Difference between revisions of "DuoSecurity"

From WHMCS Documentation

Line 1: Line 1:
 
[http://docs.whmcs.com/Two-Factor_Authentication < Back to Two-Factor Authentication]
 
[http://docs.whmcs.com/Two-Factor_Authentication < Back to Two-Factor Authentication]
  
<div class="docs-alert-info"><i class="fa fa-info-circle"></i> This page describes a feature available in version 7.0 and above</div>
+
==What is Duo Security==
  
==What is DuoSecurity==
+
Duo Security allows your users to secure their logins and transactions using their smartphones.
Duo Security enables your users to secure their logins and transactions using their smartphones. The Duo Mobile smartphone application is free and available on all major smartphone platforms, and lets users easily generate passcodes without the cost and hassle of hardware tokens. iPhone, Android, BlackBerry, and Windows Phone users can use Duo Push which “pushes” login or transaction details to the phone, allowing for immediate, one-tap approval.
 
  
Older devices like cellphones and landlines are also fully supported. Duo can send passcodes via text message, or place a phone call - users just press a button on their keypad to authenticate.
+
The Duo Mobile app is free and available on all major smartphone platforms, and lets users easily generate passcodes without the cost and hassle of hardware tokens.
DuoSecurity will prompt you for a phone number and option to receive a text or phone call. After the text or phone call is received, input the authentication code to proceed.
 
  
A second optional page at initial login will prompt to download the DuoSecurity mobile application which performs push notifications allowing you to restrict or allow access under your user from your phone.  
+
iPhone, Android, BlackBerry, and Windows Phone users can use Duo Push which “pushes” login or transaction details to the phone, allowing for immediate, one-tap approval.
 +
 
 +
==Why Duo Security?==
 +
 
 +
Duo works by adding a second identity verification, by requiring two factors: First, your password (the thing you know) then something unique (that you have) like your phone.
 +
 
 +
By enabling Duo Security, you add another layer of security that prevents attackers from being able to login using only your password.
  
 
<div class="docs-alert-info">
 
<div class="docs-alert-info">
You will require your own Duo Security account. A 'Duo MFA' or higher level account is required to access the necessary API: [http://go.whmcs.com/918/duo-security-signup Signup Here].
+
You will require your own Duo Security account. A 'Duo MFA' or higher level account is required to access the Duo API: [https://go.whmcs.com/918/duo-security-signup Click here to signup].
 
</div>
 
</div>
  
==Configuration==
+
==Configuring Duo Security==
 
[[File:Duo1.png|thumb|Protect an Application]][[File:Duo2.png|thumb|Protect Auth API]]
 
[[File:Duo1.png|thumb|Protect an Application]][[File:Duo2.png|thumb|Protect Auth API]]
First Login to your account on the [https://admin.duosecurity.com/ DuoSecurity website]:
+
 
 +
To configure Duo Security in WHMCS, follow the steps below:
 +
 
 +
# Begin by logging in to your account at [https://admin.duosecurity.com/ Duo Security]
 
# Click ''Applications'' in the left sidebar
 
# Click ''Applications'' in the left sidebar
 
# Click ''Protect an Application''
 
# Click ''Protect an Application''
Line 32: Line 39:
 
# Navigate to '''Setup > Staff Management > Two-Factor Authentication'''
 
# Navigate to '''Setup > Staff Management > Two-Factor Authentication'''
 
# Click the "Activate" button next to Duo Security
 
# Click the "Activate" button next to Duo Security
# To enable Duo Security as a two-factor option for staff and/or clients, tick the corresponding ''Enable for'' checkboxes.
+
# To enable Duo Security as a two-factor option for staff, tick the checkbox labelled '''Enable for Staff'''
# Enter the Integration Key, Secret Key and API Hostname you noted down earlier into the corresponding fields.
+
# To enable Duo Security for customers, tick the checkbox labelled '''Enable for Clients'''
 +
# Enter the Integration Key, Secret Key and API Hostname you noted down previously where requested
 
