id=1989" class="wp-image-1989" srcset="https://www.privacyidea.org/wp-content/uploads/2020/04/WebAuthn_02_Enroll-Token-1024x519.png 1024w, https://www.privacyidea.org/wp-content/uploads/2020/04/WebAuthn_02_Enroll-Token-300x152.png 300w, https://www.privacyidea.org/wp-content/uploads/2020/04/WebAuthn_02_Enroll-Token-768x389.png 768w, https://www.privacyidea.org/wp-content/uploads/2020/04/WebAuthn_02_Enroll-Token-1536x778.png 1536w, https://www.privacyidea.org/wp-content/uploads/2020/04/WebAuthn_02_Enroll-Token.png 1854w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></a></figure></li><li class="blocks-gallery-item"><figure><a href="https://www.privacyidea.org/wp-content/uploads/2020/04/WebAuthn_03_Enroll-Token-1-1024x350.png"><img loading="lazy" decoding="async" width="1024" height="350" src="https://www.privacyidea.org/wp-content/uploads/2020/04/WebAuthn_03_Enroll-Token-1-1024x350.png" alt="" data-id="1996" data-link="https://www.privacyidea.org/?attachment_id=1996" class="wp-image-1996" srcset="https://www.privacyidea.org/wp-content/uploads/2020/04/WebAuthn_03_Enroll-Token-1-1024x350.png 1024w, https://www.privacyidea.org/wp-content/uploads/2020/04/WebAuthn_03_Enroll-Token-1-300x102.png 300w, https://www.privacyidea.org/wp-content/uploads/2020/04/WebAuthn_03_Enroll-Token-1-768x262.png 768w, https://www.privacyidea.org/wp-content/uploads/2020/04/WebAuthn_03_Enroll-Token-1.png 1259w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></a></figure></li><li class="blocks-gallery-item"><figure><a href="https://www.privacyidea.org/wp-content/uploads/2020/04/WebAuthn_04_Enroll-Token-1.png"><img loading="lazy" decoding="async" width="1024" height="353" src="https://www.privacyidea.org/wp-content/uploads/2020/04/WebAuthn_04_Enroll-Token-1-1024x353.png" alt="" data-id="1997" data-full-url="https://www.privacyidea.org/wp-content/uploads/2020/04/WebAuthn_04_Enroll-Token-1.png" data-link="https://www.privacyidea.org/?attachment_id=1997" class="wp-image-1997" srcset="https://www.privacyidea.org/wp-content/uploads/2020/04/WebAuthn_04_Enroll-Token-1-1024x353.png 1024w, https://www.privacyidea.org/wp-content/uploads/2020/04/WebAuthn_04_Enroll-Token-1-300x103.png 300w, https://www.privacyidea.org/wp-content/uploads/2020/04/WebAuthn_04_Enroll-Token-1-768x265.png 768w, https://www.privacyidea.org/wp-content/uploads/2020/04/WebAuthn_04_Enroll-Token-1.png 1245w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></a></figure></li><li class="blocks-gallery-item"><figure><a href="https://www.privacyidea.org/wp-content/uploads/2020/04/WebAuthn_05_Enroll-Token-1024x411.png"><img loading="lazy" decoding="async" width="1024" height="411" src="https://www.privacyidea.org/wp-content/uploads/2020/04/WebAuthn_05_Enroll-Token-1024x411.png" alt="" data-id="1992" data-link="https://www.privacyidea.org/?attachment_id=1992" class="wp-image-1992" srcset="https://www.privacyidea.org/wp-content/uploads/2020/04/WebAuthn_05_Enroll-Token-1024x411.png 1024w, https://www.privacyidea.org/wp-content/uploads/2020/04/WebAuthn_05_Enroll-Token-300x120.png 300w, https://www.privacyidea.org/wp-content/uploads/2020/04/WebAuthn_05_Enroll-Token-768x308.png 768w, https://www.privacyidea.org/wp-content/uploads/2020/04/WebAuthn_05_Enroll-Token.png 1035w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></a></figure></li><li class="blocks-gallery-item"><figure><a href="https://www.privacyidea.org/wp-content/uploads/2020/04/WebAuthn_06_Auth.png"><img loading="lazy" decoding="async" width="819" height="454" src="https://www.privacyidea.org/wp-content/uploads/2020/04/WebAuthn_06_Auth.png" alt="" data-id="1993" data-link="https://www.privacyidea.org/?attachment_id=1993" class="wp-image-1993" srcset="https://www.privacyidea.org/wp-content/uploads/2020/04/WebAuthn_06_Auth.png 819w, https://www.privacyidea.org/wp-content/uploads/2020/04/WebAuthn_06_Auth-300x166.png 300w, https://www.privacyidea.org/wp-content/uploads/2020/04/WebAuthn_06_Auth-768x426.png 768w" sizes="auto, (max-width: 819px) 100vw, 819px" /></a></figure></li></ul></figure>



<p>However, this is pretty much it for the moment since WebAuthn requires both service and client to support it properly. As the privacyIDEA server integrates with other services like simpleSAMLphp, Keycloak, Owncloud and others via plugins, those represent the client side. The following steps will therefore be to update the plugins accordingly. With the well-documented WebAuthn API flavored with coding examples, this is a fairly straightforward task (it still requires time). Everyone is invited to speed-up the process by contributing on Github. NetKnights, the company driving the development of privacyIDEA on Github, plans on developing an SDK to help plugin developers to integrate privacyIDEA with their favorite applications.</p>



<h3 class="wp-block-heading">Log Freely</h3>



<p>Already since privacyIDEA version 2.12, the event handler supports user notifications sent by email or SMS, triggered by custom events. privacyIDEA 3.2 introduced the ContainerAudit module to support multiple logging targets which enabled the default SQLAudit and other logging modules to receive logged messages. This might be used to <a href="https://www.privacyidea.org/event-based-logging-with-privacyidea-and-logstash">integrate privacyIDEA logging with central logging systems like Logstash ans Splunk</a>.</p>



<p>The new version 3.3 builds on this basis and pushes forward towards a completely customizable logging. The new <a href="https://privacyidea.readthedocs.io/en/latest/eventhandler/logginghandler.html">event handler module <em>Logging</em></a> basically implements a UserNotification which is not sent via external service but to the Python logging facility instead. As all Event Handlers in privacyIDEA, it can be bound to any event with all the usual possibilities to configure further constraints. The custom log messages support the variables known from the UserNotification handler to provide the administrator with maximum flexibility. The privacyIDEA advanced logging is configured via a <a href="https://privacyidea.readthedocs.io/en/latest/installation/system/logging.html">configuration file</a>. Starting with version 3.3, privacyIDEA supports both YAML and INI format for the logging configuration file. This new event handler offers great flexibility since not only what is logged can be configured to your needs but also where to. The logging name can be customized, which enables an easy separation of different types of information.</p>



<h3 class="wp-block-heading">Tell me your index: the Indexed Secret Token</h3>



<p>privacyIDEA comes with a new token type, called<em> Indexed Secret</em>. This challenge response token was requested to realize a second factor using already known shared secrets between an organization and its employees. The secret is stored in privacyIDEA for every user and during login a challenge is presented, asking the user e.g. for the 1st and 4th character in his secret. For the secret &#8220;Secret&#8221;, the user would have to answer by typing &#8220;Sr&#8221;.</p>



<p>The secret may also be preset with user attributes from the userstore. However, note that using the phone numbers of your employees represent a weak second factor attribute. The potential of this token is to support complex rollout scenarios to provide every user with a unique second factor, right from the start.</p>



<h3 class="wp-block-heading">Administer Transparently</h3>



<p>Previously the admin user for whom an admin policy should be in place could be specified in privacyIDEA. This could be for example a policy to allow enabling and disabling of tokens but not the deletion. The new version adds the possibility to add specific users that are to be managed by this policy. This helps a lot in the delegation of user management and segmentation of your administrative tasks.</p>



<p>There are now separate fields for the admin user and the user himself in the admin policy creation dialog.</p>



