# Two-factor local login option

**URL:** https://meta.discourse.org/t/two-factor-local-login-option/12597
**Category:** Feature
**Created:** [10. Februar 2014 um 14:36 UTC](https://meta.discourse.org/t/two-factor-local-login-option/12597 "2014-02-10T14:36:56Z")
**Posts on this page:** 20
**Page:** 2

<div class="post-metadata">

### Author: ![siepkes](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/siepkes/32/122520_2.png) [@siepkes](https://meta.discourse.org/u/siepkes)
#### Post date: [24. März 2015 um 08:11 UTC](https://meta.discourse.org/t/two-factor-local-login-option/12597/21 "2015-03-24T08:11:35Z")

</div>

I originally posted this in the GitHub PR, sorry about that, should have posted it here. I have some thoughts and humble opinions 😉 on this and thought I’d share em:

Cool feature! We are currently using two factor authentication with Discourse and OpenAM (oauth2). One advantage of offloading the more complex authentication to an AM solution like OpenAM (or Gluu, or whatever AM solution you want to use) is that it allows for vastly more flexibility then Discourse probably ever will. So while I think its really cool what you’ve made I would just like to point out that it might be wise for the devs to think about how much security complexity they want to pull in to Discourse and where to draw the line and off-load it to other solutions.

---

<div class="post-metadata">

### Author: ![fantasticfears](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/fantasticfears/32/119608_2.png) [@fantasticfears](https://meta.discourse.org/u/fantasticfears)
#### Post date: [12. April 2015 um 09:11 UTC](https://meta.discourse.org/t/two-factor-local-login-option/12597/22 "2015-04-12T09:11:37Z")

</div>

Sorry for late response ☹

When reading about this feature request, I think the team want this in the core. So here it is. And you can still use the third party service without a doubt! It’s optional.

---

<div class="post-metadata">

### Author: ![Ryan\_Hammond](https://avatars.discourse-cdn.com/v4/letter/r/a87d85/32.png) [@Ryan\_Hammond](https://meta.discourse.org/u/Ryan_Hammond)
#### Post date: [16. September 2015 um 00:41 UTC](https://meta.discourse.org/t/two-factor-local-login-option/12597/23 "2015-09-16T00:41:20Z")

</div>

Jasper, I am an OpenAM noob. Could you please share the basics of how you implemented SSO for Discourse with OpenAM?

---

<div class="post-metadata">

### Author: ![Falco](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/falco/32/179432_2.png) [@Falco](https://meta.discourse.org/u/Falco)
#### Post date: [16. September 2015 um 03:59 UTC](https://meta.discourse.org/t/two-factor-local-login-option/12597/24 "2015-09-16T03:59:41Z")

</div>

I use openAM at work and we do authentication at reverse proxy level, using lua on nginx. To integrate with discourse was just a matter of creating one more nginx endpoint that responds to [discourse SSO](https://meta.discourse.org/t/13045?silent=true) requests, we used lua too, so everything openAM is handled at nginx.

---

<div class="post-metadata">

### Author: ![cregox](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/cregox/32/115904_2.png) [@cregox](https://meta.discourse.org/u/cregox)
#### Post date: [2. Dezember 2015 um 01:17 UTC](https://meta.discourse.org/t/two-factor-local-login-option/12597/25 "2015-12-02T01:17:07Z")

</div>

@Lee_Ars I fell here searching for another topic and [I’m not really interested in this one](https://meta.discourse.org/t/trying-to-secure-ssh-on-ubuntu-but-found-pam/36222), so I have honestly little clue what you’re talking about, but… Just wanted to thank you for mentioning `PAM` there. I enjoyed reading a few other offtopic bits here. 🙂

---

<div class="post-metadata">

### Author: ![Lee\_Ars](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/lee_ars/32/1597_2.png) [@Lee\_Ars](https://meta.discourse.org/u/Lee_Ars)
#### Post date: [3. Dezember 2015 um 01:04 UTC](https://meta.discourse.org/t/two-factor-local-login-option/12597/26 "2015-12-03T01:04:53Z")

</div>

Maybe time to bump the HAI GUYS CAN WE 2FA PLZ topic, @codinghorror??

