Securing I-MATH account with MFA

There are two different options to secure access:

  1. SSH private/public keys
  2. MFA OTP authentication

Both can be configured in parallel and it is useful to configure both.

SSH via private/public key

SSH via Time-based One-Time Password (TOTP)

The second factor is required to access the ssh server if there is no ssh private/public key setup.

TOTP login process

Preparation: Configuring MFA via TOTP

Warning Use with care: running the command will overwrite any current configuration, invalidating your current authenticating device!

Restoring/regenerating recovery codes

The recovery codes can be regenerated with authenticator refresh and displayed with authenticator show codes.

Late configuration of authenticator apps

If you no longer have the QR code, you can still configure most authenticator apps with the OTP secret. It is printed with the command authenticator show secret.