Proposed Implementation for Two-Factor Authentication

Dear colleagues, Firstly, I would like to thank all who provided feedback on our authentication proposal for RIPE NCC Access. Many responded to the request for feedback, both publicly and privately, which is very encouraging to see. Based on your input, and the fact that this functionality is very rarely used, we would like to propose the following: 1. Discontinue X.509 identity certificate login from 1 February 2014 - All users who currently have a certificate will be contacted individually - Users will only use their RIPE NCC Access username and password to log in from 1 February 2014 - Note: a lost password can be recovered at https://access.ripe.net/forgot-password 2. Build an implementation for two-factor authentication for RIPE NCC Access, supporting at least: - HMAC-Based One-Time Password (HOTP) - Time-Based One-Time Password (TOTP) We would like to plan the development effort and scheduling before the end of the year and inform you about our roadmap once the project plan is in place. Please let us know if you have any comments or questions. Kind regards, Alex Band Product Manager RIPE NCC

Hello Alex, On 12/11/2013 12:51 PM, Alex Band wrote:
2. Build an implementation for two-factor authentication for RIPE NCC Access, supporting at least: - HMAC-Based One-Time Password (HOTP) - Time-Based One-Time Password (TOTP)
Good idea, I completely agree. I would like to suggest you to investigate also the possiblity of a 2 layer access. For example, at this point I find it quite annoying that the the authentication times out after an hour (?) - especially when playing with low-impact stuff like RIPE Atlas. So requiring an OTP once an hour will be very inconvenient. A possible way: keep username/password for 'simple' services (ideally with a longer timeout), ask additionally for the OTP only when a more sensitive service is accessed (like lirportal). Best regards, Gilles -- Fondation RESTENA - DNS-LU 6, rue Coudenhove-Kalergi L-1359 Luxembourg tel: (+352) 424409 fax: (+352) 422473
participants (2)
-
Alex Band
-
Gilles Massen