Admin

18 views
Skip to first unread message

Bengt Wällstedt

unread,
Jul 5, 2026, 7:25:45 PMJul 5
to SimpleSAMLphp
Hi! I would like to implement some kind of 2FA security to the Admin pages. I've been looking at the Yubikey and WebAuthn modules but I haven't figured out how ti use them. It would be om to use like Yubikeys as a single factor, or otherwise to add Yubikeys or fingerprint sensors etc as a 2nd factor together with the Admin password. Any ideas about that?

Peter Schober

unread,
Jul 6, 2026, 4:28:36 AMJul 6
to simple...@googlegroups.com
Bengt Wällstedt <bengt.w...@gmail.com> [2026-07-06 01:25 CEST]:
> Hi! I would like to implement some kind of 2FA security to the Admin pages.

Are you sure you need the admin pages at all?
There should be nothing there you'd need for operating
SimpleSAMLphp on a daily basis, AFAIR.

(I'm aware that's not answering your literal question.)

-peter

Bengt Wällstedt

unread,
Jul 9, 2026, 11:13:49 AMJul 9
to SimpleSAMLphp
Hi!
Thanks for your reply! I am aware that the admin pages are not critical for normal operation. However, they are useful at times. The OIDC client registry administration is one thing, also they provide a good overview over configured services and their properties. I think I would miss them if we were to shut them down but even though I'm not sure they are particularly sensitive for hacking I would rather have them protected with some kind of 2 factor auth.
Kind regards
Bengt 

Tim van Dijen

unread,
Jul 9, 2026, 11:19:11 AMJul 9
to SimpleSAMLphp
Hi Bengt,

The 'admin'-authsource is just like any other authsource. It defaults to 'core:AdminPassword', but you can use any authsource here.
You could use `saml:SP` and make the admin-module a service provider and deal with MFA just like you do for any other SP's you have.
The possibilities are endless!

- Tim
Op donderdag 9 juli 2026 om 17:13:49 UTC+2 schreef bengt.w...@gmail.com:
Reply all
Reply to author
Forward
0 new messages