User Tools

Site Tools


institute_lorentz:2fa-key

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
institute_lorentz:2fa-key [2021/06/07 09:35] lenocilinstitute_lorentz:2fa-key [2021/10/08 09:05] (current) – [Introduction] lenocil
Line 1: Line 1:
-====== First-time 2FA Setup via a FIDO2 Security Key ======+====== 2FA Setup via a FIDO2 Security Key ======
  
 ===== Introduction ===== ===== Introduction =====
Line 9: Line 9:
 |https://fidoalliance.org/fido2/| |https://fidoalliance.org/fido2/|
  
-|Because 2FA via a security key offers the strongest protection against cyber criminals, the IL encourages you always to use this method to login to all IL services.|+|Because 2FA via a security key offers the strongest protection against cyber criminals, \\ the IL encourages you always to use this method to login to all IL services.
 +|:!: If you have obtained a security key from the Lorentz Institute, you must return it upon termination of your appointment at the Institute |
 ===== Preliminary Actions ===== ===== Preliminary Actions =====
  
Line 18: Line 19:
 The setup of your security key differs slightly depending on whether you have already 2FA setup under your account, for instance via TOTP, or not. Follow the workflow below that is appropriate to your situation. The setup of your security key differs slightly depending on whether you have already 2FA setup under your account, for instance via TOTP, or not. Follow the workflow below that is appropriate to your situation.
  
-===== Setup without previous 2FA ===== +===== Setup without previous 2FA in place ===== 
-The setup of your security key differs slightly depending on whether you have already 2FA setup under your account, for instance via TOTP, or not. Follow the workflow below depending on whether you have previously setup 2FA.+
 ==== Step 1 ==== ==== Step 1 ====
 Notify the intention of registering a private key to <support@lorentz.leidenuniv.nl>. Notify the intention of registering a private key to <support@lorentz.leidenuniv.nl>.
Line 61: Line 62:
  
 You will be redirected automatically to the Lorentz Institute Identity Provider login page as in **Figure 1**. You will be redirected automatically to the Lorentz Institute Identity Provider login page as in **Figure 1**.
-<figure>{{:institute_lorentz:ilkey1.png?direct&300|}}<caption>Identity Provider login page</caption></figure>+<figure>{{:institute_lorentz:ilidp1.png?direct&300|}}<caption>Identity Provider login page</caption></figure>
  
 ==== Step 2 ==== ==== Step 2 ====
Line 67: Line 68:
 Enter your IL credentials and the correct TOTP to sign in. Upon successful login, your browser will ask you to register your security key (Figure 2). Plug your security key into an available USB-A port of your PC/laptop and confirm by pressing or touching the key button ((Key confirmation actions, such as pushing or touching, depend on the key used, please read the manual of your key's vendor)). Enter your IL credentials and the correct TOTP to sign in. Upon successful login, your browser will ask you to register your security key (Figure 2). Plug your security key into an available USB-A port of your PC/laptop and confirm by pressing or touching the key button ((Key confirmation actions, such as pushing or touching, depend on the key used, please read the manual of your key's vendor)).
  
-<figure>{{:institute_lorentz:ilkey2_mod.png?direct&400|}}<caption>Security Key Registration</caption></figure>+<figure>{{:institute_lorentz:ask-otp_mod.png?direct&400|}} {{:institute_lorentz:ilkey2_mod.png?direct&470|}}<caption>TOTP validation and Security Key Registration</caption></figure>
  
 ==== Step 3 ==== ==== Step 3 ====
institute_lorentz/2fa-key.1623058548.txt.gz · Last modified: by lenocil