Security
Category
Security
Liferay Version
All
Price
All
- Kerberos SSO
- SMC TREVISO S.R.L.
- Security
- €199.00 EUR
The Integrated Windows Authentication is a set of protocols and procedures that allows a user, who has connected to a Microsoft Windows workstation with his Domain credentials, to access the applications without enter his credentials again. We are, in practice, in a Single SignOn scanario.
While standard Liferay only supports the NTLM protocol, this plugin, created by SMC, allows Liferay to participate in the Single SignOn using Kerberos.
Read the documentation for more details on how Integrated Windows Authentication works and how to configure the different actors (Liferay, the browser, etc).
While standard Liferay only supports the NTLM protocol, this plugin, created by SMC, allows Liferay to participate in the Single SignOn using Kerberos.
Read the documentation for more details on how Integrated Windows Authentication works and how to configure the different actors (Liferay, the browser, etc).
- Two Factor Authentication - Aspire
- Aspire Software Solutions
- Security
- $10.00 USD
This application provides Two-factor-authentication functionality, to integrate with liferay web application. The user can enable two-factor-authentication with a secret key or QR Image. It supports google authenticator android app and chrome browser extension to get the one-time password.
- Secure Access
- OMB Co., Ltd.
- Security
- $20.00 USD
OMB Secure Access plugin can restrict users to access to pages, sites, and control panel of the portal based on their IP addresses, and it supports IPv4-based CIDR for convenient configuration. It consists of two portlets and one hook: Secure Access Administration and Secure Acccess for Site portlets, and Login hook.
Main Features:
- Enable or disable company-wide, group-wide, per-page access policies
- Confiure allow or deny policies according to specified default rule
- Specify error page when forbidden
- Add HTML-formatted contents to default forbidden page
- English, Korean, and Thai language pre-translated
Main Features:
- Enable or disable company-wide, group-wide, per-page access policies
- Confiure allow or deny policies according to specified default rule
- Specify error page when forbidden
- Add HTML-formatted contents to default forbidden page
- English, Korean, and Thai language pre-translated
- Secure Login
- OMB Co., Ltd.
- Security
- $30.00 USD
OMB Secure Login plugin makes it more secure to sign into your site using tracking your login history, giving notifications, and requiring CAPTCHA and OTP. It consists of two portlets and one hook: Secure Login Administration and My Login portlets, and Login hook.
Main Features:
- Enable and tracking login histroy
- Enable login notifications using email
- Prevent specific devices or locations from logging in
- Configure days to keep login history and notification data
- Enable CAPTCHA on login page
- Enable TOTP on login page
- Support GEO-IP API using JSON to record login locations
- Support QR Code Generator API
- Add HTML-formatted
Main Features:
- Enable and tracking login histroy
- Enable login notifications using email
- Prevent specific devices or locations from logging in
- Configure days to keep login history and notification data
- Enable CAPTCHA on login page
- Enable TOTP on login page
- Support GEO-IP API using JSON to record login locations
- Support QR Code Generator API
- Add HTML-formatted
- Social Login for Liferay 7/DXP
- Surekha Technologies
- Security
- $29.99 USD
Social Login for Liferay 7/DXP plugin is developed by Surekha Technologies using OAuth 2.0 based social networks login.
Social Login for Liferay 7/DXP plugin for Liferay enables you to login using social networking site accounts. This Liferay plugin allows Guest users to login to Liferay portal with LinkedIn, Github, Twitter and Microsoft account. These login options are shown at the bottom of the Liferay login screen.
Social Login for Liferay 7/DXP plugin allows you to login very easily and quickly. User don’t need to create account in Liferay portal rather directly login with Linkedin, Github, Twitter or Microsoft account credentials.
Social Login for Liferay 7/DXP plugin for Liferay enables you to login using social networking site accounts. This Liferay plugin allows Guest users to login to Liferay portal with LinkedIn, Github, Twitter and Microsoft account. These login options are shown at the bottom of the Liferay login screen.
Social Login for Liferay 7/DXP plugin allows you to login very easily and quickly. User don’t need to create account in Liferay portal rather directly login with Linkedin, Github, Twitter or Microsoft account credentials.
