Release Notes Cloud Portal Guest Invitations 4.0 January 2014 Cloud Portal Guest Invitations 4.0 Release Notes Copyright sentence ( 2014, CTERA Networks. All rights reserved)
1 Release Contents Copyright 2009-2014 CTERA Networks Ltd. All rights reserved. No part of this document may be reproduced in any form or by any means without written permission from CTERA Network Ltd. Information in this document is subject to change without notice and does not represent a commitment on part of CTERA Networks Ltd. CTERA, C200, C400, C800, P1200, CloudPlug, NEXT3, Cloud Attached Storage, and Virtual Cloud Drive are trademarks, service marks, or registered trademarks of CTERA Networks Ltd. All other product names mentioned herein are trademarks or registered trademarks of their respective owners. The products described in this document are protected by U.S. patents, foreign patents, or pending applications. 2 Cloud Portal Guest Invitations 4.0 Release Notes
1 Release Contents About This Release Guest invitations are special time-limited URLs containing a secret code that grants the recipient the ability to view a specific file or folder on a Cloud Drive, and to optionally collaborate on those items. In CTERA Portal 4.0, guest invitations include the following highlights: Two-factor authentication Public link Invitation Access and Authentication Logging Two-Factor Authentication In previous versions, CTERA Portal administrators could require invitation recipients to authenticate to the CTERA Portal using their username and password, before they could access shared file/folders. This provided a single layer of protection against unintended recipients accessing the guest invitation URL. CTERA Portal 4.0 supports two-factor authentication for guest invitations. In addition to requiring recipients to authenticate to the CTERA Portal, it is possible to send them a random, 6-digit numeric passcode via email, which they must enter in order to access the shared file/folder. To enable two-factor authentication, a CTERA Portal administrator visits the Settings > Invitations page, clicks Settings, and selects Verify with Email and/or Verify with Text Message. Cloud Portal Guest Invitations 4.0 Release Notes 3
1 Release Contents When a portal user wants to share file/folder using two-factor authentication, they access their Cloud Drive, browse to the desired file/folder, and click Invite Guest. 4 Cloud Portal Guest Invitations 4.0 Release Notes
Release Contents 1 In the Protection Level field, the user selects Verify by Email, fills in the rest of the fields, and clicks Invite. The recipient will receive an email invitation with a link to the shared file/folder As well as an email with a passcode. Cloud Portal Guest Invitations 4.0 Release Notes 5
1 Release Contents When the recipient clicks on the link in the invitation, a popup window will prompt them for the passcode. The recipient can only view the shared file/folder after entering the passcode. Protection against Brute Force and DoS Attacks Two-factor authentication is protected against brute force attacks: The user is given five tries to enter the code, after which the code is disabled. In addition, rate limits are employed to restrict the number of authentication requests, so as to protect against denial of service attacks. Bypass of Two-Factor Authentication On private computers, after successfully authenticating using two-factor authentication, the user is given the option of setting their computer as "Trusted". When this option is selected, a 256-bit, unique random key is stored on the user's computer, allowing the user to bypass twofactor authentication challenges and avoid answering challenges from the same device for the next 30 days. 6 Cloud Portal Guest Invitations 4.0 Release Notes
Release Contents 1 Public Link In addition to two-factor authentication, it is possible to include a public link in guest invitations. To enable public links, a CTERA Portal administrator visits the Settings > Invitations page, clicks Settings, and then selects Public Link. When a portal user wants to share file/folder, they access their Cloud Drive, browse to the desired file/folder, and click Invite Guest. Then in the Protection Level field, they select Public Link. The recipient will receive an invitation with a public link to the shared file/folder. CTERA administrators can easily copy the link when viewing the invitation in the CTERA Portal's Settings > Invitations page. Cloud Portal Guest Invitations 4.0 Release Notes 7
1 Release Contents Invitation Access and Authentication Logging All accesses to invitations, as well as successful or failed two-factor authentication attempts, are logged in the CTERA Portal Access Log. 8 Cloud Portal Guest Invitations 4.0 Release Notes