6.0.0-beta1
7/5/25

[#12301] Secondary authentication
Summary Secondary authentication
Queue Horde Base
Queue Version Git master
Type Enhancement
State Rejected
Priority 1. Low
Owners
Requester lameventanas (at) gmail (dot) com
Created 06/05/2013 (4413 days ago)
Due
Updated 01/28/2016 (3446 days ago)
Assigned
Resolved 01/28/2016 (3446 days ago)
Milestone
Patch No

History
01/28/2016 03:16:23 PM Jan Schneider State ⇒ Rejected
 
08/30/2013 05:08:53 AM lameventanas (at) gmail (dot) com Comment #6
New Attachment: horde-auth.pdf Download
Reply to this comment

[Show Quoted Text - 20 lines]
Possible solution: for each app-specific password Horde stores the 
backend password (eg: LDAP, IMAP) in an encrypted form.  The 
app-specific password is used as the encryption key.  For safety 
reasons, the app-specific password is not stored, only a hash of it.

There might be other ways to implement it safely, this is just an idea.

Please see the attachment.




08/07/2013 04:38:35 AM Michael Rubinsky Comment #5 Reply to this comment

[Show Quoted Text - 14 lines]
How would this work? ActiveSync needs authenticated access to Horde 
and the applications (not to mention access to the IMAP server through 
IMP). Using a different password for each application, or even just 
for ActiveSync access would prevent authentication to at least some of 
the data that is needed.
08/07/2013 01:33:50 AM lameventanas (at) gmail (dot) com Comment #4 Reply to this comment
Are you requesting two-factor authentication actually?
What I am requesting is simpler, is "Application-specific passwords".

Please see this:
https://support.google.com/accounts/answer/185833

And a video explaining it:
http://www.youtube.com/watch?v=zMabEyrtPRg&t=2m13s

It is possible to implement this independently of Horde (eg: for email 
it could be done in the imap server), but we need support for SyncML 
and Activesync, and also a Horde module for the password management.
08/05/2013 09:23:02 PM Jan Schneider Comment #3
State ⇒ Feedback
Reply to this comment
Are you requesting two-factor authentication actually?
07/23/2013 07:17:06 PM Michael Slusarz Comment #2 Reply to this comment
Except we already have this.  See, e.g., IMP/Gollem - they can use 
authentication different that Horde's.  How is what you are asking for 
different than this?
07/23/2013 07:09:30 PM Ralf Lang Summary ⇒ Secondary authentication
 
06/05/2013 01:01:24 AM lameventanas (at) gmail (dot) com Comment #1
Priority ⇒ 1. Low
Type ⇒ Enhancement
Summary ⇒ Secondary authentcation
Queue ⇒ Horde Base
Milestone ⇒
Patch ⇒ No
State ⇒ New
Reply to this comment
It would be great if we could use a secondary authentication system 
for different parts of Horde.

For example, I could have my normal authentication to use every 
function in Horde, IMP, etc. And then a secondary one that only works 
to synchronize my cellphone over SyncML, or possibly for other things.

That way if my secondary password is compromised the damage is limited.
I think google has a similar system.

Saved Queries