- TwoWay Authentication Premium - 6.1
- Thread Solutions S.R.L.
- Security
- €485.00 EUR
TwoWay Premium is a plugin providing Two Steps Authentication to access you Liferay portal instance.
Two steps verification adds an extra security layer for your Liferay Portal account by requiring user to enter a one-time verification code in addition to your username and password, when signing in to your account. Our code is based on well-know libraries, open algorithms and standards and fit perfectly in Liferay Portal, so is possibile to enable it together with other authentication provider like LDAP.
Into portal control panel, Admin can:
- enable TwoWay Authentication per portal as for embedded Liferay's methods
- choose which OTP
Two steps verification adds an extra security layer for your Liferay Portal account by requiring user to enter a one-time verification code in addition to your username and password, when signing in to your account. Our code is based on well-know libraries, open algorithms and standards and fit perfectly in Liferay Portal, so is possibile to enable it together with other authentication provider like LDAP.
Into portal control panel, Admin can:
- enable TwoWay Authentication per portal as for embedded Liferay's methods
- choose which OTP
- TripWire CE
- David H Nebinger
- Security
- $12.50 USD
TripWire monitors the OSGi resources of a Liferay application server.
TripWire reports on OSGi bundle status, versions and service status changes in addition to portal and system properties, acting as a monitor for unintended or unauthorized changes. It will notify when any monitored value changes so administrators will know when some aspect of the portal has been changed.
In case of unauthorized change or deployment, administrators will be notified and can take action to undo the change, revert the deployment or capture a new baseline snapshot to accept the change.
This control panel application provides a full view into the status of
TripWire reports on OSGi bundle status, versions and service status changes in addition to portal and system properties, acting as a monitor for unintended or unauthorized changes. It will notify when any monitored value changes so administrators will know when some aspect of the portal has been changed.
In case of unauthorized change or deployment, administrators will be notified and can take action to undo the change, revert the deployment or capture a new baseline snapshot to accept the change.
This control panel application provides a full view into the status of
- TripWire DXP
- David H Nebinger
- Security
- $62.50 USD
TripWire monitors the OSGi resources of a Liferay application server.
In a standalone Liferay DXP-based installation, TripWire reports on OSGi bundle status, versions and service status changes in addition to portal and system properties, acting as a monitor for unintended or unauthorized changes. It will notify when any monitored value changes so administrators will know when some aspect of the portal has been changed.
In a cluster-based Liferay DXP installation, TripWire monitors the same but reports on differences between the nodes in the cluster, ensuring the entire cluster is in sync across all aspects of the OSGi environment and
In a standalone Liferay DXP-based installation, TripWire reports on OSGi bundle status, versions and service status changes in addition to portal and system properties, acting as a monitor for unintended or unauthorized changes. It will notify when any monitored value changes so administrators will know when some aspect of the portal has been changed.
In a cluster-based Liferay DXP installation, TripWire monitors the same but reports on differences between the nodes in the cluster, ensuring the entire cluster is in sync across all aspects of the OSGi environment and
- TwoWay Authentication - DXP and 7.0
- Thread Solutions S.R.L.
- Security
- €485.00 EUR
TwoWay Premium is a plugin providing Two Steps Authentication to access you Liferay portal instance.
Two steps verification adds an extra security layer for your Liferay Portal account by requiring user to enter a one-time verification code in addition to your username and password, when signing in to your account. Our code is based on well-know libraries, open algorithms and standards and fit perfectly in Liferay Portal, so is possibile to enable it together with other authentication provider like LDAP.
Into portal control panel, Admin can:
- enable TwoWay Authentication per portal as for embedded Liferay's methods
- choose which OTP
Two steps verification adds an extra security layer for your Liferay Portal account by requiring user to enter a one-time verification code in addition to your username and password, when signing in to your account. Our code is based on well-know libraries, open algorithms and standards and fit perfectly in Liferay Portal, so is possibile to enable it together with other authentication provider like LDAP.
Into portal control panel, Admin can:
- enable TwoWay Authentication per portal as for embedded Liferay's methods
- choose which OTP
- TwoWay Authentication Premium - 6.2
- Thread Solutions S.R.L.
