these instructions - Yale Center for Research Computing

2FactorLoginSetupInstructions
Two‐FactorAuthentication
Table of Contents Overview..................................................................................................................................................1
OverviewofTwo‐FactorAuthenticationSetup..........................................................................1
SetupInstructions.................................................................................................................................2
Software‐basedauthenticatorsetup.........................................................................................................2
eTokenPASSsetup............................................................................................................................................7
TokenUserSelf‐Validation................................................................................................................9
Logintothecluster.............................................................................................................................10
Troubleshootingandsupport.........................................................................................................11
Overview InordertoimprovesecurityontheHPCclusters,ITSisinstallingatwo‐factorloginsystem
ontheloginnodes.Two‐factorloginrequirestheusertoprovidetwopiecesofinformation
inordertossh:theirnetidpassword,andarandom6digitnumberthatisgeneratedviaa
smartphoneapporhardwarefob.
Beforeyoucanusetwo‐factorauthentication,youwillneedtosetuptheapponyour
smartphone,oracquireandregisterahardwarefob.Thisdocumentdescribesthose
processes,andalsoexplainshowtorequestsupportifyourunintoproblems.
Overview of Two‐Factor Authentication Setup 1. Selectthemethodforgeneratingtokens:
a. Software‐basedauthenticator(smartphoneapplication)
b. Hardwarebasedauthenticator(keyfob).Pleaseonlyrequestafobifyoudo
nothaveanappropriatesoftwaredevice.
2. Ifyouneedahardwarefob,[email protected]
[email protected].
3. Completethesetup:
a. Software‐based:downloadtheSafenetMobilePASSapplicationfrom:
i. iTunesStore‐AppleiPhone,iPodTouch,oriPad
ii. GooglePlayStore‐Android
iii. BlackberryStore–Blackberry
1
2Factor LoginSetup
pInstructio
ons
b. Hardw
warefob:y
youcanpick
kupthehard
dwareauth
henticatorattoneoftwo
o
locatiionsaround
dcampus.
1. CentralCampu
us:AKW21
10(ComputeerScienceD
Departmentt).
Pleeasecall432
2‐1220tosetupatimee.
2. Co
omputerSup
pportCenteer–MedicallCampus
htttp://its.yalee.edu/centeers/help‐and
d‐support‐ccenters/wallk‐
in‐‐computer‐ssupport‐135
5‐college
uthenticatorrbyfollowin
ngthestepssdetailedbeelow.
4. Enrolltheau
5. Testtheauth
T
henticatorb
byusingtheself‐validattionwebpaage(seebelo
ow).
6. Usetheappo
U
orfobtogenerateyourr6digitnum
mber,which
hwillformp
partofyourr
passwordwh
hensshingttotheclusteer.
Setup Instructio
ons Software‐based au
uthenticato
or setup Withasm
martphoneinhandand
dwhileinfrrontoftheccomputer,p
pleasefollow
wthesteps
belowto
osetupaMobilePASSssofttoken.S
Sincestepswillneedto
obetakeno
onbotha
smartph
honeandaccomputer,th
heinstructio
onsbelowaarecolor‐co
oded:instructionsinblaack
aretobeeperformed
donacomp
puterandinstructionsinbluearettobeperforrmedona
smartph
hone.
1. Smartphone
e–DownloaadtheSafen
netmobileP
Passapplicationfromyourappsto
ore.
Oncedownlo
O
oaded,launcchtheappliication.
2. Computer–
C
Onyourco
omputernav
vigatetohtttps://tfa.yalle.edu/samservice.
3. Computer–
C
Loginusinggyale\netid
dastheuserrname,andyournetidpasswordaas
th
hepassword
d.
4. Computer–
C
IntheSafen
netAuthentticationMan
nagerSelfSServiceCentter,clickon
“E
Enrollanew
wMobilePA
ASStoken.”
