On Tue, Feb 8, 2022 at 11:16 AM Alejandro Hernandez <a...@safedataserver.com>
wrote:

> I understand that the 1) was addressed on version 1.4, now you are able to
> turn on TOTP just for some users, not all of them
>
I don't think this is correct -- the TOTP changes listed for 1.4.0 are:


   - Allow for clearing TOTP Data in admin interface (GUACAMOLE-770
   <https://issues.apache.org/jira/browse/GUACAMOLE-770>)
   - User profile information cleared after TOTP enrollment (GUACAMOLE-1199
   <https://issues.apache.org/jira/browse/GUACAMOLE-1199>)
   - Automatically focus TOTP field (GUACAMOLE-1397
   <https://issues.apache.org/jira/browse/GUACAMOLE-1397>)


In 1.4.0, there are now options to clear the TOTP secret and mark it
unconfirmed (does not change the TOTP seed, but does present the user with
the QR code / TOTP seed again and require them to re-confirm it.)

[image: image.png]



> El 2022-02-04 08:31, Don Eugene Paul Viado escribió:
>
> Hello,
>
> Just wanted to ask if the below function is already possible or any
> workaround
>
> 1.) Mixing 2FA and Password only users - Currently, I have used the totp
> plugin but this seems to force all users to enroll token on the device.  Is
> it possible to configure some user to not be presented with 2FA challenge
> and only use their passwords
> 2.) Sharing profile - Very useful feature but i have concern with security
> as sharing the URL link goes to some unsecure method (chat, email) which
> will can be seen by someone else.  Is it possible to password protect it so
> the link can be passed insecurely and the password to some other means
>
> Thanks in advance.
>
>

-- 
Jonathan Hankins

Homewood City Schools

W: 205-877-4548

-- 
This e-mail is intended only for the recipient and may contain confidential 
or proprietary information. If you are not the intended recipient, the 
review, distribution, duplication or retention of this message and its 
attachments are prohibited. Please notify the sender of this error 
immediately by reply e-mail, and permanently delete this message and its 
attachments in any form in which they may have been preserved.

Reply via email to