<figure class="wp-block-image size-large is-resized"><img loading="lazy" decoding="async" src="https://www.privacyidea.org/wp-content/uploads/2020/04/policy-condition-1024x759.png" alt="" class="wp-image-1986" width="768" height="569" srcset="https://www.privacyidea.org/wp-content/uploads/2020/04/policy-condition-1024x759.png 1024w, https://www.privacyidea.org/wp-content/uploads/2020/04/policy-condition-300x222.png 300w, https://www.privacyidea.org/wp-content/uploads/2020/04/policy-condition-768x569.png 768w, https://www.privacyidea.org/wp-content/uploads/2020/04/policy-condition.png 1118w" sizes="auto, (max-width: 768px) 100vw, 768px" /></figure>



<p>The complete <a href="https://github.com/privacyidea/privacyidea/blob/master/Changelog">changelog</a> can be found at Github.</p>



<h3 class="wp-block-heading">Start your independence now</h3>



<p>privacyIDEA is the flexible open-source multi-factor-authentication solution which runs on-premises. It is hosted on <a href="https://github.com/privacyidea/">Github</a> and can be run and extended by anyone free-of-charge. But it also comes without any warranty. NetKnights provides <a href="https://netknights.it/en/produkte/privacyidea/">professional support for enterprise customers in three different levels</a>. Open-source means for privacyIDEA, that you will always be able to run it, <em>without</em> the fear of an end-of-life scenario. You can also participate in the development, reporting bugs, suggesting features or create pull requests to have your own code included on Github. You can discuss about privacyIDEA and share your use case in the privacyIDEA <a href="https://community.privacyidea.org/">community</a>.</p>



<p>privacyIDEA 3.3 can be installed from the <a href="https://github.com/privacyidea/">Github sources</a>, from the Python Package index at <a href="https://pypi.org/project/privacyIDEA/">pypi.org</a> or with the <a href="https://privacyidea.readthedocs.io/en/latest/installation/ubuntu.html">community packages</a> for Ubuntu 16.04 LTS and 18.04 LTS. NetKnights will also offer <a href="https://netknights.it/en/additional-service-privacyidea-support-customers-centos-7-repository/">packages for CentOS/RHEL</a> in the <a href="https://netknights.it/en/produkte/privacyidea/">privacyIDEA Enterprise Edition</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.privacyidea.org/privacyidea-3-3-with-webauthn/feed/</wfw:commentRss>
			<slash:comments>2</slash:comments>
		
		
			</item>
		<item>
		<title>Flexible, reliable and lasting multi factor authentication</title>
		<link>https://www.privacyidea.org/flexible-reliable-and-lasting-multi-factor-authentication/</link>
		
		<dc:creator><![CDATA[Cornelius Kölbel]]></dc:creator>
		<pubDate>Sat, 18 Jan 2020 07:33:55 +0000</pubDate>
				<category><![CDATA[events]]></category>
		<category><![CDATA[SCaLE]]></category>
		<guid isPermaLink="false">https://www.privacyidea.org/?p=1699</guid>

					<description><![CDATA[privacyIDEA was started more than five years ago. It came a long way from a decent enterprise ready 2FA system to probably the most flexible open source multi factor system. This is due to the possibility to integrate privacyIDEA into any workflows. And looking at infrastructures like universities, where students come and go, or into [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p>privacyIDEA was started more than five years ago. It came a long way from a decent enterprise ready 2FA system to probably the most flexible open source multi factor system. This is due to the possibility to integrate privacyIDEA into any workflows. And looking at infrastructures like universities, where students come and go, or into companies where users seldom stop by at the admins desk, <a href="https://www.privacyidea.org/privacyidea-flexibility-in-the-very-genes/">smooth workflows</a> are a key factor.</p>



<p>At the same time privacyIDEA provides several different ways to <a href="https://www.privacyidea.org/privacyidea-3-1-polished-policies/">migrate</a> existing 2FA system <strong>to</strong> privacyIDEA. This is important, since <a href="https://netknights.it/en/consolidation-of-the-market-and-migrations/" target="_blank" rel="noreferrer noopener" aria-label="proprietary systems tend to go end of life (opens in a new tab)">proprietary systems tend to go end of life</a>.</p>



<div class="wp-block-image"><figure class="aligncenter size-large"><img decoding="async" src="https://www.privacyidea.org/wp-content/uploads/2020/01/scale_logo_lg.svg" alt="" class="wp-image-1704"/></figure></div>



<h2 class="wp-block-heading">privacyIDEA Talk at SCALE 18x</h2>



<p>Cornelius will be giving a <a href="https://www.socallinuxexpo.org/scale/18x/presentations/flexible-reliable-and-lasting-multi-factor-authentication-privacyidea" target="_blank" rel="noreferrer noopener" aria-label="talk at SCALE 18x (opens in a new tab)">talk at SCALE 18x</a> about where 2FA or MFA is going and what we might expect from the old key players. </p>



<p>privacyIDEA can easily help you to get rid of old vendor locks once and for all. privacyIDEA aims to be future proof. Not only do we support Python 3! <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f609.png" alt="😉" class="wp-smiley" style="height: 1em; max-height: 1em;" /> but we also keep up with new developments in the authentication market. privacyIDEA provides a lot of different authentication types like U2F (FIDO2), HOTP/TOTP, SMS or PUSH notifications. This talk will give an insight of the pros and cons, which you need to know to find the right auth type for your scenario.</p>



<p>If you are around, stop by at the Southern California Linux Expo at the Convention Center in Pasadena on March 5th-8th, 2020.</p>



<p><a href="https://www.socallinuxexpo.org/scale/18x/presentations/flexible-reliable-and-lasting-multi-factor-authentication-privacyidea">Read more</a></p>



<p><strong>Update</strong>: The talk will be held on <a href="https://www.socallinuxexpo.org/scale/18x/presentations/flexible-reliable-and-lasting-multi-factor-authentication-privacyidea">March 8th in the Security track,</a> 3pm &#8211; 4pm.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>More flexible 2FA at ownCloud with U2F, Email, SMS and other Challenge Response</title>
		<link>https://www.privacyidea.org/more-flexible-2fa-at-owncloud-with-u2f-email-sms-and-other-challenge-response/</link>
		
		<dc:creator><![CDATA[Cornelius Kölbel]]></dc:creator>
		<pubDate>Tue, 16 Apr 2019 13:03:22 +0000</pubDate>
				<category><![CDATA[release]]></category>
		<category><![CDATA[Challenge Response]]></category>
		<category><![CDATA[ownCloud]]></category>
		<guid isPermaLink="false">https://www.privacyidea.org/?p=1561</guid>

					<description><![CDATA[Today we released the ownCloud App version 2.5.1. This plugin connects ownCloud to privacyIDEA adding enterprise 2FA to your ownCloud. privacyIDEA supports a lot of different token types to provide 2FA for the user. This can be keyfob tokens or Smartphone Apps but also authentication mechanisms that work with a challenge/response workflow like Email, SMS [&#8230;]]]></description>
										<content:encoded><![CDATA[
<div class="wp-block-image"><figure class="aligncenter is-resized"><img loading="lazy" decoding="async" src="https://www.privacyidea.org/wp-content/uploads/2016/06/privacyIDEA-800px.png" alt="" class="wp-image-964" width="285" height="154" srcset="https://www.privacyidea.org/wp-content/uploads/2016/06/privacyIDEA-800px.png 800w, https://www.privacyidea.org/wp-content/uploads/2016/06/privacyIDEA-800px-300x162.png 300w, https://www.privacyidea.org/wp-content/uploads/2016/06/privacyIDEA-800px-768x415.png 768w" sizes="auto, (max-width: 285px) 100vw, 285px" /></figure></div>



<p>Today we released the <a href="https://github.com/privacyidea/privacyidea-owncloud-app/releases/tag/v2.5.1" target="_blank" rel="noreferrer noopener" aria-label=" (opens in a new tab)">ownCloud App version 2.5.1</a>. This plugin connects ownCloud to privacyIDEA adding enterprise 2FA to your ownCloud.</p>



<p>privacyIDEA supports a lot of different token types to provide 2FA for the user. This can be keyfob tokens or Smartphone Apps but also authentication mechanisms that work with a challenge/response workflow like Email, SMS or U2F.</p>



<p>The version 2.5.1 of the privacyIDEA ownCloud app improves the challenge/response authentication when logging in to ownCloud. A user can now have several different challenge/response tokens, an Email, an SMS and/or a U2F device. The privacyIDEA ownCloud app will handle this correctly and allow the user to either authenticate with the code from an SMS or with his U2F device.</p>



