<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>4eyes &#8211; privacyID3A</title>
	<atom:link href="https://www.privacyidea.org/tag/4eyes/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.privacyidea.org</link>
	<description>flexible, Open Source Multi Factor Authentication (2FA)</description>
	<lastBuildDate>Tue, 22 Dec 2020 00:08:23 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.7.5</generator>

<image>
	<url>https://www.privacyidea.org/wp-content/uploads/2016/06/cropped-only-logo-white-background-32x32.png</url>
	<title>4eyes &#8211; privacyID3A</title>
	<link>https://www.privacyidea.org</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Multi-Factor Authentication privacyIDEA 3.5 released</title>
		<link>https://www.privacyidea.org/multi-factor-authentication-privacyidea-3-5-released/</link>
		
		<dc:creator><![CDATA[Cornelius Kölbel]]></dc:creator>
		<pubDate>Tue, 22 Dec 2020 00:08:21 +0000</pubDate>
				<category><![CDATA[release]]></category>
		<category><![CDATA[4eyes]]></category>
		<category><![CDATA[Dashboard]]></category>
		<category><![CDATA[Policies]]></category>
		<category><![CDATA[smartcards]]></category>
		<guid isPermaLink="false">https://www.privacyidea.org/?p=2223</guid>

					<description><![CDATA[Gaining higher security with smartcards and Four-Eyes-Tokens Today we put privacyIDEA 3.5 under your Christmas tree. Unwrap it and you will find a lot of enhancements. One of the most important features is that version 3.5 does the first step to also support smartcard management. For high security environments we drastically imrpoved the workflow of [&#8230;]]]></description>
										<content:encoded><![CDATA[
<p><strong>Gaining higher security with smartcards and Four-Eyes-Tokens</strong></p>



<div class="wp-block-image"><figure class="aligncenter size-large is-resized"><img fetchpriority="high" decoding="async" src="https://www.privacyidea.org/wp-content/uploads/2020/12/A-smartcard-in-a-notebook-1024x699.jpg" alt="" class="wp-image-2225" width="933" height="637" srcset="https://www.privacyidea.org/wp-content/uploads/2020/12/A-smartcard-in-a-notebook-1024x699.jpg 1024w, https://www.privacyidea.org/wp-content/uploads/2020/12/A-smartcard-in-a-notebook-300x205.jpg 300w, https://www.privacyidea.org/wp-content/uploads/2020/12/A-smartcard-in-a-notebook-768x524.jpg 768w, https://www.privacyidea.org/wp-content/uploads/2020/12/A-smartcard-in-a-notebook-1536x1048.jpg 1536w, https://www.privacyidea.org/wp-content/uploads/2020/12/A-smartcard-in-a-notebook-2048x1397.jpg 2048w" sizes="(max-width: 933px) 100vw, 933px" /></figure></div>



<p><em>Today we put privacyIDEA 3.5 under your Christmas tree. Unwrap it and you will find a lot of enhancements. One of the most important features is that version 3.5 does the first step to also support smartcard management. For high security  environments we drastically imrpoved the workflow of Four-Eyes-Tokens.</em></p>



<h2 class="wp-block-heading">Let&#8217;s do this togeather &#8211; Four-Eyes-Tokens</h2>



<p>Using the Four-Eyes-Tokens the administrator can define how many users from several different groups should come togeather when the account &#8211; the holder of the Four-Eyes-Token &#8211; wants to authenticate. This way you can define, that this account worthy of protection can only be used if e.g. two IT administrators and one member of the works council come togeather and use their own 2nd factors to authenticate.</p>



<p>The Four-Eyes-Token has been around for a while in privacyIDEA. But now we are using the <a href="https://www.privacyidea.org/privacyidea-3-4-released/">Multi</a><a href="https://www.privacyidea.org/privacyidea-3-4-released/" target="_blank" rel="noreferrer noopener">&#8211;</a><a href="https://www.privacyidea.org/privacyidea-3-4-released/">Challenge</a>, that was introduced in privacyIDEA 3.4, to heavily improve the workflow and authentication flow. It is totally transparent to our application plugins and the RADIUS protocol, so that it can be used e.g. with Citrix Netscaler.</p>



