Disable username / password authentication for web interface (not admin)

Status
Not open for further replies.

Wills

Free User
Joined
Feb 22, 2019
Messages
12
Reaction score
5
We have google authentication enabled for all our users, and as such I'd like to disable the unused username and password authentication for our web interface (found at https://server.domain:5001/webclient/#/login) in order to improve our security posture. Is this possible? If so, how can I do it (preferably without using a reverse proxy and mod_rewrite)
 
  • Like
Reactions: Ruben GM
I have similar request with 365 SSO. Being able to disable user/password will be a security improvement, even if it is to be set at user level, we should be able to disable it for every user with SSO, or to limit user/password to a list of Internal IP range (if the user also has a physical phone).
User and password login doesn't even allow to add MFA.

This needs to improve.
 
AFAIK this is not currently possible. I’d also like to see functionality added to disable the standard authentication to the web client when SSO is enabled - even simply removing the username and password fields from the login page would be a welcomed change. I have set up SSO and the workaround I have implemented is reset all user’s web client passwords and not provide them with the new one. I have also edited the welcome email template to remove the code that would include the password in the email and added text to inform users to click the Google/M365 button to sign in. This way new users are unaware of what the password is and the user can’t obtain the password with the “resend credentials” function.

The passwords 3CX generates are complex enough that they wouldn’t be susceptible to dictionary attacks, brute force, password spraying, or showing up in databases of compromised passwords. With the right security settings for blacklisting an attacker’s IP would be blocked almost immediately and for ~31 years! This is the closest you’re going to get, currently, to effectively disabling standard authentication.
Thanks for sharing,

We have had an intrusion with user and password in our system. We are not sure how it was done, maybe they discovered an email or plain text credentials in a file of an old user, but it happened. Our security is set to block IPs with only 2 bad passwords... so I think it is high, but attacker also use tons of IP addresses nowadays.
I understand that the user and password is used in the QR code to connect from Android or IOS, not even sure about the browser integrated application, so I imagine you don't use those applications.
I think with your settings, physical phones are still receiving the user / password credentials.
 
Status
Not open for further replies.

Forum statistics

Threads
111,974
Messages
590,083
Members
164,899
Latest member
mazet