Both sides previous revisionPrevious revisionNext revision | Previous revisionLast revisionBoth sides next revision |
institute_lorentz:2fa-pc [2021/03/15 09:03] – [Step 2] lenocil | institute_lorentz:2fa-pc [2021/04/01 14:58] – [Step 4] lenocil |
---|
<figure>{{:institute_lorentz:keepassxc1.png?direct&500|}}{{:institute_lorentz:keepassxc2.png?direct&200|}}<caption>TOTP Setup with KeePassXC. Use the TOTP settings described in Step 2.</caption></figure> | <figure>{{:institute_lorentz:keepassxc1.png?direct&500|}}{{:institute_lorentz:keepassxc2.png?direct&200|}}<caption>TOTP Setup with KeePassXC. Use the TOTP settings described in Step 2.</caption></figure> |
| |
Generate a OTP by clicking on //Entries -> TOTP -> Show TOTP// and paste it to | Generate a OTP by clicking on //Entries -> TOTP -> Show TOTP//. Insert this TOTP in the //One-time code// form input and, if you wish, a label in the form input called //Device Name//. This label is meant to help you keep track with which device the **secret key** has been shared. Click on //Submit//. |
<figure>{{:institute_lorentz:keepassxc3.png?direct&500|}}{{:institute_lorentz:keepassxc4.png?direct&200|}}{{:institute_lorentz:keepassxc5.png?direct&400|}}<caption>TOTP generation KeePassXC and final 2FA setup on the Lorentz Institute Identity Provider</caption></figure> | <figure>{{:institute_lorentz:keepassxc3.png?direct&500|}}{{:institute_lorentz:keepassxc4.png?direct&200|}}{{:institute_lorentz:keepassxc5.png?direct&400|}}<caption>TOTP generation KeePassXC and final 2FA setup on the Lorentz Institute Identity Provider</caption></figure> |
| |
| ==== Step 4 ==== |
| If Step 3 succeeds (errors might occur if there is too much lag time, i.e. the OTP expired), the system will send you an email to your private (not @lorentz) e-mail address with [[institute_lorentz:verify_identity|precise instructions]] on how to verify your identity. If your identity cannot be validated, you will not be granted access to the system. |
| |
| <figure>{{:institute_lorentz:idp4_email1.png?direct&344|}}<caption>Verify your private email address</caption></figure> |
| |
| ==== Step 5 ==== |
| Verify your identity by visiting your private email inbox. You should have received an email from the Lorentz Institute Identity Provider ((Details of this email are not disclosed here to prevent phishing.)). Open that email and __copy__ (for instance using on most platforms Control-C or right-mouse click copy) the secret code in the body of the message. Visit https://www.lorentz.leidenuniv.nl/idp/ and __paste__ (on most platforms Control-P or right-mouse click paste) the secret code in the white text area. Click on `Submit'. Your identity is now verified. |
| |
| <figure>{{:institute_lorentz:idp4_email2.png?direct&400|}}{{:institute_lorentz:idp4_email3_mod.png?direct&380|}}{{:institute_lorentz:idp4_email4.png?direct&380|}}<caption>Screenshot of e-mail verification process.</caption></figure> |
| |
| |
| ==== Step 6 ==== |
| |
| Click on //Back to application// to redirect your browser to the Lorentz Institute SSO web application from which you started the whole process or close the browser. Your setup is complete. |
| |
| ===== Problems and Solutions ===== |
| |
| |I cannot setup 2FA/access the system| Make sure we have your private email address on record| |
| |I lost my smartphone/PC with my OTP secret|Notify <support@lorentz.leidenuniv.nl> \\ [[:when_you_are_new_at_the_lorentz_institute|Change]] your IL credentials | |
| |How do I disable 2FA?| 2FA is mandatory on all SSO web services and to access our SSH server | |
| |My TOTP is incorrect| Make sure your phone's (PC's) clock is synchronised to the SSH server time and you scanned/copied all TOTP settings correctly | |
| |My OTP secret is compromised| Notify <support@lorentz.leidenuniv.nl> \\ [[:when_you_are_new_at_the_lorentz_institute|Change]] your IL credentials| |