<figure class="wp-block-gallery columns-2 is-cropped wp-block-gallery-1 is-layout-flex wp-block-gallery-is-layout-flex"><ul class="blocks-gallery-grid"><li class="blocks-gallery-item"><figure><img decoding="async" width="854" height="451" src="https://www.privacyidea.org/wp-content/uploads/2020/12/4Augen-Citrix-01-1.png" alt="" data-id="2229" data-full-url="https://www.privacyidea.org/wp-content/uploads/2020/12/4Augen-Citrix-01-1.png" data-link="https://www.privacyidea.org/?attachment_id=2229" class="wp-image-2229" srcset="https://www.privacyidea.org/wp-content/uploads/2020/12/4Augen-Citrix-01-1.png 854w, https://www.privacyidea.org/wp-content/uploads/2020/12/4Augen-Citrix-01-1-300x158.png 300w, https://www.privacyidea.org/wp-content/uploads/2020/12/4Augen-Citrix-01-1-768x406.png 768w" sizes="(max-width: 854px) 100vw, 854px" /></figure></li><li class="blocks-gallery-item"><figure><img decoding="async" width="702" height="378" src="https://www.privacyidea.org/wp-content/uploads/2020/12/4Augen-Citrix-02.png" alt="" data-id="2228" data-link="https://www.privacyidea.org/?attachment_id=2228" class="wp-image-2228" srcset="https://www.privacyidea.org/wp-content/uploads/2020/12/4Augen-Citrix-02.png 702w, https://www.privacyidea.org/wp-content/uploads/2020/12/4Augen-Citrix-02-300x162.png 300w" sizes="(max-width: 702px) 100vw, 702px" /></figure></li></ul><figcaption class="blocks-gallery-caption">Several persons want to login as &#8220;administrator@highsecurity&#8221;. <br>So in the first step the first person uses his credentials and 2nd factor. Then in a 2nd step the second user is asked for his credentials and 2nd factor.</figcaption></figure>



<h2 class="wp-block-heading">Do not copy, rather sign! &#8211; PIV smartcards with privacyIDEA</h2>



<p>Smartcards are interesting devices, that have certain disadvantages in handling but also come with advantages and features, that allow for completely other use cases like offline authentication, decryption or document signing.</p>



<p>privacyIDEA was already capable of enrolling and manageing x509v3 user certificates. As a first step to better support smartcards, privacyIDEA 3.5 now can require that certificate requests are generated on a PIV smartcard. This is done by<br>using policies to force the presence of an attestation certificate during enrollment. The attestation certificate confirms, that actually the key pair was generated on a smartcard and there is no copy of the private key.</p>



<p>This was successfully done with the Yubikey 5 and a corresponding enrollment tool. We will continue working on imrpoving the privacyIDEAs smartcard capabilities.</p>



<h2 class="wp-block-heading">Make the admin&#8217;s life easier &#8211; serveral enhancements</h2>



<h4 class="wp-block-heading">Tokens</h4>



<p>The Push token gets a lot of feedback in the community. So we are continuously improving it. User certain conditions a smartphone device can renew its firebase token, that is used to communicate with Google&#8217;s firebase push service. The smartphone app can now contact the privacyIDEA server to update this firebase token.</p>



<p>The registration token is a long &#8220;registration code&#8221;, that can be used to authenticate once during enrollment processes. The admin can now configure a policy to define the length and contents of the registration code.</p>



<p>A Webauthn token <a rel="noreferrer noopener" href="https://www.w3.org/TR/webauthn/#sign-counter" target="_blank">should also provide a signature counter</a>, that is used to identify and avoid cloned tokens. However, not all cheap devices implement this. privacyIDEA now also allows to use Webauthn tokens without a signature counter on demand.</p>