<p>A complete changelog can be found <a href="https://github.com/privacyidea/privacyidea-owncloud-app/blob/v2.5.1/Changelog" target="_blank" rel="noreferrer noopener" aria-label="here at Github (opens in a new tab)">here at Github</a>.</p>



<p>The privacyIDEA ownCloud app is also available via the <a href="https://marketplace.owncloud.com/apps/twofactor_privacyidea" target="_blank" rel="noreferrer noopener" aria-label="ownCloud Marketplace (opens in a new tab)">ownCloud Marketplace</a>.</p>



<p></p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>privacyIDEA 3.0 &#8211; Python 3, Push and Policies</title>
		<link>https://www.privacyidea.org/privacyidea-3-0-python-3-push-and-policies/</link>
					<comments>https://www.privacyidea.org/privacyidea-3-0-python-3-push-and-policies/#comments</comments>
		
		<dc:creator><![CDATA[Cornelius Kölbel]]></dc:creator>
		<pubDate>Wed, 10 Apr 2019 08:43:42 +0000</pubDate>
				<category><![CDATA[release]]></category>
		<category><![CDATA[Whatsup]]></category>
		<category><![CDATA[Push Token]]></category>
		<category><![CDATA[Python 3]]></category>
		<category><![CDATA[User Management]]></category>
		<guid isPermaLink="false">https://www.privacyidea.org/?p=1533</guid>

					<description><![CDATA[Proudly we talk about our release of the major version privacyIDEA 3.0, today. Changing the version number 2.23.5 to 3.0 indicates a lot of changes. Changes why you should take more care during the update process. And changes, why this article is a bit longer than usual. But relax! We did everything we could to [&#8230;]]]></description>
										<content:encoded><![CDATA[
<div class="wp-block-image"><figure class="aligncenter"><img loading="lazy" decoding="async" width="1024" height="512" src="https://www.privacyidea.org/wp-content/uploads/2019/04/privacyIDEA-Release-3-0-banner-1024x512.jpg" alt="" class="wp-image-1550" srcset="https://www.privacyidea.org/wp-content/uploads/2019/04/privacyIDEA-Release-3-0-banner-1024x512.jpg 1024w, https://www.privacyidea.org/wp-content/uploads/2019/04/privacyIDEA-Release-3-0-banner-300x150.jpg 300w, https://www.privacyidea.org/wp-content/uploads/2019/04/privacyIDEA-Release-3-0-banner-768x384.jpg 768w, https://www.privacyidea.org/wp-content/uploads/2019/04/privacyIDEA-Release-3-0-banner.jpg 1200w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure></div>



<p>Proudly we talk about our release of the major version privacyIDEA 3.0, today.</p>



<p>Changing the version number <a href="https://www.privacyidea.org/privacyidea-2-23-pre-events-handling-monitoring-and-statistics/">2.23.5</a> to 3.0 indicates a lot of changes. Changes why you should take more care during the update process. And changes, why this article is a bit longer than usual. But relax! We did everything we could to still give you a smooth update experience.</p>



<p>So what is so different?</p>



<h2 class="wp-block-heading">Get ready for the future</h2>



<p>The most important changes in version 3.0 are under the hood. </p>



<p>Now privacyIDEA runs well on Python 2 <strong>and Python 3</strong>! This way we will still be in business when Python 2.7 is no longer supported in 2020. Being able to run on Python 2 or Python 3 <strong>with the same code</strong> allows you to choose, whether and when you want to move your installation to Python 3!</p>



<p>The other major change is in the <strong>database schema</strong>. For years tokens were assigned to a user, by storing the link to the user in the token database table in the columns <em>userid</em> and <em>resolver</em>. From this, the limitation came that a token could originally only be assigned to one user. In version 3 we store the token assignment in a new database table &#8220;tokenowner&#8221;. This way the database schema allows that a token can have multiple token owners. While currently the API and Web UI still only allow to assign one user to a token, we have laid the foundation for an even greater flexibility in the future.</p>



<p>This change leads to something, we did not have before during update. Data migration! While the past versions contained schema migrations, that added new columns and features to privacyIDEA, this is the first time, that the update process will also change data in the database! The <em>userid</em> and <em>resolver</em> is removed from the <em>token</em> table and migrated to the <em>tokenowner</em> table. We tested this successfully with roughly 25.000 assigned tokens. Migrating more tokens will just be a matter of time.</p>



<h2 class="wp-block-heading">Push and Queue</h2>



<p>Two new main features are the Push Token and internal Queueing.</p>



<p>With the Push Token privacyIDEA will send a push notification to the user&#8217;s smartphone informing the user about the login request. Using the privacyIDEA Authenticator App the user can confirm the login request by simply clicking the notification. In the background a cryptographic challenge is signed on the smartphone and sent back to privacyIDEA. privacyIDEA verifies the signature and the login for the user is granted. The Push Token adds another unique authentication mechanism to privacyIDEA. Thus the administrator can choose between a lot of different authentication types like TOTP, HOTP, Yubikey, U2F, Email, SMS&#8230; and decide which matches the user&#8217;s needs.</p>



<figure class="wp-block-image"><img loading="lazy" decoding="async" width="1024" height="680" src="https://www.privacyidea.org/wp-content/uploads/2019/04/concept-privacyidea-push-token-1024x680.jpg" alt="" class="wp-image-1541" srcset="https://www.privacyidea.org/wp-content/uploads/2019/04/concept-privacyidea-push-token-1024x680.jpg 1024w, https://www.privacyidea.org/wp-content/uploads/2019/04/concept-privacyidea-push-token-300x199.jpg 300w, https://www.privacyidea.org/wp-content/uploads/2019/04/concept-privacyidea-push-token-768x510.jpg 768w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /><figcaption>Developing the concept for the Push Token</figcaption></figure>



<p>privacyIDEA now offers a queue, that can run tasks outside of the request context of e.g. an authentication request. For starters the task of sending an email (e.g. during authentication with an email token or with the notification event handler) can now be pushed to the queue and thus be decoupled from the original request, resulting in reliably quicker response times.</p>



<p>In the future the queue can be used for a lot more tasks.</p>



<h2 class="wp-block-heading">Tell me what happend &#8211; helping the administrator understanding his complex system</h2>



<p>In big installations the administrator might have configured a lot of different <a href="https://www.privacyidea.org/setting-policies-via-command-line/">policies</a>, to tweek the system exactly to his needs. Policies define the way, how the systems responds to an authentication request, the enrollment of a token or any other API request. The combination of the policies can make things more complex and the administrator can loose the overview. &#8220;What policy combination caused the system to respond in this way?&#8221;</p>



<div class="wp-block-image"><figure class="alignright is-resized"><img loading="lazy" decoding="async" src="https://www.privacyidea.org/wp-content/uploads/2019/04/library-2614804_1920-1024x768.jpg" alt="" class="wp-image-1546" width="319" height="239" srcset="https://www.privacyidea.org/wp-content/uploads/2019/04/library-2614804_1920-1024x768.jpg 1024w, https://www.privacyidea.org/wp-content/uploads/2019/04/library-2614804_1920-300x225.jpg 300w, https://www.privacyidea.org/wp-content/uploads/2019/04/library-2614804_1920-768x576.jpg 768w, https://www.privacyidea.org/wp-content/uploads/2019/04/library-2614804_1920.jpg 1920w" sizes="auto, (max-width: 319px) 100vw, 319px" /><figcaption>The Audit Log helps the administrator to track and reproduce what exactly happened and why!</figcaption></figure></div>



<p>The audit log already saves every API request that was sent to privacyIDEA. In version 3.0 the audit log also contains a list of all used or relevant policies during this request. I.e. the administrator can easily see, why the system behaved this way it did. The audit log will contain the complete list of policies, that led to this very decision. This will help the administrator or service desk to trouble shoot user&#8217;s requests in a shorter time.</p>



<h2 class="wp-block-heading">Get it and authenticate</h2>



<p>As always you can find the complete <a rel="noreferrer noopener" aria-label=" (opens in a new tab)" href="https://github.com/privacyidea/privacyidea/blob/master/Changelog" target="_blank">changelog at Github</a>. Please be sure, to read the <a rel="noreferrer noopener" aria-label="READ_BEFORE_UPDATE (opens in a new tab)" href="https://github.com/privacyidea/privacyidea/blob/master/READ_BEFORE_UPDATE.md" target="_blank">READ_BEFORE_UPDATE</a>, before updating! (Just like the name suggests)</p>