- Security
- €485.00 EUR
TwoWay Premium is a plugin providing Two Steps Authentication to access you Liferay portal instance.
Two steps verification adds an extra security layer for your Liferay Portal account by requiring user to enter a one-time verification code in addition to your username and password, when signing in to your account. Our code is based on well-know libraries, open algorithms and standards and fit perfectly in Liferay Portal, so is possibile to enable it together with other authentication provider like LDAP.
Into portal control panel, Admin can:
- enable TwoWay Authentication per portal as for embedded Liferay's methods
- choose which OTP
Two steps verification adds an extra security layer for your Liferay Portal account by requiring user to enter a one-time verification code in addition to your username and password, when signing in to your account. Our code is based on well-know libraries, open algorithms and standards and fit perfectly in Liferay Portal, so is possibile to enable it together with other authentication provider like LDAP.
Into portal control panel, Admin can:
- enable TwoWay Authentication per portal as for embedded Liferay's methods
- choose which OTP
- TwoWay Authentication Lite - 6.2
- Thread Solutions S.R.L.
- Security
- €215.00 EUR
TwoWay Premium is a plugin providing Two Steps Authentication to access you Liferay portal instance.
Two steps verification adds an extra security layer for your Liferay Portal account by requiring user to enter a one-time verification code in addition to your username and password, when signing in to your account. Our code is based on well-know libraries, open algorithms and standards and fit perfectly in Liferay Portal, so is possibile to enable it together with other authentication provider like LDAP.
Into portal control panel, Admin can:
- enable TwoWay Authentication per portal as for embedded Liferay's methods
- (ONLY IN THE PREMIUM
Two steps verification adds an extra security layer for your Liferay Portal account by requiring user to enter a one-time verification code in addition to your username and password, when signing in to your account. Our code is based on well-know libraries, open algorithms and standards and fit perfectly in Liferay Portal, so is possibile to enable it together with other authentication provider like LDAP.
Into portal control panel, Admin can:
- enable TwoWay Authentication per portal as for embedded Liferay's methods
- (ONLY IN THE PREMIUM
- Dockbar Integration
- D'vel Snc
- Security
- Free
The application adds a new custom permission called VIEW_DOCKBAR inside the "General Permissions" section of the role configuration (except for Guest role).
With this new custom permission, frontend developers can leverage the Liferay permission system to show/hide the portal dockbar inside a custom theme.
Here's how to initialize a Freemarker variable inside the init_custom.ftl file of a custom theme:
<#assign viewDockbar = permissionChecker.hasPermission(themeDisplay.scopeGroupId, "90", "90", "VIEW_DOCKBAR") />
And here's how to use the Freemarker variable:
<#if viewDockbar>
<@liferay.control_menu />
</#if>
With this new custom permission, frontend developers can leverage the Liferay permission system to show/hide the portal dockbar inside a custom theme.
Here's how to initialize a Freemarker variable inside the init_custom.ftl file of a custom theme:
<#assign viewDockbar = permissionChecker.hasPermission(themeDisplay.scopeGroupId, "90", "90", "VIEW_DOCKBAR") />
And here's how to use the Freemarker variable:
<#if viewDockbar>
<@liferay.control_menu />
</#if>
- Two Factor Authentication - Liferay 7.0, 7.1
- DeltaFixes Technologies LLP
- Security
- Free
Purpose of this plugin is to add an extra security layer for your Liferay Portal. In addition to username and password, user requires to enter a one-time verification code (By using Google Authenticator), when signing in to Liferay Portal (If this feature is enabled).
By using "Two Factor Config" portlet user can Enable/disable this feature. In case user lost Bar/QR code they can recover it by using Recovery option available one "Verify OTP" page. As a part of security, this plugin stores encrypted QR code in database.
To setup this plugin on your Liferay instance, please refer documentation.
By using "Two Factor Config" portlet user can Enable/disable this feature. In case user lost Bar/QR code they can recover it by using Recovery option available one "Verify OTP" page. As a part of security, this plugin stores encrypted QR code in database.
To setup this plugin on your Liferay instance, please refer documentation.
- SAML 2.0 Single Sign-On Adapter
- ASSUREBRIDGE, INC.
