BEGIN:VCALENDAR
VERSION:2.0
PRODID:-//pretalx//pretalx.com//txlf2026//talk//JZGLEW
BEGIN:VTIMEZONE
TZID:US/Central
BEGIN:STANDARD
DTSTART:20251107T000000
TZNAME:CST
TZOFFSETFROM:-0600
TZOFFSETTO:-0600
END:STANDARD
BEGIN:DAYLIGHT
DTSTART:20260308T030000
RDATE:20270314T030000
TZNAME:CDT
TZOFFSETFROM:-0600
TZOFFSETTO:-0500
END:DAYLIGHT
BEGIN:STANDARD
DTSTART:20261101T020000
TZNAME:CST
TZOFFSETFROM:-0500
TZOFFSETTO:-0600
END:STANDARD
END:VTIMEZONE
BEGIN:VEVENT
SUMMARY:Centrally managed multi factor authentication for all your users' 
 notebooks - Cornelius Kölbel
DTSTART;TZID=US/Central:20261107T170000
DTEND;TZID=US/Central:20261107T175000
DTSTAMP:20260930T141437Z
UID:pretalx-txlf2026-JZGLEW@pretalx.com
DESCRIPTION:In enterprises or organizations users and their 2nd factors ar
 e managed centrally by you\, the IT department. This works fine with login
 s to central services like web portals\, the VPN or your SSH servers.\n\nB
 ut when it comes to the login at notebooks it comes to some additional cha
 llenges you need to overcome. Even in 2026 - notebooks can go offline.\n\n
 There are many different technical ways for multi factor authentication wi
 th different underlying cryptographic mechanisms. Symmetic keys or assymme
 tic keys. Some can work offline\, some are hard to manage\, some do not wo
 rk offline in a sensible way.\nIn this talk we are looking into different 
 authentication mechanism be it x509 certificates\, OTP or FIDO2 to name a 
 few with their pros and cons.\n\nThen we check how the open source multi f
 actor management system privacyIDEA implements different ways of authentic
 ating offline at your user's notebooks - be it Linux or Windows - with OTP
  tokens or with FIDO2 devices. In 2019 I held a talk at TXLF about privacy
 IDEA in general as an on prem multi factor solution. We are now looking de
 eper into management of FIDO2 devices and management for local logins to L
 inux and Windows machines.\n\nYou will get in depth knowledge how you can 
 secure your notebooks with reliable authentication hardware like Yubikeys 
 or other FIDO2 devices centrally managed in your own on prem privacyIDEA s
 ystem.
LOCATION:Bevo
URL:https://pretalx.com/txlf2026/talk/JZGLEW/
END:VEVENT
END:VCALENDAR
