Joomla Extension

Two-Factor Authentication with SecSign ID Plugin

Use SecSign ID Joomla two factor authentication on your Joomla site with an easy and highly secure user login using iOS or Android mobile devices as well as for desktop use.


Find out why our Two-Factor Authentication is the best, some key-facts for developers and why you should upgrade to SecSign for your business.

Learn more about the options of on-premise use and your own customized ID App in your corporate design.

Download the plugin as cloud version for a free and convenient protection.

Table of contents

    SecSign ID is a plugin for real two-factor authentication (2FA) for Joomla sites. 2FA adds another layer of security to your website by using a second token. In this case the physical token is your smartphone.

    If you seek for more information about about two-factor authentication have a look at the Joomla Extension Page or our Github site.

    Questions? Feel free to get in touch with us if you need help setting up your SecSign ID plugin or to request a plugin for a not yet supported environment.

    1. Installation

    1. Log into Joomla
    2. Click on “Extensions > Extension Manager” in the main menu
    3. Go to “Install” in the submenu
    4. Select the downloaded zip archive and hit “Upload & Install”
    5. When the plugin was successfully installed, you will be redirected to the plugin page

    j1

    2. Configuration

    To use the SecSign ID Joomla two factor authentication, you need to assign SecSign IDs to the user profiles.

    1. Log into Joomla
    2. Go to “Components > SecSign ID”
    3. You will see a list with all registered users in the
      component view. You can insert or edit the
      SecSign ID for each user and deny password
      login individually

    j2

    You can also edit the SecSign ID in the respective user profile. Log into Joomla and go to the “UserManager”. Assign a SecSign ID to your profile to allow SecSign ID authentication.

    tutorial_user

    3. Plugin settings

    The configuration panel lets you manage the plugin behaviour for the Frontend and Backend Joomla two factor authentication login process.

    Backend

    1. Log into Joomla as admin
    2. Go to “Components > SecSign ID”
    3. Click on “Options” in the upper right corner

    j4

    Deactivate all passwords: All password logins will be deactivated on the admin pages and web pages. Only the secure SecSign ID Login will be available. Note: User without SecSign ID won’t be able to login.”

    Backend service name: The name of this web site as it shall be displayed on the user’s smart phone.

    The Tab Permissions:
    Enables you to grant access to the SecSign ID plugin configuration for specific user groups.

    j6

    4. Module Placement

    All frontend settings are located in the respective module. Right after installation, you can find your SecSign ID Frontend-Login at position-7.

    You are able to create any amount of frontend logins with different configurations. For example, a multi language website can use different redirections for the same login page. It is not possible to display more than one SecSign ID Login on one page.

    1. Log into Joomla as admin
    2. Go to “Extensions > Module Manager”
    3. Open the module named “SecSign ID Login” or create a new one with the module type
      “SecSign ID Login”
    4. If you want to change the visibility of the
      module on different pages, click on the Menu

    j5

    If you want to place the SecSign ID login inside an article, use {loadposition YOUR_POSITION}.

    Note: loadmodule and multiple SecSign ID login forms on the same page are not supported and will not work.

    Service name: The name of this web site as it shall be displayed on the user’s smart phone.

    Login Redirection Page: Select the page the user will be redirected to after a successful login. Select from all the pages listed in the dropdown menu. Choosing “Default” will return to the same page.

    Logout Redirection Page: Select the page the user will be redirected to after successfully ending their current session by logging out. Select from all the pages listed in the dropdown menu. Choosing “Default” will return to the same page.

    Frontend Layout: Change the layout of the SecSign ID frontend login form (frame and box-shadow).

    Show Greeting: Show or hide the simple greeting text.

    Show Name/Username: Displays the Joomla name or username after login.

    5. Plugin Contents

    1. Component SECSIGNID: Allows a login using a smart phone running SecSign ID Joomla two factor authentication App and provides the configuration interfaces.
    2. Plugin Authentication – SecSignID: This plug-in allows users to use Joomla two factor authentication via smart phone running SecSign App.
    3. Plugin Backend Authentication – SecSignID: This is the 2-step authentication plug-in, which adds an additional security layer to your Joomla backend.

    1. Plugin User – Profile – SecSignID: Allows users to assign a SecSign ID to their profile.
    2. Module SecSign ID Backend Login: This module displays a SecSignID login form at the Joomla backend login page.
    3. Module SecSign ID Login: This module displays a SecSignID login form on your website.

    6. Troubleshooting

    If you enabled the SecSign ID backend login and locked yourself out, do the following steps in order to disable the SecSign ID two factor authentication backend login.

    1. Open your SQL database via console or phpmyadmin, which contains all the data from your Joomla installation. (Not sure? Open your Joomla directory via FTP and search for host, user, password, db, dbprefix in config.php).
    2. Enter the following SQL code: update YOURDATABASE.YOURPREFIX_extensions set enabled=0 where element=mod_secsignid_backend
      a. OR open the table YOURPREFIX_extensions and search for
      mod_secsignid_backend in the column element.
      b. Change the 1 to a 0 in the column enabled.
    3. Save the changes and reload the backend login page.

    7. Available APIS

    We provide an ever growing list of APIs and plugins to easily integrate the SecSign ID Two-Factor Authentication in any project. An overview is available at Plugin and APIs.
    We do not only offer APIs in different programming languages but also plugins for CMS, Server and VPN environments, oAuth2 and many more. These plugins use our APIs and offer additional functionalities, for example user management, easy and native installation, logging or integration in firewalls or Active Directory.

    The JIRA plugin for example uses the JAVA-API. The PHP-Api and JS-API is used by WordPress, Joomla, Drupal, Typo3 and many more. The ASP.net/C#-API is used for the Windows and Cisco VPN and the C-API is used for protecting Unix SSH services. The Objective-C API is used by our AppleTV and iPhone/iPad apps.

    available_apis

    8. See for yourself

    You can experience the SecSign ID two-factor authentication and the two-factor login by simply integrating the plugin into your website or test environment. Or you can try out the login process on our website without having to register first. You already have a SecSign ID or you want one? Login now and use the portal or use our hassle free registration.

    See for yourself how fast and convenient the login process using challenge-response authentication with 2048-bit key pairs is. There is no need for passwords, and no passwords or other confidential information are ever transmitted. It is easy to integrate and simple to use.

    For more information about the patented SafeKey procedure and it's unique security can be found here.

    If you are missing an API for the programming language you are working with, feel free to contact us and we’ll find a solution with you. If you need help with the integration into an existing system or you can’t find the plugin for your content management system you are working with, don’t hesitate to contact our support team.

    Your own ID-Server

    On premise installations of SecSign ID offer the flexibility to connect with your preferred servers, services, and devices. And you can customize the SecSign ID with your own organization’s branding.

    your_own_id

    Why upgrade to SecSign?

    On-premise or in the cloud

    Choose between our SecSign ID Cloud or operate your own on-premise Two-Factor Authentication server.

    Easy customization

    Operate your own YourBrand ID app - Two-Factor Authentication customized to your needs.

    Ready-to-use SDK

    Integrate SecSign ID Two-Factor Authentication in existing apps with our ready-to-use SDK.

    Easy user management

    Use the Two-Factor Authentication Server to secure your company Active Directory/LDAP. Your own Identity and Access Management System, for example for mandatory updates and additional security features.

    Cover all logins

    Integration in any login environment: web, local, VPN, remote desktop, mobile logins and many more.

    Plugins for all your needs

    No need for complex integration: we have plugins for almost all environments.

    Do NOT follow this link or you will be banned from the site!