<p>privacyIDEA 3.0 is available via the Python Package Index and via repositories for Ubuntu 16.04LTS and 18.04LTS. The repositories have been changed to be able to provide more strictly defined installation scenarios. Please read the <a rel="noreferrer noopener" aria-label="online documentation for install methods (opens in a new tab)" href="https://privacyidea.readthedocs.io/en/latest/installation/ubuntu.html" target="_blank">online documentation for install methods</a> and the update process.</p>



<p>New users are welcome at our <a rel="noreferrer noopener" aria-label="community forum (opens in a new tab)" href="https://community.privacyidea.org/" target="_blank">community forum</a>! Enterprise users can get an Enterprise Edition <a href="https://netknights.it/en/produkte/privacyidea/" target="_blank" rel="noreferrer noopener" aria-label="here (opens in a new tab)">here</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.privacyidea.org/privacyidea-3-0-python-3-push-and-policies/feed/</wfw:commentRss>
			<slash:comments>2</slash:comments>
		
		
			</item>
		<item>
		<title>privacyIDEA 2.22 with a more flexible RADIUS integration</title>
		<link>https://www.privacyidea.org/privacyidea-2-22-with-a-more-flexible-radius-integration/</link>
					<comments>https://www.privacyidea.org/privacyidea-2-22-with-a-more-flexible-radius-integration/#comments</comments>
		
		<dc:creator><![CDATA[Cornelius Kölbel]]></dc:creator>
		<pubDate>Tue, 27 Mar 2018 07:03:25 +0000</pubDate>
				<category><![CDATA[release]]></category>
		<category><![CDATA[Whatsup]]></category>
		<category><![CDATA[Event Handler]]></category>
		<category><![CDATA[FreeRADIUS]]></category>
		<category><![CDATA[Migration]]></category>
		<category><![CDATA[talk]]></category>
		<guid isPermaLink="false">https://www.privacyidea.org/?p=1344</guid>

					<description><![CDATA[With privacyIDEA 2.22 we added the possibility to pass more useful userinformation to a RADIUS client like a VPN. The administrator can add a policy to include the resolver and the realm of a user who authenticated successfully. This response data can then be used in the FreeRADIUS plugin and modified by regular expressions to add any arbitrary RADIUS attribute in the RADIUS response, which then would be sent to the VPN. This additional information can be used by Cisco ASA, Citrix Netscaler or any other enterprise grade VPN to put the user into certain subnets or to assign resource to the user.]]></description>
										<content:encoded><![CDATA[<p>Today we are happy to release privacyIDEA 2.22. It is available in the Ubuntu repositories for Ubuntu 14.04 LTS and 16.04 LTS. You can also install privacyIDEA on any Linux distribution on a virtualenv via the Python Package Index. <a href="http://privacyidea.readthedocs.io/en/master/installation/index.html" target="_blank" rel="noopener">Read the detailed documentation on how to install or upgrade privacyIDEA</a>.</p>
<p>You should always take a look at the <a href="https://github.com/privacyidea/privacyidea/blob/master/Changelog" target="_blank" rel="noopener">Changelog</a>, but starting with privacyIDEA we added a document <a href="https://github.com/privacyidea/privacyidea/blob/master/READ_BEFORE_UPDATE.md" target="_blank" rel="noopener">READ_BEFORE_UPDATE</a>, which contains important information to consider before upgrade.</p>
<p><figure id="attachment_1352" aria-describedby="caption-attachment-1352" style="width: 1280px" class="wp-caption aligncenter"><a href="https://www.privacyidea.org/wp-content/uploads/2018/03/background-3228704_1280.jpg"><img loading="lazy" decoding="async" class="size-full wp-image-1352" src="https://www.privacyidea.org/wp-content/uploads/2018/03/background-3228704_1280.jpg" alt="" width="1280" height="544" srcset="https://www.privacyidea.org/wp-content/uploads/2018/03/background-3228704_1280.jpg 1280w, https://www.privacyidea.org/wp-content/uploads/2018/03/background-3228704_1280-300x128.jpg 300w, https://www.privacyidea.org/wp-content/uploads/2018/03/background-3228704_1280-768x326.jpg 768w, https://www.privacyidea.org/wp-content/uploads/2018/03/background-3228704_1280-1024x435.jpg 1024w" sizes="auto, (max-width: 1280px) 100vw, 1280px" /></a><figcaption id="caption-attachment-1352" class="wp-caption-text">privacyIDEA 2.22 is improving the RADIUS functionality to be more flexible in combination with VPNs and firewalls.</figcaption></figure></p>
<h3>New Features: RADIUS integration, VASCO support, Offline Refill and more</h3>
<p>With privacyIDEA 2.22 we added the possibility to pass more useful userinformation to a RADIUS client like a VPN. The administrator can add a policy to include the resolver and the realm of a user who authenticated successfully. This response data can then be used in the FreeRADIUS plugin and modified by regular expressions to add any arbitrary RADIUS attribute in the RADIUS response, which then would be sent to the VPN. This additional information can be used by Cisco ASA, Citrix Netscaler or any other enterprise grade VPN to put the user into certain subnets or to assign resource to the user.</p>
<h4>VASCO token support</h4>
<p>privacyIDEA is Open Source. We love Open Source and open standards. But sometimes you have to communicate with proprietary partners, so that they have the chance to become open. This is why privacyIDEA 2.22 comes with support for the proprietary VASCO Digipass tokens. This way it is easier to run VASCO tokens and open standards tokens like HOTP, TOTP or Yuibkeys in parallel and maybe even one day migrate all VASCO tokens &#8211; after the batteries have died &#8211; to other devices.</p>
<p>If you want to learn more about migrating your VASCO tokens, please contact <a href="https://netknights.it/en/unternehmen/kontakt/" target="_blank" rel="noopener">NetKnights for professional sevices</a>.</p>
<h4>Offline Refill</h4>
<p>We are improving the offline capability of privacyIDEA in conjunction with the PAM module and the <a href="https://netknights.it/en/produkte/privacyidea-credential-provider/" target="_blank" rel="noopener">privacyIDEA Credential Provider</a>. The new offline refill will allow to automatically refill the hashed OTP values on the notebooks, which are available for authentication, if the notebook is offline. This way users or administrators will not have to worry anymore when taking the hardware on a business trip.</p>
<h4>Send SMS via SMPP</h4>
<p>SMPP (Short Message Peer-to-Peer) is a protocol used by carriers for sending SMS. privacyIDEA 2.22 comes with a new SMS Provider to send SMS via SMPP. This can be used for sending SMS in the SMS token during authentication but also for sending SMS in the notification event handler, to notify users or administrators on certain events.</p>
<h4>Use Counter handler for monitoring and statistics</h4>
<p>&nbsp;</p>
<p><figure id="attachment_1355" aria-describedby="caption-attachment-1355" style="width: 283px" class="wp-caption alignright"><a href="https://www.privacyidea.org/wp-content/uploads/2018/03/speedometer-662191_1280.jpg"><img loading="lazy" decoding="async" class=" wp-image-1355" src="https://www.privacyidea.org/wp-content/uploads/2018/03/speedometer-662191_1280.jpg" alt="" width="283" height="212" srcset="https://www.privacyidea.org/wp-content/uploads/2018/03/speedometer-662191_1280.jpg 1280w, https://www.privacyidea.org/wp-content/uploads/2018/03/speedometer-662191_1280-300x225.jpg 300w, https://www.privacyidea.org/wp-content/uploads/2018/03/speedometer-662191_1280-768x576.jpg 768w, https://www.privacyidea.org/wp-content/uploads/2018/03/speedometer-662191_1280-1024x768.jpg 1024w" sizes="auto, (max-width: 283px) 100vw, 283px" /></a><figcaption id="caption-attachment-1355" class="wp-caption-text">With the counter handler the administrator can count arbitrary events and use this data for statistics.</figcaption></figure></p>
<p>We often see, that the event handler is a mighty tool to cope with many different requirements. In addition to the notification handler, token handler, script handler and federation handler privacyIDEA 2.22 now comes with a simply but very flexible counter handler. Just like every handler it can be attached to any event (API call) and will trigger under defined conditions. The counter handler simply increses a counter in the database for this very event.</p>
<p>These counters can now be used for statistics or monitoring, e.g. when increasing a certain counter on the event failed authentication with HOTP token. This way the administrator could monitor the number of failed authentications per time interval.</p>
<h4>Each token has a tokenkind</h4>
<p>Many installations use hardware tokens and software tokens at the same time. To be more flexible in distinguishing these tokens when it comes to deleting tokens or deciding giving access, we added an additional class attribute to tokens. The &#8220;tokenkind&#8221;. In contrast to the tokentype, which is simply the mathematics of the token, the tokenkind defines if this very token object is  hardware token, a software token or a virtual token.</p>
<h4>Use arbitrary tokeninfo in authorization policies</h4>
<p>Authorization policies are used to decide if an authenticated user should get access or not. As the arbitrary tokeninfo fields are getting used more in more in event handler definitions, the tokeninfo can now also be used in the authorization policies to grant or deny access.</p>
<p>This way event handlers could modify token information and this modified token information can be used for granting access. Event handling and authorization thus get connected more tightly.</p>
<h3>Lots of enhancements</h3>
<p>There are further enhancements of existing features in privacyIDEA. We improved the token export the PSKC files &#8211; we will also export PW token types and the counter values of HOTP and TOTP tokens. The export can now also be used to reencrypt a token database.</p>
<p>The SMS and Email token types can now either use the fixed mobile number or email address in the token data or read the mobile/email dynamically from the user store on each authentication event.</p>
<p>The administrator can define a policy so that the validity of the U2F attestation certificate will be ignored. Some U2F devices come with a attestation certificate with an invalid validity period.</p>
<p>We improved the speed of the LinOTP migration script, so that a database with tens of thousands of tokens can be easily migrated.</p>
<p>The pi-manage script can now generate API tokens with a freely chosen validity time.</p>
<p>The user can now set the description of HOTP and TOTP tokens during enrollment.</p>
<p>The administrator can add a timeout to the SMTP server configuration.</p>
<p>The email tokens can now use a complex html template for sending emails.</p>
<p>The LDAP resolver allows to define each attribute as a multivalue attribute.</p>
<p>The event handler condition can trigger on failed authentication.</p>
<p>For the complete changelog with also contains all the fixes, please take a look a the <a href="https://github.com/privacyidea/privacyidea/blob/master/Changelog" target="_blank" rel="noopener">Github repository</a>.</p>
<h3>Enterprise Edition</h3>
<p>If you are running large mission critical setups, privacyIDEA is also available as <a href="https://netknights.it/en/produkte/privacyidea/" target="_blank" rel="noopener">Enterprise Edition with support and warranty/liability</a>.</p>
<h3>privacyIDEA at Grazer Linuxtage and Linuxfest Northwest</h3>
<p>At the end of April you can hear a <a href="https://glt18-programm.linuxtage.at/events/322.html" target="_blank" rel="noopener">talk about privacyIDEA</a> in Austria at the <a href="https://www.linuxtage.at/" target="_blank" rel="noopener">Grazer Linuxtage</a>. You will learn, how you can easily migrate an old, existing, proprietary 2FA system to privacyIDEA. Project member Friedrich Weber will also host a <a href="https://glt18-programm.linuxtage.at/events/323.html" target="_blank" rel="noopener">workshop at the Grazer Linuxtage</a>, where you can participate in installing privacyIDEA and configuring to your needs.</p>
<p>At the same time Cornelius Kölbel will give a talk in Bellingham Technical Colleage, U.S.A. At the <a href="https://www.linuxfestnorthwest.org/conferences/lfnw18" target="_blank" rel="noopener">LinuxFest NorthWest 2018</a> you can learn about what makes privacyIDEA so unique in regards to workflow integrations using the privacyIDEA Event Handler system automating a lot of individual tasks.</p>
<h3>Join the discussion</h3>
<p>Join the discussion a <a href="https://community.privacyidea.org" target="_blank" rel="noopener">community.privacyidea.org</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.privacyidea.org/privacyidea-2-22-with-a-more-flexible-radius-integration/feed/</wfw:commentRss>
			<slash:comments>1</slash:comments>
		
