MFA: I-MATH & DM3L
MFA I-MATH/DM3L services
Step 1 - configure MFA
Standard option via Web
The way you obtain this second factor code is what differentiates second factor methods.
Do this: Configure the sameOpen TOTP token in KeepassXC and an additional authenticator app. Also generate recovery codes, save them to KeepassXC as well. If you want, enable your imath account's email as a second factor as well. This can all be done at http:https://login.math.uzh.ch
See
Two-factor authentication
Wedaily use
See below for more detailsmobile and screenshots.
TypesEmail ofaccess secondnecessary.
factors
TOTP
(Time-basedRecovery OneCodes
TimeEmergency
Passwords)Stupid
Email codes
Recoverynew (static)codes.
A set of codes (usually 6) is shared between user and the server.
The web panel
This is the most user-friendly way to configure second factor and the only one to manage them later.
Otherwise,the most recently used method is selected as the second factor, but a different method can be selected.
Some points to consider:
(Althgouth several TOTPs can be configured (like in the screenshot) and any code is acceptedcurrently,currently.
SSH:Alternative terminalMFA setup option via SSH
If you have no clue what SSH is - skip this section, you won't miss anything.
The second factor is checked by SSH connections. If no second factor is configured yet, you will have a chance to configure one.
Note 1: You can select any text with a mouse and copy to the clipboard with Ctrl+Shift+C.C.
Note 2: Press Ctrl+C to cancel the authentication at any step.
- Recovery codes:
- TOTP: copy the secret to your authenticator (such as KeePassXC)
- Email: the email assigned to your account will be used
If second factor is already configured, you can use a code from any method. Type email to request an email code - an email is sent automatically only when it is the only method. 
Entering an invalid code does not break the authentication process: you will be given another chance to enter a correct code.
SSH/ThinLinc: GUI client
The authentication process is the same when a GUI client like !ThinLinc client is used. However, this method is least friendly for the initial configuration: the displayed text cannot be copied. Because of this we suggest other ways to configure the MFA initially.
1. Please login over ssh or with !ThinLinc. If no MFA device is configured yet, a selection of options is shown.


2. The easiest one to configure is email, but all three choices are possible:



3. If the second factor is configured, a list of methods is shown and you can use a code from any of them. Type email to request an email code - an email is sent automatically only when it is the only method.



Services used by MFA login.math.uzh.ch
Problems
I cannot configure email codes
Please contact us on support@math.uzh.ch . Possible causes:
- There is another account this with email configured as a second factor. This usually happens to secondary accounts only.
- You have already started to configure the email, but the address has not been verified. Your MFA configuration must be cleaned.
I have lost access to my device and cannot sign in anymore
Please contact us - we will generate a short-living one-time URL to let you access your account and reconfigure MFA.
I'm stuck at "Something went wrong! Please try again later."
This usually happens when you try to configure an email-based MFA for an email that is already in use. You have to delete cookies in your browser that are associated with the domain login.math.uzh.ch, then try to use another method as a second factor.