- Security
- Free
The SAML 2.0 Single Sign-On Adapter allows your Liferay server to act as a SAML Identity (IDP) or Service (SP) Provider or both. The SSO adapter is a lightweight Liferay hook that connects Liferay server to the AssureBridge SSO Hub. This provides advanced SAML capabilities including:
- Connect a single Liferay Service Provider to multiple SAML 2.0 Identity Providers
- Allow a single Liferay Server to act as a Service Provider and an Identity Provider simultaneously
- Allows a single Liferay Server to mix SAML SSO with the native Liferay Login
- Allows for user auto-provisioning
- Provides flexible and extensible mechanisms to
- Connect a single Liferay Service Provider to multiple SAML 2.0 Identity Providers
- Allow a single Liferay Server to act as a Service Provider and an Identity Provider simultaneously
- Allows a single Liferay Server to mix SAML SSO with the native Liferay Login
- Allows for user auto-provisioning
- Provides flexible and extensible mechanisms to
- Liferay CE Portal Security SSO OpenID
- Liferay, Inc.
- Security
- Free
OpenID is a single sign-on standard implemented by multiple vendors. Users can register for an ID with the vendor they trust. The credential issued by that vendor can be used by all the web sites that support OpenID. Some high profile OpenID vendors are Google, Paypal, Amazon, and Microsoft. Please see the [OpenID site](http://www.openid.net/) for a more complete list.
Note: OpenID was deprecated in Liferay 7.1 and may be removed in future versions. Users should migrate to OpenID Connect.
Note: OpenID was deprecated in Liferay 7.1 and may be removed in future versions. Users should migrate to OpenID Connect.
- Liferay CE Portal Security SSO NTLM
- Liferay, Inc.
- Security
- Free
NTLM (NT LAN Manager) is a suite of Microsoft protocols that provide authentication, integrity, and confidentiality for users. Though Microsoft has adopted Kerberos in modern versions of Windows server, NTLM is still used when authenticating to a workgroup. @product@ supports NTLM v2 authentication. NTLM v2 is more secure and has a stronger authentication process than NTLMv1.
Note: NTLM authentication is deprecated in Liferay 7.1 and may be removed in future versions. Users should migrate to Kerberos.
Note: NTLM authentication is deprecated in Liferay 7.1 and may be removed in future versions. Users should migrate to Kerberos.
- Liferay CE Portal Security SSO Google
- Liferay, Inc.
- Security
- Free
Google Authorization is a way of authorizing access to Google services.
Note: Google authorization is deprecated in Liferay 7.2 and may be removed in future versions. Users should migrate to OAuth 2.0
Note: Google authorization is deprecated in Liferay 7.2 and may be removed in future versions. Users should migrate to OAuth 2.0
- Liferay CE Plugin for OAuth 2.0
- Liferay, Inc.
- Security
- Free
OAuth 2.0 is an industry-standard authorization protocol. Users can seamlessly share select credentials from another website to log into yours. It works by authorizing password-less access to portions of user-owned resources (such as an email address, a user profile picture, or something else from your account) and other permissioned resources.
- Two Factor Secure Login
- Knowarth Technologies Pvt Ltd (India)
- Security
- Free
Accessing any system with just single Password is an old way today. Single password authentication is not strong enough and hacker can steal it with multiple methods. One workaround is to create and remember complex passwords but then it’s not good idea and users are not willing enough to use it. This is the reason Two Factor Authentication (2FA) is becoming so essential today.
We at KNOWARTH created a 2FA component called “SecureLogin” which is useful for easy and secure login on Liferay platform with your mobile device.
Problem:- Out of the box, Liferay doesn’t provide 2FA (Two Factor Authentication) mechanism.
Pre-Requisite:- We have
We at KNOWARTH created a 2FA component called “SecureLogin” which is useful for easy and secure login on Liferay platform with your mobile device.
Problem:- Out of the box, Liferay doesn’t provide 2FA (Two Factor Authentication) mechanism.
Pre-Requisite:- We have
- Yubikey OTP Login for Liferay
- Mika Koivisto
- Security
- Free
Yubikey OTP Login provides strong authentication to Liferay. Each account can have multiple keys registed but a key can only be associated with only one account.
