Wtyczka Google Authenticator dla WordPressa pozwala na dwuskładnikowe uwierzytelnianie za pomocą aplikacji Google Authenticator na urządzenia Androida/iPhone’a/Blackberry.
Jeśli wiesz coś na temat bezpieczeństwa, być może masz już zainstalowaną aplikację Google Authenticator na swoim smartfonie, używając jej do uwierzytelniania dwuskładnikowego w Gmailu/Dropbox/Lastpass/Amazon itp.
Wymóg uwierzytelniania dwuskładnikowego można włączyć dla każdego użytkownika. Można włączyć dla swojego konta administratora, ale rozważ logowanie się jak na mniej uprzywilejowane konta.
Jeśli występuje potrzeba prowadzenia bloga za pomocą aplikacji na Androida/iPhone’a lub innego oprogramowania korzystającego z interfejsu XMLRPC, można włączyć funkcję hasła do aplikacji w tej wtyczce, proszę pamiętać, że włączenie funkcji hasła do aplikacji zmniejszy bezpieczeństwo witryny.
- Make sure your webhost is capable of providing accurate time information for PHP/WordPress, ie. make sure a NTP daemon is running on the server.
- Zainstaluj i włącz wtyczkę
- Enter a description on the Users -> Profile and Personal options page, in the Google Authenticator section.
- Scan the generated QR code with your phone, or enter the secret manually, remember to pick the time based one.
You may also want to write down the secret on a piece of paper and store it in a safe place. - Remember to hit the Update profile button at the bottom of the page before leaving the Personal options page.
- That’s it, your WordPress blog is now a little more secure.
Najczęściej zadawane pytania
Can I use Google Authenticator for WordPress with the Android/iPhone apps for WordPress?
Yes, you can enable the App password feature to make that possible, but notice that the XMLRPC interface isn’t protected by two-factor authentication, only a long password.
I want to update the secret, should I just scan the new QR code after creating a new secret?
No, you’ll have to delete the existing account from the Google Authenticator app on your smartphone before you scan the new QR code, that is unless you change the description as well.
I am unable to log in using this plugin, what’s wrong ?
The Google Authenticator verification codes are time based, so it’s crucial that the clock in your phone is accurate and in sync with the clock on the server where your WordPress installation is hosted.
If you have an Android phone, you can use an app like ClockSync to set your clock in case your Cell provider doesn’t provide accurate time information
Another option is to enable „relaxed mode” in the settings for the plugin, this will enable more valid codes by allowing up to a 4 min. timedrift in each direction. -
I have several users on my WordPress installation, is that a supported configuration ?
Yes, each user has his own Google Authenticator settings.
During installation I forgot the thing about making sure my webhost is capable of providing accurate time information, I’m now unable to login, please help.
If you have SSH or FTP access to your webhosting account, you can manually delete the plugin from your WordPress installation,
just delete the wp-content/plugins/google-authenticator directory, and you’ll be able to login using username/password again. -
I don’t own a Smartphone, isn’t there another way to generate these secret codes ?
Tak, jest tutaj wersja internetowa: https://gauth.apps.gbraad.nl/
Projekt na Githubie: https://github.com/gbraad/gauth -
Can I create backupcodes ?
No, but if you’re using an Android smartphone you can replace the Google Authenticator app with Authenticator Plus.
It’s a really nice app that can import your existing settings, sync between devices and backup/restore using your sd-card.
It’s not a free app, but it’s well worth the money. -
Any known incompatabilities ?
Yes, the Man-in-the-middle attack/replay detection code isn’t compatible with the test/setup mode in the „Stop spammer registration plugin”,
please remember to remove the „Check credentials on all login attempts” checkmark before installing my plugin.
