goauthentik / goauthentik/authentik

Require 2FA for non bind LDAP accounts

Open
#7,780 1 comment 0 reactions 0 assignees View on GitHub
question
Dominant language
Python
Stars
25.6k
Forks
2k
Avg merge
1d 2h
Merged PRs (30d)
651

Description

When creating a LDAP flow you have to auth with a bind account for LDAP querying which is fine and 2FA wouldn't be wanted here, but how do I force 2FA for the other accounts?

Contributor guide

Open the contributing guide

Research direction

Start by tracing the LDAP flow and how it distinguishes the bind account from other accounts, then inspect the existing 2FA enforcement configuration. The issue is done when the supported configuration or behavior for requiring 2FA on non-bind LDAP accounts is defined and verified.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
authentication, security
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.