Hi,
I have a question to the state of development/support for 2FA in SOGo.
As far as I have read the current way to go is:
OIDC support for the Webinterface, username/password for the DAV
endpoints, username/password at IMAP.
Did anyone test OAUTH2 support for Thunderbird? (it would be possible to
use passwordless connections from SOGo to IMAP (network level auth) and
use OAUTH2 on the public interface of an IMAP server.
* https://github.com/ttaeschn/Thunderbird-OAuth2-Provider-Plugin
* https://github.com/sonroyaalmerol/xoauth-thunderbird
These two addons where referenced in the Mozilla discussion and could be
used for that.
What would be absolutely lovely where application passwords / accounts
that Users generate by themself for the DAV endpoints.. even better
would be a 2FA secured endpoint that the TB extension calls to create
these for itself. Which would not negate the need for this in the
webinterface (for e.g. DAVx5 on Android..).
Is there a roadmap for plans? Is there even a need? Or am I in a
dinosaur organization and everybody else uses Webif only?
Thanks,
--
Rainer Ruprechtsberger
Volkshilfe Oberösterreich
IT
4020 Linz, Glimpfingerstrasse 48
Volkshilfe. Wir sind für die Menschen da.