Jump to content

2 Factor Autnentication for Sub Accounts


Recommended Posts

Enforcing 2FA finally... and it seems like all customers who have subaccounts are having issues with 2FA. From testing, it appears that 2FA is tied to the WHMCS account, not the email address used to login,  so if a developer enables 2FA, their client (our client) is also placed under 2FA, but the developer has the code (weird??)

 

Conversely, if a client enables 2FA, the developer / subaccount is automatically locked out. 

Why do WHMCS accounts share 2FA for the entire account instead of being user based? 

How can this be fixed ASAP as this is a pretty high security problem. It forces providers to either enforce 2FA or not. And that causes a big glaring security hole. 

Link to comment
Share on other sites

  • 2 weeks later...

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use & Guidelines and understand your posts will initially be pre-moderated