<p>Hardware tokens come with a seed file. privacyIDEA can import a lot of different formats, also PSKC which is defined in RFC6030. The import of PSKC files now also verifies the MAC of the token secrets.</p>



<p>The questionnaire token can now ask more than one question during the authentication process.</p>



<h4 class="wp-block-heading">Event handlers and policies</h4>



<p>The policies may now contain additional extened conditions from the tokeninfo attributes. This can be any arbitrary  attribute, so that the admin could define policies, that e.g. allow the authentication at certain applications with a hardware token but not with a software token. </p>



<p>The Tokenhandler can choose the SMS Gateway Identifier or the SMTP Identifier when enrolling an SMS or respectively an Email token.</p>



<p>The Tokenhandler can now increase and decrease the fail counter and also set the Maxfail counter.</p>



<h4 class="wp-block-heading">The Web UI</h4>



<p>Several enhancements allow a smoother work experience for administrators and service desk users. The admin can define a policy to hide certain columns in the audit log. This way the service desk users only see this information, which they really need. Also, the audit log contains the start time, the end time and the duration of a request. This way it is easy to filter or search for long running requests to debug authentication problems. In the dashboard the usernames of the users with failed authentications are displayed with a short link to their user details. This helps the service desk to immidiately find failing users and offer quickers support.</p>



<div class="wp-block-image"><figure class="aligncenter size-large"><img loading="lazy" decoding="async" width="586" height="249" src="https://www.privacyidea.org/wp-content/uploads/2020/12/dashboard-failed-user.png" alt="" class="wp-image-2231" srcset="https://www.privacyidea.org/wp-content/uploads/2020/12/dashboard-failed-user.png 586w, https://www.privacyidea.org/wp-content/uploads/2020/12/dashboard-failed-user-300x127.png 300w" sizes="auto, (max-width: 586px) 100vw, 586px" /><figcaption>The sercice desk user can see the failed user&#8217;s details directly by clicking on the linked username.</figcaption></figure></div>



<p>The WebUI now supports the PIN change via multi-challenge response.</p>



<p>The conditions for event handlers and actions for policies have been redesigned to make them look the same and easily searchable.</p>



<h4 class="wp-block-heading">Managing privacyIDEA</h4>



<p>In certain setups you might have a testing environment, a staging environment and a production environment. Configuration changes are often first tested in the testing environment and then transferred to the staging and production environment.</p>



<p>The pi-manage script has a new sub command to export and import resolver configuration, that will help in such scenarios.</p>



<p>The full list of features, enhancements and fixes can be found in the <a href="https://github.com/privacyidea/privacyidea/blob/master/Changelog">Changelog</a>.</p>



<h2 class="wp-block-heading">Get privacyIDEA</h2>



<p>privacyIDEA is an enterprise grade, extremely flexible multi-factor authentication system, that can adapt to your needs and  that lets you automate a lot of tasks. Using privacyIDEA will increase your security. Migrating from other mult-factor<br>systems to privacyIDEA will ease your life. People have done this and dropped many well-known, but old and crusty authentication systems. Take a look at privacyIDEA and join the community.</p>



<p>It is freely available via the <a href="https://privacyidea.readthedocs.io/en/latest/installation/pip.html">Python package index</a> and via community repositories for <a href="https://privacyidea.readthedocs.io/en/latest/installation/ubuntu.html">Ubuntu LTS 16.04, 18.04 and 20.04</a>.</p>



<p>The company NetKnights provides an <a href="https://netknights.it/en/produkte/privacyidea/">Enterprise Edition</a> with Service Level Agreements and stable packages for Ubuntu LTS and Red Hat Enterprise Linux/CentOS.</p>



<p>If you want to stay tuned, join the <a rel="noreferrer noopener" href="https://community.privacyidea.org" target="_blank">community forum</a> or subscribe the <a rel="noreferrer noopener" href="https://netknights.it/en/newsletter/" target="_blank">NetKnights&#8217; newsletter</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