		
			</item>
		<item>
		<title>privacyIDEA 2.19.1</title>
		<link>https://www.privacyidea.org/privacyidea-2-19-1/</link>
		
		<dc:creator><![CDATA[Cornelius Kölbel]]></dc:creator>
		<pubDate>Sun, 02 Jul 2017 10:45:09 +0000</pubDate>
				<category><![CDATA[release]]></category>
		<guid isPermaLink="false">https://www.privacyidea.org/?p=1238</guid>

					<description><![CDATA[The Enterprise Release 2.19.1 was published to the repositories today. 2.19.1 is a bugfixing release of privacyIDEA 2.19. The following changes were made in 2.19.1: Minor enhancements: Add &#8220;pi-manage policy load&#8221; and &#8220;pi-manage policy export&#8221;. (#721) Allow customization via pi.cfg file. Add {username} and {realm} as tags for the tokenhandler. (#735) Fixes Fix pi-manage file [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>The Enterprise Release 2.19.1 was published to the repositories today. 2.19.1 is a bugfixing release of <a href="https://www.privacyidea.org/privacyidea-2-19-u2f-secure-smartphone-apps/">privacyIDEA 2.19</a>.</p>
<p>The following changes were made in 2.19.1:</p>
<p>Minor enhancements:</p>
<ul>
<li>Add &#8220;pi-manage policy load&#8221; and &#8220;pi-manage policy export&#8221;. (#721)</li>
<li>Allow customization via pi.cfg file.</li>
<li>Add {username} and {realm} as tags for the tokenhandler. (#735)</li>
</ul>
<p>Fixes</p>
<ul>
<li>Fix pi-manage file permission for backup</li>
<li>Fix search for resolver in audit log</li>
<li>Allow to read old legacy time from validity period</li>
<li>Fix wrong enddate with lost_token</li>
<li>Fix typos</li>
<li>Improve documentation for yubikey</li>
<li>Improve documentation for cache decorator</li>
<li>Improve documentation for webui policy</li>
</ul>
<p>With privacyIDEA 2.19.1 the company NetKnights also started to provide a <a href="https://netknights.it/en/privacyidea-enterprise-edition-and-appliance/" target="_blank" rel="noopener noreferrer">privacyIDEA appliance</a>.</p>
<p>You can install and update privacyIDEA from the Ubuntu PPA repositories for Ubuntu 14.04 and 16.04 and from the python package index.</p>
<p>Do not forget to stop by the <a href="https://community.privacyidea.org" target="_blank" rel="noopener noreferrer">privacyIDEA Forum</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>2FA Workshop at tuebix</title>
		<link>https://www.privacyidea.org/2fa-workshop-tuebix/</link>
		
		<dc:creator><![CDATA[Cornelius Kölbel]]></dc:creator>
		<pubDate>Thu, 22 Jun 2017 10:14:51 +0000</pubDate>
				<category><![CDATA[documentation]]></category>
		<category><![CDATA[events]]></category>
		<category><![CDATA[Howto]]></category>
		<category><![CDATA[LDAP]]></category>
		<category><![CDATA[ownCloud]]></category>
		<category><![CDATA[talk]]></category>
		<category><![CDATA[Univention Corporate Server]]></category>
		<guid isPermaLink="false">https://www.privacyidea.org/?p=1226</guid>