---

<div class="post-metadata">

### Author: ![fantasticfears](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/fantasticfears/32/119608_2.png) [@fantasticfears](https://meta.discourse.org/u/fantasticfears)
#### Post date: [9. April 2016 um 17:36 UTC](https://meta.discourse.org/t/two-factor-local-login-option/12597/27 "2016-04-09T17:36:41Z")

</div>

As far as I know, it won’t get into the core but as a plugin.

The code was scrambled in this commit. I believe I didn’t think much about sso, invite and many more stuff though (based on the age of this commit).

[https://github.com/fantasticfears/discourse/commit/08cec58f5d37a92030fd712216cea96df02f8953](https://github.com/fantasticfears/discourse/commit/08cec58f5d37a92030fd712216cea96df02f8953)

---

<div class="post-metadata">

### Author: ![bek](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/bek/32/61660_2.png) [@bek](https://meta.discourse.org/u/bek)
#### Post date: [17. September 2016 um 21:32 UTC](https://meta.discourse.org/t/two-factor-local-login-option/12597/28 "2016-09-17T21:32:14Z")

</div>

Is there any update on this?

---

<div class="post-metadata">

### Author: ![Lee\_Ars](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/lee_ars/32/1597_2.png) [@Lee\_Ars](https://meta.discourse.org/u/Lee_Ars)
#### Post date: [20. November 2016 um 04:24 UTC](https://meta.discourse.org/t/two-factor-local-login-option/12597/29 "2016-11-20T04:24:01Z")

</div>

Since we’re nearing the end of the year I’ll give this thread my yearly “hey @sam we would love 2FA” bump 🙂 Duo, Yubi, or just plain ol’ TOTP—anything would be great.

---

<div class="post-metadata">

### Author: ![SGTGunner](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sgtgunner/32/121330_2.png) [@SGTGunner](https://meta.discourse.org/u/SGTGunner)
#### Post date: [25. Dezember 2016 um 04:47 UTC](https://meta.discourse.org/t/two-factor-local-login-option/12597/30 "2016-12-25T04:47:56Z")

</div>

Is there any chance that this is still being looked at?

I think it would be a great option to have. Security and especially 2FA is such an important feature!

Thanks in Advance.

---

<div class="post-metadata">

### Author: ![Falco](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/falco/32/179432_2.png) [@Falco](https://meta.discourse.org/u/Falco)
#### Post date: [25. Dezember 2016 um 16:04 UTC](https://meta.discourse.org/t/two-factor-local-login-option/12597/31 "2016-12-25T16:04:45Z")

</div>

Now it’s a good time to ask @codinghorror about this 😄

> <https://twitter.com/codinghorror/status/812400149938876416>

---

<div class="post-metadata">

### Author: ![SGTGunner](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sgtgunner/32/121330_2.png) [@SGTGunner](https://meta.discourse.org/u/SGTGunner)
#### Post date: [30. Dezember 2016 um 16:46 UTC](https://meta.discourse.org/t/two-factor-local-login-option/12597/32 "2016-12-30T16:46:28Z")

</div>

Let’s hope the @codinghorror likes it. I did find this code on how to integrate [https://github.com/TwoFactorAuth/ruby](https://github.com/TwoFactorAuth/ruby) which uses the U2F FIDO standard.

---

<div class="post-metadata">

### Author: ![Deukhoofd](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/deukhoofd/32/52342_2.png) [@Deukhoofd](https://meta.discourse.org/u/Deukhoofd)
#### Post date: [13. Januar 2017 um 02:17 UTC](https://meta.discourse.org/t/two-factor-local-login-option/12597/33 "2017-01-13T02:17:26Z")

</div>

Are there any updates on this? This is still a must have in security for any community, and it’s one of the things I’d love to offer my users.

