Skip to main content

MFA: I-MATH & DM3L


MFA I-MATH/DM3L services

    Thinlinc - https://tl.math.uzh.ch Wiki - https://wiki.math.uzh.ch Hello - https://hello.math.uzh.ch SSH - ssh.math.uzh.ch More will follow (GIT, Nextcloud, R-Studio,...).

    Step 1 - configure MFA

    Standard option via Web

    The way you obtain this second factor code is what differentiates second factor methods.

    Do this: Configure the sameOpen TOTP token in KeepassXC and an additional authenticator app. Also generate recovery codes, save them to KeepassXC as well. If you want, enable your imath account's email as a second factor as well. This can all be done at http:https://login.math.uzh.ch

    See

    below Type Use Pro Contra TOTP Best for precise instructions. You got this!

    Two-factor authentication

    Wedaily use

    a centralized authentication server https://login.math.uzh.ch/ to manage MFAPossible configuration foron everymultiple I-MATHdevices account.- Ourno recommendationsingle device dependency:.
      TOTP SignApp innecessary. to https://login.math.uzh.ch/CreateEmail anIf initialTOTP setupis Oncenot loggedavailable in,Email addis atoften leastalready oneconfigured moreon authentication method.

      See below for more detailsmobile and screenshots.

      laptop.

      TypesEmail ofaccess secondnecessary. factors

      TOTP (Time-basedRecovery OneCodes TimeEmergency Passwords)Stupid
        simple. Codes are generatedquickly locally by a user's device (an authenticator app on a phone, KeePassXC, in-browser extension). A new code is generated every 30 seconds. Configuring TOTP requires to share a secret data between the server and the device: either by copying it directly or by scanning a QR code
        Email codes
          Codes are sent by the server to user's email and are valid several minutes. Onlyexhausted, the last email's code is valid. This method requires accesshas to thebe emailreservered account.to get
          Recoverynew (static)codes.
          codes

          • A set of codes (usually 6) is shared between user and the server.
          No expiration time. Not practical for every day use, but can be treated as a backup method.

          The web panel

          This is the most user-friendly way to configure second factor and the only one to manage them later.

            Please login to https://login.math.uzh.ch/. If no MFA device is configured yet, the page asks to configure one.

            || authentik-login.png  || authentik-configure-mfa.png ||



            1. Otherwise, the most recently used method is selected as the second factor, but a different method can be selected.

            || authentik-mfa-challenge.png || authentik-select-mfa.png ||

              Once logged-in you can create newSetup MFA methods or delete those already configured.
                Recommended: Setup a) TOTP, b) EMAIL and c) Recovery - ALL of them!authentik-setup-mfa.png

                Some points to consider:

                  Only one email-base MFA can be configured and the email can't be changed, it uses the email assigned to the account. This is your Primary UZH Email address. We recommend configuring only one TOTP, across several devices (by copying the code to e.g. KeepassXC and scanning the QR code with MS Authenticator).
                  • (Althgouth several TOTPs can be configured (like in the screenshot) and any code is accepted currently,currently.
                  we're unsure if this is intentional and suspect it might change.)

                  SSH:Alternative terminalMFA setup option via SSH

                  If you have no clue what SSH is - skip this section, you won't miss anything.

                  The second factor is checked by SSH connections. If no second factor is configured yet, you will have a chance to configure one.

                  Note 1: You can select any text with a mouse and copy to the clipboard with Ctrl+Shift+C.C.

                  Note 2: Press Ctrl+C to cancel the authentication at any step.

                  1. Recovery codes:
                    • mfa-ssh-setup-recovery-codes.png
                  2. TOTP: copy the secret to your authenticator (such as KeePassXC)
                    • mfa-ssh-setup-totp.png
                  3. Email: the email assigned to your account will be used
                    • mfa-ssh-setup-email.png

                  If second factor is already configured, you can use a code from any method. Type email to request an email code - an email is sent automatically only when it is the only method. mfa-ssh-challenge.png

                  Entering an invalid code does not break the authentication process: you will be given another chance to enter a correct code.

                  SSH/ThinLinc: GUI client

                  The authentication process is the same when a GUI client like !ThinLinc client is used. However, this method is least friendly for the initial configuration: the displayed text cannot be copied. Because of this we suggest other ways to configure the MFA initially.

                  1. Please login over ssh or with !ThinLinc. If no MFA device is configured yet, a selection of options is shown.

                    mfa-tl-login.png mfa-tl-choose-setup.png

                    2. The easiest one to configure is email, but all three choices are possible:

                      mfa-tl-setup-totp.png mfa-tl-setup-recovery-codes.png mfa-tl-setup-email.png

                      3. If the second factor is configured, a list of methods is shown and you can use a code from any of them. Type email to request an email code - an email is sent automatically only when it is the only method.

                        mfa-tl-login.png mfa-tl-challenge.png mfa-tl-email-challenge.png

                        Services used by MFA login.math.uzh.ch

                          Thinlinc - https://thinlinc.math.uzh.ch RocketChat - https://hello.math.uzh.ch Wikis - https://wiki.math.uhz.ch More will follow

                          Problems

                          I cannot configure email codes

                          Please contact us on support@math.uzh.ch . Possible causes:

                          1. There is another account this with email configured as a second factor. This usually happens to secondary accounts only.
                          2. You have already started to configure the email, but the address has not been verified. Your MFA configuration must be cleaned.

                          I have lost access to my device and cannot sign in anymore

                          Please contact us - we will generate a short-living one-time URL to let you access your account and reconfigure MFA.

                          I'm stuck at "Something went wrong! Please try again later."

                          This usually happens when you try to configure an email-based MFA for an email that is already in use. You have to delete cookies in your browser that are associated with the domain login.math.uzh.ch, then try to use another method as a second factor.