meta data for this page
  •  

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
account:mfa [2026/06/02 08:57] hkunzaccount:mfa [2026/06/03 14:35] (current) hkunz
Line 1: Line 1:
-====== Two-Factor Authentication @ IfI (2FA) ======+====== 2-Factor Authentication @ IfI (2FA) ======
  
 {{indexmenu_n>10}} {{indexmenu_n>10}}
Line 11: Line 11:
 <WRAP danger> <WRAP danger>
  
-Besides the instructions on how to setup the tokens, this page is still under heavy construction work.+If you feel completely overwhelmed and/or do not understand a word, we suggest to to dive in first with enrolling a PUSH or a TOTP token (scroll down for the step-by-step guides) and read then read the rest of this document afterwardsChances are good, that things are much clearer then :)
  
 </WRAP> </WRAP>
Line 40: Line 40:
       * **Keep your hardware token / yubikey in your pocket**. If you just keep it plugged to your laptop, anyone can use it who gets hold of your laptop. If you absolutely want to keep the yubikey plugged in, buy a (more expensive) **yubikey with fingerprint authentication**  and/or use **PIN protection**  for the stored passkeys.       * **Keep your hardware token / yubikey in your pocket**. If you just keep it plugged to your laptop, anyone can use it who gets hold of your laptop. If you absolutely want to keep the yubikey plugged in, buy a (more expensive) **yubikey with fingerprint authentication**  and/or use **PIN protection**  for the stored passkeys.
       * If you absolutely must store your 2nd factor in your password manager, make sure that you have **protected your password manager **  (auto lock, strong (secret) passphrase to unlock it). And also make sure that your laptop is always locked (screen lock) when you leave it unsupervised (i.e. if you leave the office shortly, etc.). Please note: **these two things are absolutely essential anyhow**.       * If you absolutely must store your 2nd factor in your password manager, make sure that you have **protected your password manager **  (auto lock, strong (secret) passphrase to unlock it). And also make sure that your laptop is always locked (screen lock) when you leave it unsupervised (i.e. if you leave the office shortly, etc.). Please note: **these two things are absolutely essential anyhow**.
-      * **Enable locking for the authenticator app**  (PrivacyIDEA authenticator / Google/MS authenticator) holding e.g. PUSH and TOTP tokens, such that even if someone gains access to your phone cannot use it without **fingerprint**  or **PIN**  (in addition to locking your mobile phone).+      * **Enable locking for the authenticator app**  (PrivacyIDEA / Google / MS authenticator) holding e.g. PUSH and TOTP tokens, such that even if someone gains access to your phone cannot use it without **fingerprint**  or **PIN**  (in addition to locking your mobile phone).
 ===== Overview of Token Types ===== ===== Overview of Token Types =====
  
 ^Token type  ^Application / Hardware Token  ^Devices  ^Security notes (see also Best Practices)  | ^Token type  ^Application / Hardware Token  ^Devices  ^Security notes (see also Best Practices)  |
 ^PUSH  |PrivacyIDEA authenticator  |mobile phone  |enable locking  | ^PUSH  |PrivacyIDEA authenticator  |mobile phone  |enable locking  |
-^OTP  |PrivacyIDEA/MS/Google/etc. authenticator  |mobile phone / laptop  |enable locking  |+^OTP  |PrivacyIDEA / MS / Google / etc. authenticator  |mobile phone / laptop  |enable locking  |
 ^Passkey  |stored on Yubikey  |yubikey  |enable PIN  | ^Passkey  |stored on Yubikey  |yubikey  |enable PIN  |
 ^Passkey  |stored in your password manager  |mobile phone / laptop  |enable locking  | ^Passkey  |stored in your password manager  |mobile phone / laptop  |enable locking  |
Line 53: Line 53:
  
