Replies: 7 comments 9 replies
-
|
@yordis It'd be great to have the "Magic link" authentication method included in Keycloak as it'd be also suitable for 2FA. IMHO, it's a step forward and it can be also useful for adaptive MFA. It's very similar to the Keycloak reset credential approach, where the email is sent to the user with a token, so there might be only a few custom changes in order to accomplish the goal. It can be also very useful with the Trusted devices feature in the future as it could be used as the complete passwordless approach. @mposolda WDYT? |
Beta Was this translation helpful? Give feedback.
-
|
Please check code given in below link. You can use keycloak for OTP validation as primary login. Many portal want either user can login with username/password or can do login by entering registered mobile number and enter received OTP on portal to login. Valid token needs to be generated by calling keycloak API. This plugin serve the purpose of both user can login with either password or OTP. OOTB keycloak does not provide this feature, instead it provide 2F OTP authenticator with well-known OTP application. |
Beta Was this translation helpful? Give feedback.
-
|
Hi, I would like to have an OTP sent by email, as a second auth factor, so if I understand, Also, please note that the various links in the answers are currently broken... Regards |
Beta Was this translation helpful? Give feedback.
-
|
Hi, Just to let you know that phasetwo did an extension for it. You can have a look to the github repo here. If you need more info or details, I think @xgp can give you some. Best regards, |
Beta Was this translation helpful? Give feedback.
-
|
Hi, @MGLL thank you for the link, I already know that extension, but its license does not permit its use :( https://github.com/p2-inc/keycloak-magic-link/blob/main/COPYING So it seems that we are currently missing a true open source plugin for it. Regards |
Beta Was this translation helpful? Give feedback.
-
|
Hi, Using email as 2FA is really a bad idea security wise. It's not really a second factor. If user email got compromised, the attacher can reset the password using the email, and send the OTP/magic link to the email and gain full access to the account. NIST recommends against it. |
Beta Was this translation helpful? Give feedback.
-
Magic Link Passwordless AuthenticationIt seems the discussion got sidetracked by focusing on "email" and "SMS" for MFA, which serve a different use case than magic links. Mabartos' suggestion seems to be on the right track, though it hasn't been implemented yet. If you're interested in this feature, feel free to share your use case here and upvote it by adding a β¬οΈ to the discussionβs description. SMS and Email for MFAThis question has been asked several times before. You can find previous discussions by searching for βsmsβ or βemailβ in the GitHub search bar of the Keycloak repository [3][4]. Currently, there is no official support for using email or phone numbers for authentication in Keycloak. Therefore, any issues you encounter with third-party solutions should be reported in their respective repositories, not here. If you're interested in this feature, feel free to share your use case here [5], and upvote it by adding a β¬οΈ to the discussionβs description after reading this answer carefully [6]. [1] https://docs.github.com/en/issues/tracking-your-work-with-issues/administering-issues/closing-an-issue |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
Description
Jira Ticket: https://issues.redhat.com/browse/KEYCLOAK-17578
As an admin user,
I would like to add passwordless authentication to my authentication and registration. Such authentication will send a magic link and/or code to an email and/or SMS that I can use to authenticate
Reference:
Discussion
No response
Motivation
No response
Details
No response
Beta Was this translation helpful? Give feedback.
All reactions