<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>2fa on C&amp;CZ News</title>
    <link>https://cncz.science.ru.nl/en/tags/2fa/</link>
    <description>Recent content in 2fa on C&amp;CZ News</description>
    <generator>Hugo -- gohugo.io</generator>
    <language>en</language>
    <lastBuildDate>Wed, 11 Jun 2025 00:00:00 +0200</lastBuildDate><atom:link href="https://cncz.science.ru.nl/en/tags/2fa/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>DIY functionality only available with two-factor authentication</title>
      <link>https://cncz.science.ru.nl/en/news/2025-06-11-diy-2fa-restriction/</link>
      <pubDate>Wed, 11 Jun 2025 00:00:00 +0200</pubDate>
      <author>Miek Gieben</author>
      <guid>https://cncz.science.ru.nl/en/news/2025-06-11-diy-2fa-restriction/</guid>
      <description>&lt;p&gt;As most Science users have enabled their &lt;a href=&#34;https://cncz.science.ru.nl/en/news/2025-05-14-2fa-services&#34;&gt;two-factor&lt;/a&gt; authentication, we are
now going to restrict DIY functionality for accounts &lt;em&gt;without&lt;/em&gt; a second factor. If you have not enabled a second factor, you can:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Login into DIY&lt;/li&gt;
&lt;li&gt;Set a password&lt;/li&gt;
&lt;li&gt;Enable your second factor&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;All other functionally is disabled and will lead to an &amp;lsquo;Insufficient access&amp;rsquo; error. In subsequent versions of
the DIY software we will (further) hide actions and listing that you will not be able to use.&lt;/p&gt;</description>
    </item>
    
    <item>
      <title>Using multifactor authentication for Science services</title>
      <link>https://cncz.science.ru.nl/en/news/2025-05-14-2fa-services/</link>
      <pubDate>Tue, 20 May 2025 00:00:00 +0200</pubDate>
      <author></author>
      <guid>https://cncz.science.ru.nl/en/news/2025-05-14-2fa-services/</guid>
      <description>&lt;blockquote&gt;
&lt;h1 id=&#34;update-2025-05-20&#34;&gt;Update 2025-05-20&lt;/h1&gt;
&lt;p&gt;This has been activated around 11 &amp;lsquo;o clock.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;On May the 20th we have enabled mandatory multifactor authentication for the following services:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&#34;https://diy.science.ru.nl&#34; target=&#34;_blank&#34;&gt;DIY&lt;/a&gt; web site.&lt;/li&gt;
&lt;li&gt;&lt;a href=&#34;https://roundcube.science.ru.nl&#34; target=&#34;_blank&#34;&gt;Roundcube&lt;/a&gt;, for reading mail.&lt;/li&gt;
&lt;li&gt;SSH from the internet to public servers, like the lilos.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Below you can read how you can log in for each service.&lt;/p&gt;
&lt;h2 id=&#34;diy&#34;&gt;DIY&lt;/h2&gt;
&lt;p&gt;Enter your Science login name, your password and the TOTP code from your authenticator app.&lt;/p&gt;
&lt;p&gt;If you have configured a Yubi key with us, you can also use the Yubi key&amp;rsquo;s OTP.&lt;/p&gt;</description>
    </item>
    
