Remote Admin questions

Continuing the discussion from Introducing Remote Admin:

Some quick questions:

  1. Two-factor authentication? (key-based factor, not email or phone)

  2. Does this provide a fully validated TLS path?

On the latter, if they go to https://my.hubitat.com/ that will be a valid TLS cert. Does the link from that also have a valid cert? Is the communication between your backend and the end node likewise handled by valid TLS certs, or another buiilt-in valiidation tree based on internal certs? In short, does this more effectively prevent MitM ?

1 Like

I haven’t personally tried out the new remote admin service because I use a VPN for remote access to my LAN.

But I haven’t seen anything here to indicate it supports MFA logins at this time.

1 Like

Neither have I. Was questioning more as of a "can we get..." :smile_cat:

It is optional.

1 Like

Great question. We get TLS from remote to gateway, but how is the connection from gateway to hub secured?

I have remote admin and so far have found it incredibly useful and appreciate the feature. I don't have all my full networking equipment setup yet in house we're about to move into so this is clutch for me, even if just temporary.

However, I notice that if I navigate away from the tab and leave it idle it ends my session so quickly. I'd guess 1 minute?! Is there any way to adjust the timeout settings?

Not sure. But tagging @gopher.ny

Session timeout is 30 minutes. I'll take a look.

2 Likes

Thanks @gopher.ny and @aaiyar - not sure if it's an actual timeout or just a bug. I get that message even if I don't navigate away from the tab I noticed this morning. It presents a link that redirects me to the 'front page' of the remote admin and then I click 'connect to hub' and it displays the main page again. Sometimes I forces me to login in between, but not always.

I did a quick test, 1 minute inactivity doesn't result in timeouts while 90 seconds reliably does. That's way quick for a timeout, and the issue will get corrected quickly.

great, thanks so much!! @gopher.ny

1 Like

Uploaded remote admin with new version just (my apologies to those who got bumped out from their sessions). It appears to hold sessions better. There will be a matching change to hub software in the next hotfix, too, but even with one sided change it looks like an improvement. We'll know for sure in a few hours.

3 Likes

awesome thanks so much!!!

1 Like

Are you guys thinking about incorporating both subscriptions into one package?

I currently have two physical c7 hubs at two different locations. Does "remote admin" create a third virtual hub that could be used with Google Home? Right now I can only connect one hub to Google Home and so cannot control the devices connected to the other hub.

Thank you.

AFAIK that is not how the remote admin service works.

1 Like

@marktheknife has already answered your question. I just want to point out two alternatives to get Google Home working with both your hubs:

  1. Use HubConnect to share devices to the Google Home-connected hub, or,
  2. Use a second Google account for the second hub.
1 Like

My sister just sold her house in NYC and is moving permanently to Puerto Rico. She came to visit before going to the island and fell in love with the system and wanted to do the same thing in her apartment she got in the island but she is not that computer savvy and knowing how long it took me to learn how to maneuver around and have hubitat do what i wanted i doubt she will ever be able to fully understand the system and end up giving up.
She is about to get the hub and after the holidays i will be going over to the island to set it up and add all the sensors she needs and such.
My question is....
To be able to access her hub should i register it under my name to be able to use RA?
I just don't want to have to access 2 different accounts if she register the hub under her name.
Will there be any problem doing the RA when i'm in Florida and the other hub is in Puerto Rico?

2 Likes

Yes, Remote Admin is licensed per account. Once you subscribe to one hub registered with an account, all other hubs become eligible to be accessed via Remote Admin. So in your case, it sounds like the best is to register her hub with your account.

2 Likes

Kudos on being a rock star brother! I hope she realizes how lucky she is.