- OpenID Connect plugin
- Finalist IT Group BV
- Security
- Free
Let users log in to Liferay with their social network account or any OpenID Connect compatible SSO system.
Most social networks support OpenID Connect to authenticate for third party applications.
This plugin enables Liferay to integrate with the OpenID Connect provider you choose, be it Google or Facebook or your own SSO provider (like OpenAM, Gluu, Ping Identity, etc.)
Liferay supports OAuth 1.0 out of the box, but that OAuth-version is deprecated. OpenID Connect is based on OAuth 2.0. Use OpenID Connect, the proper modern SSO standard.
Key features:
* Creates users if they do not exist upon successful authentication, update existing
Most social networks support OpenID Connect to authenticate for third party applications.
This plugin enables Liferay to integrate with the OpenID Connect provider you choose, be it Google or Facebook or your own SSO provider (like OpenAM, Gluu, Ping Identity, etc.)
Liferay supports OAuth 1.0 out of the box, but that OAuth-version is deprecated. OpenID Connect is based on OAuth 2.0. Use OpenID Connect, the proper modern SSO standard.
Key features:
* Creates users if they do not exist upon successful authentication, update existing
- Social Login for Liferay 6.2
- Surekha Technologies
- Security
- Free
Social Login hook plugin is developed by Surekha Technologies using OAuth 2.0 based social networks login.
Social Login hook plugin for Liferay enables you to login using social networking site accounts. This Liferay plugin allows Guest users to login to Liferay portal with LinkedIn or Google account. These login options are shown at the bottom of the Liferay login screen.
Social Login hook plugin allows you to login very easily and quickly. User don’t need to create account in Liferay portal rather directly login with Linkedin or Google account credentials.
Key Benefits:
- Allows user to login via OAuth2 based login
- Linkedin
Social Login hook plugin for Liferay enables you to login using social networking site accounts. This Liferay plugin allows Guest users to login to Liferay portal with LinkedIn or Google account. These login options are shown at the bottom of the Liferay login screen.
Social Login hook plugin allows you to login very easily and quickly. User don’t need to create account in Liferay portal rather directly login with Linkedin or Google account credentials.
Key Benefits:
- Allows user to login via OAuth2 based login
- Device Based Security
- Hardik Rajani
- Security
- Free
Device based security is a reusable component for Liferay. This component will secure user login as per the devices. Once user will login to portal from some particular device. Portal will store user’s IP address as device identity. Next time if user will login through some other device/Network. User will be asked to answer security question/answer. When user will login for the first time, portal will ask 3 different security questions and will store the answers to database.
For add security question of your choice, You can add question in portal.properties file of the portlet. Change value of following 3 property. For adding localization,
For add security question of your choice, You can add question in portal.properties file of the portlet. Change value of following 3 property. For adding localization,
- Mobile Verification
- Hardik Rajani
- Security
- Free
Now a days, Most of the site needs to verify the mobile number and email address of their users for security purpose. Liferay is providing email verification OOB.
This plugin will help to integrate that functionality directly to the Liferay portal.
Key Features
- Admin can enable/disable mobile verification very easily.
- Mobile verification can be set to be mandatory/optional.
- Further development depending upon mobile verification can be done easily. As mobile number and its status is stored in User Custom Attribute.
Steps to Use
1) Deploy Hook
2) As Admin Go to Control Panel -> Portal Settings -> Authentication
3) Select Tab “SMS”
This plugin will help to integrate that functionality directly to the Liferay portal.
Key Features
- Admin can enable/disable mobile verification very easily.
- Mobile verification can be set to be mandatory/optional.
- Further development depending upon mobile verification can be done easily. As mobile number and its status is stored in User Custom Attribute.
Steps to Use
1) Deploy Hook
2) As Admin Go to Control Panel -> Portal Settings -> Authentication
3) Select Tab “SMS”
- Liferay CE Solr 4 Search Engine
- Liferay, Inc.