2
2Factor LoginSetup
pInstructio
ons
C
Enteranop
ptionalnick
knameforth
hesmartpho
onetoken.Ifyouhave
5. Computer–
multipleMob
m
bilePassacccounts,youmaywantttoconsidernamingthemtobeableto
betterdistinguishtheminsidetheaapplication.Ifyoudon
notwanttoentera
nickname,leeavethedefaault“MobileePASS”nam
me.Pleasecclickonsubm
mittoadvan
nce
to
othenextsttepintheprrocess,whicchwilldisp layaspecifficpolicystrringthatneeeds
to
obeentered
dintothesm
martphoneapplication .
3
2Factor LoginSetup
pInstructio
ons
e–(Onceth
heSafeNetM
MobilePass application
nislaunched
d)clickon““My
6. Smartphone
Token1”
T
7. Smartphone
e–Clickon“ManualEn
nrollment”
4
2Factor LoginSetup
pInstructio
ons
e–EnterthepolicystriingwhichissdisplayedontheSafeNet
8. Smartphone
Authenticati
A
onManagerrandclickccontinue.
C
–Anactivatiioncodewiillbedisplayyedonthessmartphonee.Takethiss
9. Computer–
co
odeandinp
putitintoth
heSafeNetA
AuthenticatiionManagerconsole.O
Oncethatis
entered,click
ksubmit.
5
2Factor LoginSetup
pInstructio
ons
6
2Factor LoginSetup
pInstructio
ons
C
Iftheactivaationcodew
wasentered
dsuccessfullly,youwillreceiveanotice
10. Computer–
saayingthat“TheMobilePASStoken
nissuccessfu
fullyenrolleed".
11. Smartphone
e–Clickcon
ntinue.Ontthenextscreeenyourpaasscode(sixx‐digitnumb
ber)
willbedispla
w
ayed.
eTokenP
PASS setup Pleasefo
ollowthesteepsbelowttosetupaneeTokenPassshardware fob.
1. Navigatetoh
N
https://tfa.y
yale.edu/samservice.
2. Logintothesamservice,usingyale\\netidasth
heusernamee,andyournetidpassw
word
asthepassw
word.
7
2Factor LoginSetup
pInstructio
ons
PToken”
3. Select“EnrolllanewOTP
TokenPASSShardwareaauthenticattor
4. EntertheserrialnumberrfromtheeT
U
tofthesucccessmessagge,youreTookenPASSso
oftwaretok
kenhasbeen
n
5. Uponreceipt
enrolledand
dcannowbeeused.
8
2Factor LoginSetup
pInstructio
ons
Token User Selff‐Validatiion Onceeith
heraMobilePASSoreT
TokenPASSdeviceissu
uccessfullyeenrolled,an
newoptionon
theself‐sservicemainscreenwiillbepresen
nted:“ValidaatetheOTP
Ptoken.”
kenthatyou
uwouldlikeetovalidateefromtheccolumnontthelefthand
d
1. Selectthetok
siideofthepaage.(Ifausseronlyhasonetoken, noactionissneededinthisstep)
OTP(six‐digitpasscodeplusNetIDpassword)
2. EnteryourO
9
2Factor LoginSetup
pInstructio
ons
O
P(passcodee+NetIDPaassword)isenteredsucccessfully,yyouwillreceeive
3. OncetheOTP
amessageth
hat“TheOTP
Ptokenisv
validated.”
ormessageisreceived,,pleasecon
ntacttheITSSHelpdeskaat203‐432‐‐9000.
Ifanerro
Login tto the clu
uster Onceyou
urdeviceisregistered,youwillbeeabletouseeittologintotheclustter.Useyou
ur
netidastheusernam
me,andthegeneratedsixdigitnum
mber+yournetidpassw
wordasthee
passworrd.Forexam
mple:ifyourrrandomlygeneratedp
passcodeiss123456an
ndyourNetIID
passworrdisPassw0
0rd,thepasswordwouldbe12345
56Passw0rd
d.Notethattthe6digit
numberisonlyvalid
dforabout1minute,afterwhichyyouwillneeedtogeneraateanother
number..
10
2FactorLoginSetupInstructions
Troubleshooting and support 1. First,testtherandomkeygeneration.Gotohttps://tfa.yale.edu/samserviceand
selectthe“ValidateOTPoption.”Enteryournetidandpasscode+netidpasswordas
describedabove.
2. Ifyouareunsuccessful,calltheITShelpdeskat203‐432‐9000.
11