Drecca Posted May 30, 2020 Share Posted May 30, 2020 Enforcing 2FA finally... and it seems like all customers who have subaccounts are having issues with 2FA. From testing, it appears that 2FA is tied to the WHMCS account, not the email address used to login, so if a developer enables 2FA, their client (our client) is also placed under 2FA, but the developer has the code (weird??) Conversely, if a client enables 2FA, the developer / subaccount is automatically locked out. Why do WHMCS accounts share 2FA for the entire account instead of being user based? How can this be fixed ASAP as this is a pretty high security problem. It forces providers to either enforce 2FA or not. And that causes a big glaring security hole. 0 Quote Link to comment Share on other sites More sharing options...
wsa Posted June 8, 2020 Share Posted June 8, 2020 You can look at https://requests.whmcs.com/topic/two-factor-authentication-for-sub-account 0 Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.