   * enable locking ⇒ make sure that the authenticator app / password manager is locked (automatically) and needs a fingerprint or a PIN before usage.   * enable locking ⇒ make sure that the authenticator app / password manager is locked (automatically) and needs a fingerprint or a PIN before usage.
-  * remove Yubikey ⇒ Yubikeys without fingerprint or PIN protection need to be removed from the laptop when not used and store in a secure location, i.e. together with your other keys in your pocket. otherwise anyone getting hold of the laptop can also access your 2nd factor(s). +  * remove Yubikey ⇒ Yubikeys without fingerprint or PIN protection need to be removed from the laptop when not used and stored in a secure location, i.e. together with your other keys in your pocket. Alternatively use Yubikey with fingerprint sensor.
-  * Yubikey with fingerprint ⇒ do not need to be stored in a secure location.+
  
 ===== Enrolling and Using 2nd Factors / Tokens ===== ===== Enrolling and Using 2nd Factors / Tokens =====
Line 66: Line 65:
 To setup the PUSH token, do the following: To setup the PUSH token, do the following:
  
-  - Open [[https://pi.ifi.uzh.ch|PrivacyIDEA]], click on //Enroll Token//. The //PUSH//  token should be selected by default.+  - Open [[https://pi.ifi.uzh.ch|pi.ifi.uzh.ch]], click on //Enroll Token//. The //PUSH//  token should be selected by default.
   - Install the //PrivacyIDEA Authenticator//  on your phone. You can use the QR codes provided to do that.   - Install the //PrivacyIDEA Authenticator//  on your phone. You can use the QR codes provided to do that.
   - Add a //Description//  (to distinguish your tokens easily) and click //Enroll Token//.   - Add a //Description//  (to distinguish your tokens easily) and click //Enroll Token//.
Line 75: Line 74:
 <WRAP safety> <WRAP safety>
  
-We strongly recommend to protect/lock your tokens in the PrivbacyIDEA Authenticator app. To do so, swipe right on the token and choose lock.+We strongly recommend to protect/lock your tokens in the PrivacyIDEA Authenticator app. To do so, swipe right on the token and choose lock.
  
 </WRAP> </WRAP>
Line 89: Line 88:
 For all Authenticator apps the procedure is basically the same: For all Authenticator apps the procedure is basically the same:
  
-  - Open [[https://pi.ifi.uzh.ch|PrivacyIDEA]], click on //Enroll Token //and choos the //TOTP//  token.+  - Open [[https://pi.ifi.uzh.ch|pi.ifi.uzh.ch]], click on //Enroll Token //and choos the //TOTP//  token.
   - If necessary, install the //PrivacyIDEA Authenticator//  on your phone. You can use the QR codes provided to do that.   - If necessary, install the //PrivacyIDEA Authenticator//  on your phone. You can use the QR codes provided to do that.
   - Add a //Description//  (to distinguish your tokens easily) and click //Enroll Token//.   - Add a //Description//  (to distinguish your tokens easily) and click //Enroll Token//.
Line 98: Line 97:
 <WRAP safety> <WRAP safety>
  
-We strongly recommend to protect/lock your tokens in the PrivbacyIDEA Authenticator app. To do so, swipe right on the token and choose lock. If you use another Authenticator app, please also make sure that is used some kind of authentication (fingerprint) before usage.+We strongly recommend to protect/lock your tokens in the PrivacyIDEA Authenticator app. To do so, swipe right on the token and choose lock. If you use another Authenticator app, please also make sure that is used some kind of authentication (fingerprint) before usage.
  
 </WRAP> </WRAP>
Line 111: Line 110:
  