- Security
- Free
This app provides integration with Apache Solr, the popular open source enterprise search platform from the Apache Lucene project. Its major features include powerful full-text search, hit highlighting, faceted search, dynamic clustering, database integration, rich document (e.g., Word, PDF) handling, and geospatial search. Solr is highly scalable, providing distributed search and index replication, and it powers the search and navigation features of many of the world's largest internet sites. On installing and enabling this app, Liferay Portal will communicate with a remotely deployed Solr server for indexing and searching.
This app uses
This app uses
- VK.com Single Sign On
- EmDev Limited
- Security
- Free
VK.com (Vkontakte) is most popular social network in exUSSR countries (like Russia, Ukraine, Belarus,Kazakhstan and so on) with more then 200 millions users.
This plugin allows admins to configure Liferay for login via VK.com (like default Facebook implementation). To enable using this feature you need enable VK on portal authentication settings and specify your application credentials (need first to register application on vk.com).
Plugin supports both - Liferay 6.1 and 6.2 versions.
This plugin allows admins to configure Liferay for login via VK.com (like default Facebook implementation). To enable using this feature you need enable VK on portal authentication settings and specify your application credentials (need first to register application on vk.com).
Plugin supports both - Liferay 6.1 and 6.2 versions.
- Liferay CE Shibboleth Single Sign On
- Liferay, Inc.
- Security
- Free
The Shibboleth Single Sign On hook enables Liferay to use a Shibboleth Identity Provider to sign into the portal. It's completely configurable, allowing you to set a custom header attribute and a logout URL to give your users a seamless experience.
- SQLI Authenticator
- SQLI
- Security
- Free
The Liferay Authentication portlet relies on a "Two-Factor" authentication system. It's a method of strong authentication requiring two different forms of identification instead of the traditional single password. The application, based on Google Authenticator, offers the following functionalities :
- Secret management and assignment workflow
- Integrated interface dedicated to account administration.
- Customizable and user friendly interface.
- Easily Upgradable Application.
Google Authenticator must be installed on the smartphone.
- Secret management and assignment workflow
- Integrated interface dedicated to account administration.
- Customizable and user friendly interface.
- Easily Upgradable Application.
Google Authenticator must be installed on the smartphone.
- HSTS (RFC6797) HTTP Strict Transport Security
- Olaf Kock
- Security
- Free
This app adds the HSTS header (RFC-6797) to https-responses. More information about HSTS (HTTP Strict Transport Security) can be found here:
* https://tools.ietf.org/html/rfc6797
* http://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security
* https://www.owasp.org/index.php/HTTP_Strict_Transport_Security
While it's possible to configure frontend webservers to add this header automatically, this app enables you to conditionally handle anonymous users differently from logged in users: You can configure the timeout for both kinds of users differently, e.g. to totally disable HSTS for anonymous users, while enforcing it for logged in users.
* https://tools.ietf.org/html/rfc6797
* http://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security
* https://www.owasp.org/index.php/HTTP_Strict_Transport_Security
While it's possible to configure frontend webservers to add this header automatically, this app enables you to conditionally handle anonymous users differently from logged in users: You can configure the timeout for both kinds of users differently, e.g. to totally disable HSTS for anonymous users, while enforcing it for logged in users.
- TwoWay Authentication Lite - 6.1
- Thread Solutions S.R.L.
- Security
- Free
TwoWay Premium is a plugin providing Two Steps Authentication to access you Liferay portal instance.
Two steps verification adds an extra security layer for your Liferay Portal account by requiring user to enter a one-time verification code in addition to your username and password, when signing in to your account. Our code is based on well-know libraries, open algorithms and standards and fit perfectly in Liferay Portal, so is possibile to enable it together with other authentication provider like LDAP.
Into portal control panel, Admin can:
- enable TwoWay Authentication per portal as for embedded Liferay's methods
- (ONLY IN THE PREMIUM
Two steps verification adds an extra security layer for your Liferay Portal account by requiring user to enter a one-time verification code in addition to your username and password, when signing in to your account. Our code is based on well-know libraries, open algorithms and standards and fit perfectly in Liferay Portal, so is possibile to enable it together with other authentication provider like LDAP.
Into portal control panel, Admin can:
- enable TwoWay Authentication per portal as for embedded Liferay's methods
- (ONLY IN THE PREMIUM