					<description><![CDATA[We are at Tübix 2017 and doing a workshop about adding a 2nd Factor to your applications. If you can not attend or if you want to try this at home afterwards, here is what we will do! Setup 10.0.2.201 ucs.tuebix.intranet (LDAP) Univention Corporate Server 4.2 10.0.2.202 privacyidea.tuebix.intranet, Ubuntu 16.04 LTS 10.0.2.203 wordpress.tuebix.intranet, Ubuntu 16.04 LTS [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>We are at <a href="http://www.tuebix.org/2017/programm/cornelius-koelbel-mehr-faktor-authentifizierung-nicht-nur-fuer-die-eigene-cloud/" target="_blank" rel="noopener noreferrer">Tübix 2017</a> and doing a workshop about adding a 2nd Factor to your applications.</p>
<p>If you can not attend or if you want to try this at home afterwards, here is what we will do!</p>
<h2>Setup</h2>
<p>10.0.2.201 ucs.tuebix.intranet (LDAP) Univention Corporate Server 4.2<br />
10.0.2.202 privacyidea.tuebix.intranet, Ubuntu 16.04 LTS<br />
10.0.2.203 wordpress.tuebix.intranet, Ubuntu 16.04 LTS with latest wordpress<br />
10.0.2.204 owncloud.tuebix.intranet, Ubuntu 16.04 LTS with ownCloud 10</p>
<h3>LDAP</h3>
<p>BaseDN: cn=users,dc=tuebix,dc=intranet</p>
<p>The UCS has the following users:</p>
<ul>
<li>admininistrator</li>
<li>user1</li>
<li>user2</li>
<li>user3</li>
</ul>
<h3>ownCloud</h3>
<p>ownCloud is connected via LDAP, so the LDAP users can connect to ownCloud.</p>
<p>The ownCloud Administrator is called: admin</p>
<h3>WordPress</h3>
<p>WordPress only has internal users. Nevertheless the user are also called:</p>
<ul>
<li>administrator</li>
<li>user1</li>
<li>user2</li>
<li>user3</li>
</ul>
<h2>What we will do &#8211; our Agenda</h2>
<ul>
<li>We will install privacyIDEA and connect privacyIDEA to the UCS, so that privacyIDEA knows the users from the LDAP directory</li>
<li>Then we will enroll different kind of tokens to the users.
<ul>
<li>The administrator can enroll a token for the users but</li>
<li>users can also login to the webui with their LDAP password an enroll a token for themselves.</li>
</ul>
</li>
<li>Then we start connecting <strong>applications</strong> to privacyIDEA to add <strong>2FA</strong> to the <strong>applications</strong>
<ul>
<li>WordPress with &#8220;strong authentication&#8221; plugin</li>
<li>ownCloud with the &#8220;privacyIDEA ownCloud App&#8221; from the market place</li>
<li>SSH login with 2FA for users user1, user2, user3</li>
</ul>
</li>
</ul>
<h2>privacyIDEA</h2>
<h3>Install</h3>
<p>privacyIDEA can be <a href="http://privacyidea.readthedocs.io/en/latest/installation/ubuntu.html" target="_blank" rel="noopener noreferrer">installed</a> in many different ways on different Linux distributions. We will install privacyIDEA on our Ubuntu 16.04 machine 10.0.2.202.</p>
<p>As root:</p>
<pre>add-apt-repository ppa:privacyidea/privacyidea

apt update

apt install privacyidea-apache2</pre>
<p>privacyidea-apache2 is a meta package which will install MySQL, Apache and set up privacyIDEA. Finally we only need to create the first token administrator.</p>
<pre>pi-manage add admin super</pre>
<p>Now we have an administrator called &#8220;super&#8221;</p>
<h3>Configure</h3>
<p>privacyIDEA can be configured via command line, API or the web UI.</p>
<p><a href="https://10.0.2.202" target="_blank" rel="noopener noreferrer">https://10.0.2.202</a></p>
<p>We need to configure the Resolver <strong>tuebix_users</strong> as Active Directory. For this we need to fetch the certificate of the UCS server.</p>
<ul>
<li>LDAP Resolver to ldaps://ucs.tuebix.intranet</li>
<li>Base DN cn=users,dc=tuebix,dc=intranet</li>
<li>Bind DN cn=administrator,cn=users,dc=tuebix,dc=intranet</li>
<li>Preset AD</li>
</ul>
<p>And a Realm <strong>tuebix</strong> with the resolver <strong>tuebix_users</strong>.</p>
<p>We can also take a look at the policies and configure a policy to use otppin=userstore.</p>
<h3>Enroll tokens</h3>
<p>Enroll tokens as administrator and as normal user&#8230;</p>
<ul>
<li>Enroll Smartphone App</li>
<li>Yubikey</li>
<li>U2F Token</li>
<li>Feitian C200 (import File Feitian.csv)</li>
</ul>
<h2>ownCloud with 2FA</h2>
<p>For ownCloud X we login as administrator and install the &#8220;privacyIDEA ownCloud App&#8221; from the Marketplace.</p>
<p>We need to configure the App against privacyIDEA:</p>
<ul>
<li>https://privacyidea.tuebix.intranet</li>
<li>no realm</li>
<li>no ssl check</li>
</ul>
<p><strong>Note:</strong> The privacyIDEA ownCloud App will authenticate <strong>all</strong> users with a 2nd factor!</p>
<p>After this, users need to present a 2nd factor against privacyIDEA when they log in.</p>
<h2>WordPress with 2FA</h2>
<p>Install the &#8220;strong authentication&#8221; plugin.</p>
<p>We need to configure the Plugin against privacyIDEA:</p>
<ul>
<li>https://privacyidea.tuebix.intranet&#8230;</li>
</ul>
<p><strong>Note:</strong> Users need to enter both factors in the password field at the same time.</p>
<p>The WordPress plugin authenticates users <strong>only</strong> against privacyIDEA; while with ownCloud users are authenticated by ownCloud and by privacyIDEA.</p>
<h2>SSH with 2FA</h2>
<p>On either owncloud machine or wordpress machine we install the privacyIDEA PAM module:</p>
<pre>add-apt-repository ppa:privacyidea/privacyidea

apt update

apt install privacyidea-pam</pre>
<p>&#8230;and configure it accordingly against https://privacyidea.tuebix.intranet.</p>
<p><strong>Note</strong>: Users need to match!</p>
<h2>privacyIDEA LDAP Proxy</h2>
<p>Bonus!</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Is it really faster? Measuring the performance of authentication requests</title>
		<link>https://www.privacyidea.org/measuring-the-performance-of-authentication-requests/</link>
		
		<dc:creator><![CDATA[Friedrich Weber]]></dc:creator>
		<pubDate>Wed, 31 May 2017 10:11:04 +0000</pubDate>
				<category><![CDATA[release]]></category>
		<category><![CDATA[Whatsup]]></category>
		<category><![CDATA[Authentication]]></category>
		<category><![CDATA[Benchmark]]></category>
		<category><![CDATA[Performance]]></category>
		<guid isPermaLink="false">https://www.privacyidea.org/?p=1214</guid>

