We are introducing two-factor authentication for certain services. This is an additional protection for your central user data. This prevents attackers from accessing user accounts, even if they know the password. The password is the first authentication factor and a temporary, single-use confirmation code is used as the second factor.
This second factor (TOTP token) usually requires a smartphone with a corresponding app that can be used to register this token. Another method is to register the token using the KeePassXC password manager on a PC.
Prerequisite
- A connection to the university's internal network or VPN (Eduroam does not count as internal network!)
1.2 Create a new database in KeePassXC
First click on "Create new database"
Create a database name and a description for your database and press "Next"
Press "Next" again
Create a password to protect your database. Then press "Done"
Now save the database to a location of your choice
1.3 Add a new root entry
To add a new root entry, select the "plus symbol" in the top menu bar.
Use a title of your choice and your TUBAF Login as "User name". You can leave the "Password" field empty. Then press "OK"
Now you have an entry in your list. Press the right mouse button on this entry, hover over "TOTP" with the mouse and select "Set up TOTP" in the tab that appears.
Do not close the KeePassXC window that appears!
2. Two-factor authentication
Follow the link and log in with your TUBAF login: https://2fa.tu-freiberg.de/ (only accessible from the internal network and VPN!)
Press "Enroll Token" on the left-hand side of the screen.
Press "Enroll Token" again, but this time the button in the center of the screen.
Right-click on the link in the text ("Click here or scan ...") and select "Copy link address".
Paste the link into a text editor or Word and copy only the the code after "secret=" up to but excluding "&period". Paste it into KeePassXC as a secret key and click "OK".
Right-click on the entry in your list, click on the TOTP tab and left-click on Show TOTP.
You can see how the "Time-based password" window opens. Copy the code within the displayed time.
Finally, enter the number combination from KeePassXC on the 2FA website under the QR code. (There is no space between the numbers, the numbers must be entered one after the other)
After successful entry, your token is verified.