# Click ''Save Changes''
 
# Click ''Save Changes''
  
Once a member of staff or client has [[Security_Modules#Enable_for_Clients|activated Two Factor Authentication]] on their account, upon the next login they will be prompted to complete the DuoSecurity registration process.
+
==Enabling Duo Security as an Admin User==
 +
 
 +
To enable Duo Security for your admin user account, begin by configuring Duo Security as instructed above.
 +
 
 +
Once complete, navigate to the My Account page within the WHMCS admin area and from there you will see an option to enable Two-Factor Authentication.
 +
 
 +
You will then be guided through the setup process.
 +
 
 +
On all future login attempts, you will be asked to complete the Two-Factor Authentication process.
 +
 
 +
==Enabling Duo Security as a Client==
 +
 
 +
Login to the WHMCS client area and then navigate to My Account > Security Settings.
 +
 
 +
From there, click the Enable Two-Factor Authentication button.
 +
 
 +
You will then be guided through the setup process.
 +
 
 +
On all future login attempts, you will be asked to complete the Two-Factor Authentication process.
  
 
==Troubleshooting==
 
==Troubleshooting==

Revision as of 18:18, 15 December 2017

< Back to Two-Factor Authentication

What is Duo Security

Duo Security allows your users to secure their logins and transactions using their smartphones.

The Duo Mobile app is free and available on all major smartphone platforms, and lets users easily generate passcodes without the cost and hassle of hardware tokens.

iPhone, Android, BlackBerry, and Windows Phone users can use Duo Push which “pushes” login or transaction details to the phone, allowing for immediate, one-tap approval.

Why Duo Security?

Duo works by adding a second identity verification, by requiring two factors: First, your password (the thing you know) then something unique (that you have) like your phone.

By enabling Duo Security, you add another layer of security that prevents attackers from being able to login using only your password.

You will require your own Duo Security account. A 'Duo MFA' or higher level account is required to access the Duo API: Click here to signup.

Configuring Duo Security

Protect an Application
Protect Auth API

To configure Duo Security in WHMCS, follow the steps below:

  1. Begin by logging in to your account at Duo Security
  2. Click Applications in the left sidebar
  3. Click Protect an Application
  4. Locate the Auth API option
    • If you are missing this option from your Duo account, you will need to contact Duo to have them activate this for your account
  5. Beneath it click Protect this Application
  6. Take note of following values:
  • Integration Key
  • Secret Key
  • API hostname

Now login to your WHMCS Admin area as a Full Administrator user:

Complete configuration in WHMCS
  1. Navigate to Setup > Staff Management > Two-Factor Authentication
  2. Click the "Activate" button next to Duo Security
  3. To enable Duo Security as a two-factor option for staff, tick the checkbox labelled Enable for Staff
  4. To enable Duo Security for customers, tick the checkbox labelled Enable for Clients
  5. Enter the Integration Key, Secret Key and API Hostname you noted down previously where requested
  6. Click Save Changes

Enabling Duo Security as an Admin User

To enable Duo Security for your admin user account, begin by configuring Duo Security as instructed above.

Once complete, navigate to the My Account page within the WHMCS admin area and from there you will see an option to enable Two-Factor Authentication.

You will then be guided through the setup process.

On all future login attempts, you will be asked to complete the Two-Factor Authentication process.

Enabling Duo Security as a Client

Login to the WHMCS client area and then navigate to My Account > Security Settings.

From there, click the Enable Two-Factor Authentication button.

You will then be guided through the setup process.

On all future login attempts, you will be asked to complete the Two-Factor Authentication process.

Troubleshooting

The second factor you supplied was incorrect. Please try again

Seeing this error when activating the DuoSecurity method for the first time means that the code being entered does not match that which DuoSecurity expects. This is caused by the time on your server not matching DuoSecurity's clocks

You can see the time in the top-right corner of your WHMCS admin area, it's taken directly from your server's PHP configuration. So you must ensure the server time is synced exactly with UTC. For example if the server time is 00:01 and the time at DuoSecurity is 00:00 you will see this error. Syncing the server with NTP to ensure the time is exactly right will resolve this.

Different time-zones are taken into account, so time-zone differences won't cause a problem.