Moderator
Jan Dembowski
(@jdembowski)
Forum Moderator and Brute Squad
I just want our Administrators to login with some sort of key fob, or as they were once known as dongles. That gives my age away !!!
Which ones are you looking for support? RSA SecurID or something else like HID? I’m asking because there may be a 2FA that you can use if you already have the infrastructure.
I am at the first stage of trying to get 2FA so have nothing installed. I don’t want to use Smart phones to generate the key. Everything I have read about talks of using Google or similar to generate the key. I just want a simple dongle to do the job. I understand the key is generated by passing the exact time through an algorithm to give the key which is automatically inserted. I have not found a WordPress plugin that works this way. A shame really, as the dongles are available that will do exactly what I want.
I would appreciate your help an hope you can point me in the right direction.
Regards
Pringle Stik (David)
Moderator
Jan Dembowski
(@jdembowski)
Forum Moderator and Brute Squad
I am at the first stage of trying to get 2FA so have nothing installed.
Ah. I was hoping you’d had an existing 2FA setup already that you’d like to take advantage off. For example, at work we use RSA SecurID tokens that display a time based number using a secret seed and has a RADIUS interface.
I don’t want to use Smart phones to generate the key.
That’s kind of a problem. The infrastructure to manage and maintain your own key fob (dongle) is prohibitively expensive. As someone who uses a 2FA dongle everyday I appreciate what you are trying to do. 😉
The best I can suggest is that you try this plugin search.
https://ww.wp.xz.cn/plugins/search.php?q=2fa
https://ww.wp.xz.cn/plugins/search.php?q=OTP
In the absence of having someway to add the second factor (a dongle or key fob) you may need to use a phone. For my personal site I use Google Authenticator and an app on my smartphone. It’s time based and does not require any network connectivity on my phone and it works well. My smartphone is the dongle for me.
But you’ve made it clear you do not want to go that route. The first search uses plugins that support SMS as a means of sending the user a code required to complete the loigin process.
The second search is for using one time passwords. It’s not a dongle but can partly fil that need. Personally I think the SMS option is better but your mileage may vary. 😉
The problem is my Mobile is very erratic where live and work. I can get Yubikeys locally no problem but I have only found two plugins that are supposed to work with them. When I dig deeper I find very few have uploaded the plugin and the last update is months or years away. Not exactly a five star recommendation. I have Wordfence but that only seems to work with telephones. I doubt I will get what I want and what I do finally get will have be a compromise not what I am about!
Thanks for you help
David