Active
Project:
Two-factor Authentication (TFA)
Version:
2.x-dev
Component:
Documentation
Priority:
Normal
Category:
Task
Assigned:
Unassigned
Reporter:
Created:
29 Aug 2014 at 15:10 UTC
Updated:
4 Jan 2025 at 07:38 UTC
Jump to comment: Most recent
Comments
Comment #1
banviktor commentedIn the meantime #2329867: Prevent the re-use of TOTP codes got committed, so TOTP reuse is not possible.
However encouraging SSL is always a good thing (see #2548483: Option to require SSL connection to show Recovery codes, or insist on sending them through email instead) so we might still want to do this.
Thoughts?
Comment #2
cmlaraIn preparation for D7 EOL in a couple days moving this to 2.x branch.
While using SSL should be 'common knowledge' for anyone deploying MFA I could see room for it to be included somewhere in the documentation. Possibly under the Install Hardening section? (Maybe rename to "Deployment Hardening" to be more agnostic to setup itself?). Could also be a good option to create a "Security Considerations" as I could see us desiring to document the DB storage and multi-environment related concerns.