We are introducing two-factor authentication for certain services. This is an additional protection for your central user data. This prevents attackers from accessing user accounts, even if they know the password. The password is the first authentication factor and a temporary, single-use confirmation code is used as the second factor.

This second factor (TOTP token) usually requires a smartphone with a corresponding app that can be used to register this token. Another method is to register the token using the KeePassXC password manager on a PC.

Prerequisite

  • A connection to the university's internal network or VPN (Eduroam does not count as internal network!)

1. Install KeePassXC

1.1 Select the software for your operating system

Install KeePassXC on the device of your choice.

Image
Start screen of the KeePassXC application

1.2 Create a new database in KeePassXC

First click on "Create new database"

Image
Erstellen einer neuen Datenbank

Create a database name and a description for your database and press "Next"

Image
Konfigurieren der Verschlüsselungs-Einstellungen

Press "Next" again

Image
Erstellen eines Passworts für die Datenbank

Create a password to protect your database. Then press "Done"

Image
Hinzufügen eines neuen Root-Eintrages

Now save the database to a location of your choice

1.3 Add a new root entry

To add a new root entry, select the "plus symbol" in the top menu bar.

Image
Einloggen mittels zentraler Nutzerdaten

Use a title of your choice and your TUBAF Login as "User name". You can leave the "Password" field empty. Then press "OK"

Image
Eingabe TOTP Schlüssel

Do not close the KeePassXC window that appears!

2. Two-factor authentication

Image
Ausrollen des Verifizierungs-Token

Follow the link and log in with your TUBAF login: https://2fa.tu-freiberg.de/ (only accessible from the internal network and VPN!)

Press "Enroll Token" on the left-hand side of the screen.

Image
Generierung des neuen Tokens

Press "Enroll Token" again, but this time the button in the center of the screen.

Image
Copy Token URI

Right-click on the link in the text ("Click here or scan ...") and select "Copy link address".

Paste the link into a text editor or Word and copy only the the code after "secret=" up to but excluding "&period". Paste it into KeePassXC as a secret key and click "OK".

Image
Anzeigen des neu konfigurierten TOTP-Token

Right-click on the entry in your list, click on the TOTP tab and left-click on Show TOTP.

Image
30 Sekunden-Vorschau auf den sich erneuernden TOTP-Token

You can see how the "Time-based password" window opens. Copy the code within the displayed time.

Image
Verifizieren des Token bei der Zwei-Faktor-Authentifizierung

Finally, enter the number combination from KeePassXC on the 2FA website under the QR code. (There is no space between the numbers, the numbers must be entered one after the other)

After successful entry, your token is verified.