Users change password remotely?


(Dan) #1

Continuing to evaluate Neth… My server is used by a number of family members for email and Nextcloud. Most of them are remote, have no reason to need VPN access to my LAN, and I don’t particularly want to give them access either. But they really need a way to be able to change their passwords. Is there a way to do this in Neth, either built-in or as a module?


Change user's password from roundcube
(Michael Kicks) #2

Every user can access to admin console for change it’s password.
https://nethserverip:980


(Marc) #3

Server-manager allows users to change its password from profile page.


(Dan) #4

And that’s accessible from outside the LAN?


(Michael Kicks) #5

Only you can tell to us…
I dont know which is your RED interface configuration or how is setup internet access.
Also, firewall configuration can block connection to admin interface from any connection.


(Alessio Fattorini) #6

Yes if 980 is accessible from outside the LAN


(Dan) #7

It’s probably my background with SME–in that environment, the server manager isn’t available to the WAN at all, at least by default. And that seems like a good security measure–if system administration isn’t accessible from the Internet at all, that closes off a lot of attack vectors. But it sounds like you’re saying that the only way a remote user can change his/her password is if the server manager is exposed to the Internet. That sounds like a lot of exposure for a very small operation.

Also in the SME environment, there’s a separate user-password page. I’d feel a lot better about exposing that than about exposing the entire server manager.

Can I expose it? Sure, it’s behind a pfSense router, so I can easily forward another port. But putting the server manager out on the Internet, protected only by a password (no matter how strong), doesn’t give me warm fuzzies.


(Michael Kicks) #8

By design, admin interface has crypted access.
If passwords are good enough, associate the service at fail2ban, it’s not the safest setting.

But for me is quite safe enough.


(Marc) #9

I prefer not exposing it to WAN. Don’t know if there are other options than VPN or SSH forwarding.


(Michael Kicks) #10

Did you try to access with user credentials at admin interfaces?


(Dan) #11

Yes, and getting trusted certs through Let’s Encrypt is easy as well–all of which is good. But all that does is prevent some one from getting usable data by sniffing on the wire. It doesn’t stop brute-forcing a password (though fail2ban would help here), and it doesn’t protect against any vulnerabilities in the server manager.

Likewise. VPN and SSH forwarding work around the issue by making a remote user effectively non-remote, but add a step that most of my users wouldn’t know how to do.

What about the groupware apps? Horde/Sogo/WebTop–does any of them have a “change password” function, and would it work for this?


(Dan) #12

Yes, and that works–I can log in as a user and change that user’s password. So if I do feel comfortable exposing the server manager to the Internet, that’s a way to do what I’m looking for.


(Jeroen Visser) #13

It would be nice to have an isolated page for users to change their password. But then again, I would never want my authentication server exposing anything to the wan.

SOGo lacks the option to change the password afaik. Outlook might be able to handle the forced change and be of use there, haven’t tested that tho.

I have read that, for implementation reasons, passwords should be changed through server manager. I would expect this not to be the case for AD account provider being used for all authentication (nor single server implementations where only mail is used by users)


(Marc) #14

For apps it could depend on ldap bind parameters ( write permissions)…
Horde and Nextcloud have it if I recall correctly, but never tried.

For Nextcloud with Active Directory account provider:

  • Admin > LDAP/AD integration > Advanced > Directory Settings:
  • Enable LDAP password changes per user (checkbox)
  • Default password policy DN

(Dan) #15

Ah, hadn’t thought about Nextcloud–and I would be running that, too. I’ll have to test to make sure it works, but that’s a possibility. Though I’d still be concerned about the “implementation reasons” @planet_jeroen mentions.


(Jeroen Visser) #16

Maybe @giacomo can shed some light on this, I am just parrotting him from here:


(Michael Kicks) #17

I agree. But there are thousand of services which allow change of passwords throught the internet. Consequently, it’s still not the safest choice, but for me a safe enough one.


(Dan) #18

Indeed, which is what I’m wanting to do as well. But I expect most of them keep their overall administration interface much more locked down.