Project

General

Profile

Actions

Feature #12546

open

Add 2FA Support to pfSense Plus Local Database Authentication

Added by Kris Phillips about 1 year ago. Updated 7 months ago.

Status:
New
Priority:
Normal
Assignee:
-
Category:
Authentication
Target version:
-
Start date:
Due date:
% Done:

0%

Estimated time:
Release Notes:
Default

Description

To eliminate the reliance on unsupported packages like freeRADIUS for making this work, we should add the capability to the built-in user database in pfSense for time-based tokens. This could be "bolted on" to the end of passwords similar to how other options accomplish this for OpenVPN or IPSec VPNs, but we may be able to add a field to the webConfigurator login for 2FA.

Actions #1

Updated by Eyvind Baadnes about 1 year ago

Yes please!

Actions #2

Updated by Michael Pace 9 months ago

Hello,

This would be hugely helpful. Insurance companies are starting to require we implement 2FA across the board. Having it natively in pfSense would save a great deal of frustration.

Actions #3

Updated by Kris Phillips 7 months ago

Further expounding on this, it appears that Viscosity has native capability to add prompts in the client config.

auth-user-pass
static-challenge "Please provide your One-Time Passcode" 0

This can be "merged" into the password field with a bit of finagling and scripting. May be a way to add a backend for this in pfSense.

Actions

Also available in: Atom PDF