					<description><![CDATA[Some days ago, we released the new version 2.19 of the privacyIDEA authentication system. As explained in the release notes, we worked on improving the performance of authentication requests and managed to reduce the time needed to handle one authentication request by up to 71%! If such claims make you suspicious, we totally understand your [&#8230;]]]></description>
										<content:encoded><![CDATA[<p><a href="https://www.privacyidea.org/wp-content/uploads/2017/05/group-of-people-1645356_1280.jpg"><img loading="lazy" decoding="async" class="alignleft size-medium wp-image-1215" src="https://www.privacyidea.org/wp-content/uploads/2017/05/group-of-people-1645356_1280-300x200.jpg" alt="" width="300" height="200" srcset="https://www.privacyidea.org/wp-content/uploads/2017/05/group-of-people-1645356_1280-300x200.jpg 300w, https://www.privacyidea.org/wp-content/uploads/2017/05/group-of-people-1645356_1280-768x512.jpg 768w, https://www.privacyidea.org/wp-content/uploads/2017/05/group-of-people-1645356_1280-1024x682.jpg 1024w, https://www.privacyidea.org/wp-content/uploads/2017/05/group-of-people-1645356_1280.jpg 1280w" sizes="auto, (max-width: 300px) 100vw, 300px" /></a>Some days ago, we released the <a href="https://www.privacyidea.org/privacyidea-2-19-u2f-secure-smartphone-apps/">new version 2.19</a> of the privacyIDEA authentication system. As explained in the release notes, we worked on improving the performance of authentication requests and managed to reduce the time needed to handle one authentication request by up to 71%! If such claims make you suspicious, we totally understand your concerns. This is why we will explain our benchmark approach in this blog post, so you can see for yourself where our numbers come from.</p>
<p>The first question we asked ourselves was: What exactly do we want to find out? As we worked a lot on optimizing the LDAP resolver, we first wanted to know if privacyIDEA 2.19 by itself processes authentication requests faster than privacyIDEA 2.18.1. The next question was whether performance can be further improved by enabling the new user cache feature of privacyIDEA 2.19. Here, we wanted to differentiate between a worst-case scenario with an empty cache and a best-case scenario with an already-populated cache. For each scenario, we wanted to get an idea of the time that privacyIDEA needs to handle an incoming authentication request. Having cleared our objective, the next step was creating a suitable lab environment that resembles the real world as closely as possible to run our benchmarks in.</p>
<h2>Our lab environment</h2>
<p>We created a lab environment as follows. First, we set up an <a href="https://www.univention.com/products/ucs/">Univention Corporate Server</a> and added 1000 users to its directory, which we simply called <code>user000</code> to <code>user999</code>, as well as a privacyIDEA service account. In the same network, we prepared two Ubuntu 16.04 virtual machines and installed privacyIDEA 2.18.1 on the first and privacyIDEA 2.19-dev5 on the second machine. On both instances, we added a realm with a LDAP resolver connecting to the Univention Corporate Server via LDAPS.</p>
<p>In order to keep our environment as close to the real world as possible, we would need to enroll HOTP or TOTP tokens for our 1000 users. However, we ultimately decided against it. For one, we suspected that the time spent calculating and checking the next OTP value on the server is relatively small in comparison to the time spent communicating with the LDAP server. Enrolling real OTP tokens would also require us to keep track of secrets and counter values on our benchmark client, which would complicate our setup a lot. To keep things simple, we instead decided to enroll one <a href="http://privacyidea.readthedocs.io/en/latest/configuration/tokens/spass.html">simple password (SPASS)</a> token for each user.</p>
<h2>Our benchmarking approach</h2>
<p>Now, we had set up two privacyIDEA instances with 1000 tokens. The next question was: How exactly do we now measure the performance of one authentication request? We decided to settle on the following approach: One benchmark consists of 2000 successful authentication requests, performed one after another for the users <code>user000</code> to <code>user999</code>. This means that each user is authenticated twice during one benchmark. For each authentication request, we measured the time from sending the request until receiving the response using a simple benchmarking script in Python based on <a href="http://docs.python-requests.org/en/master/">python-requests</a>. We copied the script to the virtual machines and performed all authentication requests against <code>https://localhost</code> in order to exclude the network delay from our measurements. Running the script then produces 2000 measurements of response time, of which we computed the median response time.</p>
<p>We decided to measure the response times for the following scenarios:</p>
<ul>
<li>Scenario #1: Authentication against privacyIDEA 2.18.1</li>
<li>Scenario #2: Authentication against privacyIDEA 2.19, with the user cache feature disabled</li>
<li>Scenario #3: Authentication against privacyIDEA 2.19, with the user cache enabled and initially empty</li>
<li>Scenario #4: Authentication against privacyIDEA 2.19, with an already-populated user cache. This means<br />
that the user cache contains valid 1000 entries, one for each user from <code>user000</code> to<br />
<code>user999</code>.</li>
</ul>
<p>The scenarios 2, 3 and 4 were carried out on the privacyIDEA 2.19 machine. For scenarios 3 and 4, we enabled the user cache with a timeout of one day (corresponding to 86400 seconds).</p>
<h2>Our results</h2>
<p>Now, we had everything in place to start our benchmarks! In total, running the benchmark for all four scenarios took roughly one hour and we obtained the following results.</p>
<table>
<tbody>
<tr>
<th>scenario#</th>
<th>description</th>
<th>median response time</th>
</tr>
<tr>
<td>#1</td>
<td>privacyIDEA 2.18.1</td>
<td>716ms</td>
</tr>
<tr>
<td>#2</td>
<td>privacyIDEA 2.19, disabled user cache</td>
<td>306ms</td>
</tr>
<tr>
<td>#3</td>
<td>privacyIDEA 2.19, enabled but initially empty user cache</td>
<td>268ms</td>
</tr>
<tr>
<td>#4</td>
<td>privacyIDEA 2.19, enabled and populated user cache</td>
<td>203ms</td>
</tr>
</tbody>
</table>
<p>Interesting! According to our measurements, an update to privacyIDEA 2.19 alone seems to reduce the median response time by roughly 57% (Scenario #2), even without enabling the user cache. This speedup can probably be attributed to some performance improvements in the LDAP resolver (see issues <a href="https://github.com/privacyidea/privacyidea/issues/655">655</a> and <a href="https://github.com/privacyidea/privacyidea/issues/664">664</a>).</p>
<p>Furthermore, if the user cache is enabled and fully populated (Scenario #4), the median response time is reduced by another 33%. In comparison to privacyIDEA 2.18.1, this corresponds to a reduction by 71%. Of course, this models a best-case scenario in which the LDAP server does not need to be queried any more at all. This may not be the case in the real world, e.g. if <a href="http://privacyidea.readthedocs.io/en/latest/policies/authentication.html#otppin">an otppin=userstore policy</a> is enabled.</p>
<p>Scenario #3 is quite interesting, as the user cache is initially empty and is subsequently populated during the first 1000 authentication requests. For the second round of 1000 authentications, privacyIDEA can rely on the user cache instead of querying the LDAP server. We can also observe this if we plot our measurements:</p>
<p><a href="https://www.privacyidea.org/wp-content/uploads/2017/05/run1-pi2.19-usercache.png"><img loading="lazy" decoding="async" class="aligncenter size-medium wp-image-1217" src="https://www.privacyidea.org/wp-content/uploads/2017/05/run1-pi2.19-usercache-300x225.png" alt="" width="300" height="225" srcset="https://www.privacyidea.org/wp-content/uploads/2017/05/run1-pi2.19-usercache-300x225.png 300w, https://www.privacyidea.org/wp-content/uploads/2017/05/run1-pi2.19-usercache.png 640w" sizes="auto, (max-width: 300px) 100vw, 300px" /></a></p>
<p>The horizontal axis denotes our measurements and the vertical axis gives the median response time in milliseconds. We can observe that the median response time drops dramatically after the thousandth measurement, from which we can conclude that the user cache does have a measurable positive impact on the performance of authentication requests.</p>
<p>Of course, our benchmark is not perfect and leaves room for improvement due to multiple reasons. Firstly, the measurements also include the round-trip time between LDAP server and privacyIDEA instance, which significantly depends on the network setup. Secondly, we have only enrolled SPASS tokens and no real OTP tokens. Thirdly, we have not performed any concurrent requests and cannot, for example, say anything about the maximum number of authentication requests per second. Finally, two authentication requests by the same user are several minutes apart. If the same user sends two authentication requests during the timespan configured by the <em>cache timeout</em> option of the LDAP resolver (which defaults to 2 minutes), privacyIDEA queries an in-memory cache, which may be even faster than the query to the local database performed by the user cache.</p>
<p>However, we believe that our benchmark shows that privacyIDEA 2.19 improves the performance of authentication requests quite significantly even without the user cache. Additionally, enabling the user cache may bring significant performance improvements in case a large number of users are expected to send authentication requests over a large timespan. Finally, we noticed that the LDAP connection in our test setup is quite fast (a LDAP search takes just unter 30 milliseconds), so the user cache may provide an even better speedup in case of slower LDAP servers or connections. You are welcome to try it out for yourself! If you have any further questions, pleask ask them on our <a href="https://community.privacyidea.org/">community site</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>privacyIDEA 2.19 &#8211; U2F and Secure Smartphone Apps</title>
		<link>https://www.privacyidea.org/privacyidea-2-19-u2f-secure-smartphone-apps/</link>
					<comments>https://www.privacyidea.org/privacyidea-2-19-u2f-secure-smartphone-apps/#comments</comments>
		
		<dc:creator><![CDATA[Cornelius Kölbel]]></dc:creator>
		<pubDate>Fri, 26 May 2017 08:27:12 +0000</pubDate>
				<category><![CDATA[Uncategorized]]></category>
		<guid isPermaLink="false">https://www.privacyidea.org/?p=1206</guid>

