Two-Factor Authentication

Two-Factor Authentication
M2

by XTENTO
Technology Partner General
TOTAL:
$89.00
Compatible With: Community 2.0, 2.1, 2.2 Enterprise 2.0, 2.1, 2.2

Tech Specifications

Seller:
Current Version:
2.1.3
Type:
Stable Build
Updated:
25 August, 2017
Categories:
Extensions, Payments & Security
License Type:

Overview

Protect your Magento backend against unauthorized logins and fraudsters today!

Other Extensions by XTENTO

Overview

Back to top

Protect your Magento backend against unauthorized logins and fraudsters today! Because passwords just aren't enough! Fearing someone could log into your Magento store to download all your orders, customers and other sensitive data? Fearing hackers and the consequences after getting hacked? Fear no more!

Using the Two-Factor Authentication extension by XTENTO, additional security information will be required when logging into the Magento backend. Besides the username and the password, a so called security code (see screenshot below) will be required to log in. The security code gets generated by your smartphone (the secondfactor). Each security code can be used once only and is valid for 30 seconds only. Just turn on your smartphone - open the Authenticator application - and you'll immediately see the security code required to log in, valid for the next 30 seconds only. It's really easy, but the increase in security is immense.

As long as you've got your phone, this will ensure only YOU are able to login, and nobody else. No other person is able to generate the security code as it's generated using a unique secret key only known to your phone. You can't log in if you don't have the security code. You can't log in if you don't have the password. You always need the password and the security code to log in. This makes it almost impossible for hackers to log into your Magento backend.

Setting up Two-Factor Authentication for an adminstrator in Magento is easy: Just go to the Users section in the Magento backend, click Create secret key and scan the barcode using the Authenticator application. That's it! Your account is now protected against unauthorized logins.

Get the Two-Factor Authentication extension now to protect against today's threats without the hassle and cost of yesterday's technology.

More Information

This extension is compatible with every iPhone, iPad, iPod touch, Android and BlackBerry smartphone that supports Google Authenticator. The extension uses the free open-source Google Authenticator application to generate the security code required to log in.

Before your purchase, please make sure your device is able to run the Authenticator application.

  • Android: Open the Android Market and search for Google Authenticator
  • iPhone/iPad/iTouch: Visit the App Store and search for Google Authenticator
  • BlackBerry: Visit http://m.google.com/authenticator on your BlackBerry

Additional Information

The secret key will only be saved on your smartphone. Neither XTENTO nor Google will be able to recover it. The magic all happens on your device.

If you ever lose your smartphone, be sure to create a new key in the Two-Factor Authentication section under 'Users' in Magento so no one is able to log in using your smartphone.

This extension does not guarantee a 100% protection against hackers. If someone hacks your FTP server, they will be able to disable the security code login, but if that ever happens, they'd be able to download your database anyways without Magento backend access.

Questions?

If you have any questions regarding this extension, please do not hesitate to contact us at info@xtento.com. We'll be happy to help!

 

Release Notes

Back to top

2.1.3:

  • Compatible with CE: 2.0 2.1 2.2
  • Compatible with EE: 2.0 2.1 2.2
  • Stability: Stable Build
  • Description:

    ===== 2.1.3 =====
    + Compatibility with Magento 2.2 established

2.1.2:

  • Compatible with CE: 2.0 2.1
  • Compatible with EE: 2.0 2.1
  • Stability: Stable Build
  • Description:

    Xtento_TwoFactorAuth

    -------------
    CHANGELOG
    -------------

    ===== 2.0.0 =====
    * Initial stable M2 release

    ===== 2.0.1 =====
    * Compatibility with Magento 2.0.2
    * Several code optimizations, code cleanup
    * Updated Xtento_XtCore

    ===== 2.0.2 =====
    * Updated Xtento_XtCore to 2.0.3

    ===== 2.0.3 =====
    * Fixed bug that could lead to TFA can't be disabled anymore for an user after enabling it
    * Compatibility with Magento 2.1.0 established

    ===== 2.0.4 =====
    * Bugfix release

    ===== 2.0.5 =====
    * Updated composer.json to require XTENTO "XtCore" base module

    ===== 2.0.6 =====
    * Fixed error message "Please enter your security code" that was shown after editing an admin user

    ===== 2.0.7 ======
    * Fixed bug after saving user role

    ===== 2.0.8 ======
    * Added ability to change password at "My Account" without TFA prompt

    ===== 2.0.9 =====
    * Fixed composer.json / PHP version requirement now according to Magento 2 requirements

    ===== 2.1.0 =====
    * Fixed IP whitelisting for NginX SSL offloading into Varnish into NginX as PHP-FPM loadbalancer. The resulting IP was , 127.0.0.1

    ===== 2.1.1 =====
    * Updated Xtento_XtCore to version 2.0.7 ("Added warning in module configuration at System > Configuration if module output is disabled via "Disable Module Output" at System > Configuration > Advanced > Advanced")

    ===== 2.1.2 =====
    * Updated Xtento_XtCore to version 2.0.8

2.1.0:

  • Compatible with CE: 2.0 2.1
  • Compatible with EE: 2.0 2.1
  • Stability: Stable Build
  • Description:

    Xtento_TwoFactorAuth

    -------------
    CHANGELOG
    -------------

    ===== 2.0.0 =====
    * Initial stable M2 release

    ===== 2.0.1 =====
    * Compatibility with Magento 2.0.2
    * Several code optimizations, code cleanup
    * Updated Xtento_XtCore

    ===== 2.0.2 =====
    * Updated Xtento_XtCore to 2.0.3

    ===== 2.0.3 =====
    * Fixed bug that could lead to TFA can't be disabled anymore for an user after enabling it
    * Compatibility with Magento 2.1.0 established

    ===== 2.0.4 =====
    * Bugfix release

    ===== 2.0.5 =====
    * Updated composer.json to require XTENTO "XtCore" base module

    ===== 2.0.6 =====
    * Fixed error message "Please enter your security code" that was shown after editing an admin user

    ===== 2.0.7 ======
    * Fixed bug after saving user role

    ===== 2.0.8 ======
    * Added ability to change password at "My Account" without TFA prompt

    ===== 2.0.9 =====
    * Fixed composer.json / PHP version requirement now according to Magento 2 requirements

    ===== 2.1.0 =====
    * Fixed IP whitelisting for NginX SSL offloading into Varnish into NginX as PHP-FPM loadbalancer. The resulting IP was , 127.0.0.1

2.0.3:

  • Compatible with CE: 2.0 2.1
  • Compatible with EE: 2.0 2.1
  • Stability: Stable Build
  • Description:

    Xtento_TwoFactorAuth

    -------------
    CHANGELOG
    -------------

    ===== 2.0.0 =====
    * Initial stable M2 release

    ===== 2.0.1 =====
    * Compatibility with Magento 2.0.2
    * Several code optimizations, code cleanup
    * Updated Xtento_XtCore

    ===== 2.0.2 =====
    * Updated Xtento_XtCore to 2.0.3

    ===== 2.0.3 =====
    * Fixed bug that could lead to TFA can't be disabled anymore for an user after enabling it
    * Compatibility with Magento 2.1.0 established

Support

Back to top
The best place to start if you need help with a specific extension is to contact the developer. All Magento developers have both a contact email and a support email listed.

Q & A

Back to top

Reviews

Back to top