---

<div class="post-metadata">

### Author: ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)
#### Post date: [13. Januar 2017 um 03:29 UTC](https://meta.discourse.org/t/two-factor-local-login-option/12597/34 "2017-01-13T03:29:09Z")

</div>

> [@Deukhoofd](#):
>
> This is still a must have in security for any community

Perhaps, and we totally love 2fa at Discourse, but none of our paying customers are pushing for it. Keep in mind, if you use Google, you get 2fa for free by the virtue of using Google.

---

<div class="post-metadata">

### Author: ![FlyingSwitzerland](https://avatars.discourse-cdn.com/v4/letter/f/96bed5/32.png) [@FlyingSwitzerland](https://meta.discourse.org/u/FlyingSwitzerland)
#### Post date: [28. Januar 2017 um 19:52 UTC](https://meta.discourse.org/t/two-factor-local-login-option/12597/35 "2017-01-28T19:52:13Z")

</div>

As a customer we think this feature is necessary… if it’s possible to think about it that will be awesome

---

<div class="post-metadata">

### Author: ![mrphs](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/mrphs/32/70153_2.png) [@mrphs](https://meta.discourse.org/u/mrphs)
#### Post date: [1. April 2017 um 23:52 UTC](https://meta.discourse.org/t/two-factor-local-login-option/12597/36 "2017-04-01T23:52:05Z")

</div>

> [@sam](#):
>
> we totally love 2fa at Discourse, but none of our paying customers are pushing for it. Keep in mind, if you use Google, you get 2fa for free by the virtue of using Google

should we start a campaign to help your paying customers see this thread? 😉

That reminds me… do you have a “tip jar” somewhere, where community can donate small amounts in $ or BTC?

---

<div class="post-metadata">

### Author: ![codinghorror](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/codinghorror/32/110067_2.png) [@codinghorror](https://meta.discourse.org/u/codinghorror)
#### Post date: [2. April 2017 um 05:25 UTC](https://meta.discourse.org/t/two-factor-local-login-option/12597/37 "2017-04-02T05:25:18Z")

</div>

Yes it is at [https://discourse.org/buy](https://discourse.org/buy) 🙂

---

<div class="post-metadata">

### Author: ![Noah751](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/noah751/32/82274_2.png) [@Noah751](https://meta.discourse.org/u/Noah751)
#### Post date: [15. August 2017 um 01:02 UTC](https://meta.discourse.org/t/two-factor-local-login-option/12597/40 "2017-08-15T01:02:12Z")

</div>

Hopefully, this will be implemented very soon, security is 100% very important too me, even a site setting “Require two factor authentication to enter admin panel” is a great idea. I’m with this idea! 🙂

---

<div class="post-metadata">

### Author: ![arun](https://avatars.discourse-cdn.com/v4/letter/a/ee7513/32.png) [@arun](https://meta.discourse.org/u/arun)
#### Post date: [13. Dezember 2017 um 08:11 UTC](https://meta.discourse.org/t/two-factor-local-login-option/12597/41 "2017-12-13T08:11:10Z")

</div>

Wondering what the progress has been on this idea. 🙂

---

<div class="post-metadata">

### Author: ![sam](https://sea3.discourse-cdn.com/meta/user_avatar/meta.discourse.org/sam/32/102149_2.png) [@sam](https://meta.discourse.org/u/sam)
#### Post date: [13. Dezember 2017 um 09:01 UTC](https://meta.discourse.org/t/two-factor-local-login-option/12597/42 "2017-12-13T09:01:29Z")

</div>

Will happen some time in 2018

[Previous page](https://meta.discourse.org/t/two-factor-local-login-option/12597.md?page=1)

[Next page](https://meta.discourse.org/t/two-factor-local-login-option/12597.md?page=3)