   - Insert the Yubikey, start the //YubiKey Authenticator//  and go to //Passkeys//. Unlock the passkey store with your PIN, or set a PIN if you have not done that yet.   - Insert the Yubikey, start the //YubiKey Authenticator//  and go to //Passkeys//. Unlock the passkey store with your PIN, or set a PIN if you have not done that yet.
-  - Open [[https://pi.ifi.uzh.ch|PrivacyIDEA]], click on //Enroll Token//  and choose the token type //Passkey//  add a //Description//  (to distinguish your tokens easily) and click //Enroll Token//.+  - Open [[https://pi.ifi.uzh.ch|pi.ifi.uzh.ch]], click on //Enroll Token//  and choose the token type //Passkey//  add a //Description//  (to distinguish your tokens easily) and click //Enroll Token//.
   - Depending on your environment, your password manager might pop-up and ask to store the passkey. Do not store the passkey there, instead close/cancel that dialog. A new dialog box should pop up, asking you for the PIN of your Yubikey passkey store. Enter the pin and follow the instructions, i.e. press the button on the Yubikey.   - Depending on your environment, your password manager might pop-up and ask to store the passkey. Do not store the passkey there, instead close/cancel that dialog. A new dialog box should pop up, asking you for the PIN of your Yubikey passkey store. Enter the pin and follow the instructions, i.e. press the button on the Yubikey.
   - Check the //YubiKey Authenticator//  for the just saved passkey.   - Check the //YubiKey Authenticator//  for the just saved passkey.
Line 124: Line 123:
   - Assign a //public ID//  or simply use the //serial//  (click the diamonds). Generate the //Private ID//  and the //Secret key//  (using the circular arrows).   - Assign a //public ID//  or simply use the //serial//  (click the diamonds). Generate the //Private ID//  and the //Secret key//  (using the circular arrows).
   - Copy the //Secret key//  and click //Save//.   - Copy the //Secret key//  and click //Save//.
-  - Open [[https://pi.ifi.uzh.ch|PrivacyIDEA]], click on //Enroll Token//  and choose the token type //Yubikey AES mode//.+  - Open [[https://pi.ifi.uzh.ch|pi.ifi.uzh.ch]], click on //Enroll Token//  and choose the token type //Yubikey AES mode//.
   - Paste the //Secret key//  (copied from the YubiKey Authenticator) to the// OTP Key//  field (PrivacyIDEA), add a //Description//  (to distinguish your tokens easily) and click //Enroll Token//.   - Paste the //Secret key//  (copied from the YubiKey Authenticator) to the// OTP Key//  field (PrivacyIDEA), add a //Description//  (to distinguish your tokens easily) and click //Enroll Token//.
  
Line 134: Line 133:
  
 </WRAP> </WRAP>
 +
 +===== Special Case: SSH and sudo =====
 +
 +We enforce 2FA also for SSH and sudo. For technical reasons, it is not possible authenticate over keycloak and therefore there is no single sign-on (SSO) for SSH and sudo. This means, that you will have to present your 2nd factor each time you login (SSH) or use sudo. When using SSH and sudo a lot, this can become painful, so there are two mechanisms in place to mitigate this situation a bit:
 +
 +  * if you use **key-based authentication**  with SSH, you will neither need to enter your password, nor a 2nd factor. Check e.g. here on how to setup key-based authentication. **Important: check the notes below**.
 +  * sudo has a **cache time of 2hrs**, which means a sudo session will ask for your password and 2nd factor when you use it the first time, but then only again if the session was idle for 2hrs.
 +
 +<WRAP danger>
 +
 +**Always protect your ssh (private) key with a passphrase**. **Never**  use a ssh keys with an empty passphrase, as everybody that gets hold on your keys could use them.
 +
 +</WRAP>
 +
 +<WRAP notice>
 +
 +Of course you want to avoid typing the passphrase each time you login. you can do that using **ssh-agent**. Here, you can unlock your (private) key once you login to your laptop/desktop and use it without passphrase (until you logout or shutdown your laptop/desktop).
 +
 +</WRAP>
 +
 +To setup key-based authentication and use the ssh-agent, please check the following tutorials (if necessary):
 +
 +  * [[https://www.digitalocean.com/community/tutorials/ssh-essentials-working-with-ssh-servers-clients-and-keys|SSH Essentials: Working with SSH Servers, Clients, and Keys]] (digital ocean)
 +  * [[https://www.digitalocean.com/community/tutorials/how-to-create-ssh-keys-with-openssh-on-macos-or-linux|Create SSH Keys with OpenSSH on macOS, Linux, or Window]]s (digital ocean)
 +
 +The second tutorial also explains how to use the ssh-agent.