					<description><![CDATA[We released privacyIDEA 2.19! Need for Speed privacyIDEA is used in quite some big setups. So in this release we also had the focus on speed! With different actions we were able to reduce the time needed for one authentication request by up to 72%! (According to our lab environment &#8211; other numbers may differ) [&#8230;]]]></description>
										<content:encoded><![CDATA[<p>We released privacyIDEA 2.19!</p>
<h2>Need for Speed</h2>
<p><figure id="attachment_1209" aria-describedby="caption-attachment-1209" style="width: 269px" class="wp-caption alignleft"><a href="https://www.privacyidea.org/wp-content/uploads/2017/05/traffic-332857_1280.jpg"><img loading="lazy" decoding="async" class="wp-image-1209" src="https://www.privacyidea.org/wp-content/uploads/2017/05/traffic-332857_1280-300x200.jpg" alt="" width="269" height="179" srcset="https://www.privacyidea.org/wp-content/uploads/2017/05/traffic-332857_1280-300x200.jpg 300w, https://www.privacyidea.org/wp-content/uploads/2017/05/traffic-332857_1280-768x512.jpg 768w, https://www.privacyidea.org/wp-content/uploads/2017/05/traffic-332857_1280-1024x682.jpg 1024w, https://www.privacyidea.org/wp-content/uploads/2017/05/traffic-332857_1280.jpg 1280w" sizes="auto, (max-width: 269px) 100vw, 269px" /></a><figcaption id="caption-attachment-1209" class="wp-caption-text">privacyIDEA 2.19 is much faster, now.</figcaption></figure></p>
<p>privacyIDEA is used in quite some big setups. So in this release we also had the focus on speed! With different actions we were able to reduce the time needed for one authentication request by up to 72%! (According to our lab environment &#8211; other numbers may differ)</p>
<p>So how did we manage this?</p>
<p>Many setups run their users in an LDAP directory or Microsoft Active Directory. As privacyIDEA does not store users but only references to user objects in user directories, we need to find the user object, when a user enters a login name. Thus, during authentication some LDAP requests are involved to resolve the login name to this user reference. We manage to optimize our LDAP calls, which resulted in a speed up of 57% in comparison to privacyIDEA 2.18.</p>
<h3>The User Cache</h3>
<p>But still privacyIDEA has to query the LDAP server. There can be setups, where the connection to the LDAP server is rather slow, since it is located behind a VPN connection. So we added a user cache in privacyIDEA 2.19. The <a href="http://privacyidea.readthedocs.io/en/latest/configuration/useridresolvers.html#user-cache" target="_blank" rel="noopener noreferrer">user cache</a> stores the login name and reference to user object in the local SQL database. Thus, once a user is know, there is no need for a further LDAP call.</p>
<p>In our lab environment we measured a further speed up of 33%, if the user cache is used with LDAP users. This effect could be even better, if you are running a slow LDAP connection!</p>
<h2>U2F</h2>
<p><figure id="attachment_1210" aria-describedby="caption-attachment-1210" style="width: 123px" class="wp-caption alignright"><a href="https://www.privacyidea.org/wp-content/uploads/2017/05/Security-Key-by-Yubico-1000-2016-444x444.png"><img loading="lazy" decoding="async" class="wp-image-1210" src="https://www.privacyidea.org/wp-content/uploads/2017/05/Security-Key-by-Yubico-1000-2016-444x444-300x300.png" alt="" width="123" height="123" srcset="https://www.privacyidea.org/wp-content/uploads/2017/05/Security-Key-by-Yubico-1000-2016-444x444-300x300.png 300w, https://www.privacyidea.org/wp-content/uploads/2017/05/Security-Key-by-Yubico-1000-2016-444x444-150x150.png 150w, https://www.privacyidea.org/wp-content/uploads/2017/05/Security-Key-by-Yubico-1000-2016-444x444.png 444w" sizes="auto, (max-width: 123px) 100vw, 123px" /></a><figcaption id="caption-attachment-1210" class="wp-caption-text">privacyIDEA can filter for certain U2F device types.</figcaption></figure></p>
<p>privacyIDEA comes with two new policies for <a href="http://privacyidea.readthedocs.io/en/latest/policies/enrollment.html#u2f-req" target="_blank" rel="noopener noreferrer">enrollment</a> and for <a href="http://privacyidea.readthedocs.io/en/latest/policies/authorization.html#u2f-req" target="_blank" rel="noopener noreferrer">authentication</a>.</p>
<p>The administrator can define a regular expression to restrict the types of U2F devices, that may be enrolled or used for authentication. This way a company may restrict the usage of U2F devices to one of a specific vendor. Or certain resources may only be accessed with some special U2F devices.</p>
<h2>Secure Smartphones Apps</h2>
<p>To use the Smartphone as your authentication device is a very common scenario nowadays. Everyone is taking care for his smartphone and is carrying it along. But as <a href="https://netknights.it/en/the-problem-with-the-google-authenticator/" target="_blank" rel="noopener noreferrer">stated in the NetKnights blog post</a>, the enrollment process most of the time is not that secure. The Key URI in the QR Code introduced with the Google Authenticator and used by many smartphone apps out there, contains the secret key.</p>
<p>privacyIDEA comes with a new integrated mutual key enrollment which makes implementing smartphone apps with a secure key enrollment much simpler. The privacyIDEA server and the smartphone app both create one component. The actual key is generated from these two components. Thus the secret key can not be easily copied and shared between several smartphones.</p>
<h2>Further enhancements</h2>
<p>There are many other enhancements. The time format was improved by adding a timezone. Policies and Eventhandler had some improvements like being able to set the Client IP or the User Agent in the tokeninfo fields.</p>
<p>The full Changelog can be found <a href="https://github.com/privacyidea/privacyidea/blob/v2.19/Changelog" target="_blank" rel="noopener noreferrer">here</a>.</p>
<p>&nbsp;</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.privacyidea.org/privacyidea-2-19-u2f-secure-smartphone-apps/feed/</wfw:commentRss>
			<slash:comments>2</slash:comments>
		
		
			</item>
		<item>
		<title>privacyIDEA at Open Source Event Chemnitzer Linuxtage</title>
		<link>https://www.privacyidea.org/privacyidea-open-source-event-chemnitzer-linuxtage/</link>
		
		<dc:creator><![CDATA[Cornelius Kölbel]]></dc:creator>
		<pubDate>Sat, 18 Feb 2017 16:43:27 +0000</pubDate>
				<category><![CDATA[events]]></category>
		<category><![CDATA[Whatsup]]></category>
		<category><![CDATA[Linuxtag]]></category>
		<category><![CDATA[talk]]></category>
		<guid isPermaLink="false">https://www.privacyidea.org/?p=1148</guid>

					<description><![CDATA[Get involved! In March we will have a booth at the Chemnitzer Linuxtage (March 11th and 12th). Chemnitzer Linuxtage is the biggest yearly Linux event in Germany with about 3000 visitors. At the booth we will have a demo installation of privacyIDEA, different token types like Yubikeys, U2F devices, Nitrokeys or OTP-Tokens and Cards to present [&#8230;]]]></description>
										<content:encoded><![CDATA[<h2>Get involved!</h2>
<p>In March we will have a booth at the <a href="https://chemnitzer.linux-tage.de/2017/en/programm/live" target="_blank">Chemnitzer Linuxtage</a> (March 11th and 12th). Chemnitzer Linuxtage is the biggest yearly Linux event in Germany with about 3000 visitors.</p>
<p>At the booth we will have a demo installation of privacyIDEA, different token types like Yubikeys, U2F devices, Nitrokeys or OTP-Tokens and Cards to present possible solutions to interested visitors. <a href="https://www.privacyidea.org/wp-content/uploads/2017/02/clt_180dpi-2.png"><img loading="lazy" decoding="async" class="size-medium wp-image-1149 alignright" src="https://www.privacyidea.org/wp-content/uploads/2017/02/clt_180dpi-2-300x107.png" alt="" width="300" height="107" srcset="https://www.privacyidea.org/wp-content/uploads/2017/02/clt_180dpi-2-300x107.png 300w, https://www.privacyidea.org/wp-content/uploads/2017/02/clt_180dpi-2.png 394w" sizes="auto, (max-width: 300px) 100vw, 300px" /></a></p>
<p>If you also want to get personally involved in the privacyIDEA project and development and act as a stand helper you are welcome to join us at our stand. Please drop me a <a href="https://groups.google.com/forum/#!topic/privacyidea/HZVKhOGX6ac" target="_blank">note via the Google Group</a>. You will get free entrance, catering and saturday night event dinner. At the moment we are three persons at the stand. We are looking forward to your experiences, your questions and you as a real life person.</p>
<p>See you in Chemnitz!</p>
<p>Cornelius</p>
<p>&nbsp;</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
