6.0.0-RC7
6/21/26

[#12301] Secondary authentication
Summary Secondary authentication
Queue Horde Base
Queue Version Git master
Type Enhancement
State Rejected
Priority 1. Low
Owners
Requester lameventanas (at) gmail (dot) com
Created 6/5/13 (4764 days ago)
Due
Updated 1/28/16 (3797 days ago)
Assigned
Resolved 1/28/16 (3797 days ago)
Milestone
Patch No

History
233 Jan Schneider State ⇒ Rejected
 
535 lameventanas (at) gmail (dot) com Comment #6
New Attachment: horde-auth.pdf Download
Reply to this comment

[Show Quoted Text - 20 lines]
Possible solution: for each app-specific password Horde stores the 
backend password (eg: LDAP, IMAP) in an encrypted form.  The 
app-specific password is used as the encryption key.  For safety 
reasons, the app-specific password is not stored, only a hash of it.

There might be other ways to implement it safely, this is just an idea.

Please see the attachment.




354 Michael Rubinsky Comment #5 Reply to this comment

[Show Quoted Text - 14 lines]
How would this work? ActiveSync needs authenticated access to Horde 
and the applications (not to mention access to the IMAP server through 
IMP). Using a different password for each application, or even just 
for ActiveSync access would prevent authentication to at least some of 
the data that is needed.
501 lameventanas (at) gmail (dot) com Comment #4 Reply to this comment
Are you requesting two-factor authentication actually?
What I am requesting is simpler, is "Application-specific passwords".

Please see this:
https://support.google.com/accounts/answer/185833

And a video explaining it:
http://www.youtube.com/watch?v=zMabEyrtPRg&t=2m13s

It is possible to implement this independently of Horde (eg: for email 
it could be done in the imap server), but we need support for SyncML 
and Activesync, and also a Horde module for the password management.
29 Jan Schneider Comment #3
State ⇒ Feedback
Reply to this comment
Are you requesting two-factor authentication actually?
67 Michael Slusarz Comment #2 Reply to this comment
Except we already have this.  See, e.g., IMP/Gollem - they can use 
authentication different that Horde's.  How is what you are asking for 
different than this?
307 rlang Summary ⇒ Secondary authentication
 
241 lameventanas (at) gmail (dot) com Comment #1
Priority ⇒ 1. Low
Type ⇒ Enhancement
Summary ⇒ Secondary authentcation
Queue ⇒ Horde Base
Milestone ⇒
Patch ⇒ No
State ⇒ New
Reply to this comment
It would be great if we could use a secondary authentication system 
for different parts of Horde.

For example, I could have my normal authentication to use every 
function in Horde, IMP, etc. And then a secondary one that only works 
to synchronize my cellphone over SyncML, or possibly for other things.

That way if my secondary password is compromised the damage is limited.
I think google has a similar system.

Saved Queries