FIDO Universal 2nd Factor (U2F) is an open authentication standard that strengthens and simplifies two-factor authentication using specialized USB or NFC devices based on similar security technology found in smart cards.
Learn more about the U2F standard on Gluu's website.
This document will explain how to use Gluu's U2F interception script to configure the Gluu Server for a two-step authentication process with username and password as the first step, and any U2F device as the second step.
Check FIDO's certified products for a comprehensive list of U2F devices (sort by
- A Gluu Server (installation instructions);
- At least one U2F device for testing, like one of the devices listed above.
The script has the following properties
|u2f_application_id||URL of the application||
|u2f_server_uri||DNS/URL of the oxauth/u2f server||
|u2f_server_metadata_uri||URL of the u2f server metadata||
Follow the steps below to configure the U2F module in the oxTrust Admin GUI.
Manage Custom Scripts.
Click on the
Find the U2F script
Enable the script by ticking the check box
Now U2F is an available authentication mechanism for your Gluu Server. This means that, using OpenID Connect
acr_values, applications can now request U2F authentication for users.
To make sure U2F has been enabled successfully, you can check your Gluu Server's OpenID Connect configuration by navigating to the following URL:
"acr_values_supported": and you should see
Make U2F the Default Authentication Mechanism#
Now applications can request U2F authentication, but what if you want to make U2F your default authentication mechanism? You can follow these instructions:
- Navigate to
- Select the
Default Authentication Methodtab.
- In the Default Authentication Method window you will see two options:
oxTrust acrfield controls the authentication mechanism that is presented to access the oxTrust dashboard GUI (the application you are in).
Default acrfield controls the default authentication mechanism that is presented to users from all applications that leverage your Gluu Server for authentication.
You can change one or both fields to U2F authentication as you see fit. If you want U2F to be the default authentication mechanism for access to oxTrust (the admin portal) and all other applications that leverage your Gluu Server, change both fields to U2F.