    <item>
      <title>Authenticator Apps</title>
      <link>https://cncz.science.ru.nl/en/howto/diy/authenticator/</link>
      <pubDate>Tue, 08 Apr 2025 10:00:00 +0000</pubDate>
      <author>Simon Oosthoek</author>
      <guid>https://cncz.science.ru.nl/en/howto/diy/authenticator/</guid>
      <description>&lt;h1 id=&#34;totp-authenticator-apps&#34;&gt;TOTP Authenticator Apps&lt;/h1&gt;
&lt;p&gt;To generate a 6-digit code for two-factor login verification, you’ll need an app. Below is a list of apps you can use for this purpose—but if none of these suit you, there are plenty of other compatible options out there.&lt;/p&gt;
&lt;div&gt;&lt;svg width=&#34;0&#34; height=&#34;0&#34; display=&#34;none&#34; xmlns=&#34;http://www.w3.org/2000/svg&#34;&gt;&lt;symbol id=&#34;tip-notice&#34; viewBox=&#34;0 0 512 512&#34; preserveAspectRatio=&#34;xMidYMid meet&#34;&gt;&lt;path d=&#34;M504 256c0 136.967-111.033 248-248 248S8 392.967 8 256 119.033 8 256 8s248 111.033 248 248zM227.314 387.314l184-184c6.248-6.248 6.248-16.379 0-22.627l-22.627-22.627c-6.248-6.249-16.379-6.249-22.628 0L216 308.118l-70.059-70.059c-6.248-6.248-16.379-6.248-22.628 0l-22.627 22.627c-6.248 6.248-6.248 16.379 0 22.627l104 104c6.249 6.249 16.379 6.249 22.628.001z&#34;/&gt;&lt;/symbol&gt;&lt;symbol id=&#34;note-notice&#34; viewBox=&#34;0 0 512 512&#34; preserveAspectRatio=&#34;xMidYMid meet&#34;&gt;&lt;path d=&#34;M504 256c0 136.997-111.043 248-248 248S8 392.997 8 256C8 119.083 119.043 8 256 8s248 111.083 248 248zm-248 50c-25.405 0-46 20.595-46 46s20.595 46 46 46 46-20.595 46-46-20.595-46-46-46zm-43.673-165.346l7.418 136c.347 6.364 5.609 11.346 11.982 11.346h48.546c6.373 0 11.635-4.982 11.982-11.346l7.418-136c.375-6.874-5.098-12.654-11.982-12.654h-63.383c-6.884 0-12.356 5.78-11.981 12.654z&#34;/&gt;&lt;/symbol&gt;&lt;symbol id=&#34;warning-notice&#34; viewBox=&#34;0 0 576 512&#34; preserveAspectRatio=&#34;xMidYMid meet&#34;&gt;&lt;path d=&#34;M569.517 440.013C587.975 472.007 564.806 512 527.94 512H48.054c-36.937 0-59.999-40.055-41.577-71.987L246.423 23.985c18.467-32.009 64.72-31.951 83.154 0l239.94 416.028zM288 354c-25.405 0-46 20.595-46 46s20.595 46 46 46 46-20.595 46-46-20.595-46-46-46zm-43.673-165.346l7.418 136c.347 6.364 5.609 11.346 11.982 11.346h48.546c6.373 0 11.635-4.982 11.982-11.346l7.418-136c.375-6.874-5.098-12.654-11.982-12.654h-63.383c-6.884 0-12.356 5.78-11.981 12.654z&#34;/&gt;&lt;/symbol&gt;&lt;symbol id=&#34;info-notice&#34; viewBox=&#34;0 0 512 512&#34; preserveAspectRatio=&#34;xMidYMid meet&#34;&gt;&lt;path d=&#34;M256 8C119.043 8 8 119.083 8 256c0 136.997 111.043 248 248 248s248-111.003 248-248C504 119.083 392.957 8 256 8zm0 110c23.196 0 42 18.804 42 42s-18.804 42-42 42-42-18.804-42-42 18.804-42 42-42zm56 254c0 6.627-5.373 12-12 12h-88c-6.627 0-12-5.373-12-12v-24c0-6.627 5.373-12 12-12h12v-64h-12c-6.627 0-12-5.373-12-12v-24c0-6.627 5.373-12 12-12h64c6.627 0 12 5.373 12 12v100h12c6.627 0 12 5.373 12 12v24z&#34;/&gt;&lt;/symbol&gt;&lt;/svg&gt;&lt;/div&gt;&lt;div class=&#34;notice info&#34; &gt;
&lt;p class=&#34;first notice-title&#34;&gt;&lt;span class=&#34;icon-notice baseline&#34;&gt;&lt;svg&gt;&lt;use href=&#34;#info-notice&#34;&gt;&lt;/use&gt;&lt;/svg&gt;&lt;/span&gt;Info&lt;/p&gt;</description>
    </item>
    
    <item>
      <title>Continued rollout of multifactor authentication for Science accounts</title>
      <link>https://cncz.science.ru.nl/en/news/2025-03-31_2fa/</link>
      <pubDate>Mon, 07 Apr 2025 00:00:00 +0200</pubDate>
      <author></author>
      <guid>https://cncz.science.ru.nl/en/news/2025-03-31_2fa/</guid>
      <description>&lt;p&gt;On the &lt;strong&gt;20&lt;sup&gt;th&lt;/sup&gt;
 of May 2025&lt;/strong&gt; we are enabling 2FA (second-factor-authentication) on the C&amp;amp;CZ services: DIY, Roundcube and SSH on the &lt;a href=&#34;https://cncz.science.ru.nl/en/howto/hardware-servers/#linux-login-servers&#34;&gt;login servers&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;In this article you can find information on this roll-out and how to activate 2Fa on your Science account.&lt;/p&gt;
&lt;p&gt;As mentioned in an &lt;a href=&#34;https://cncz.science.ru.nl/en/news/2025-01-15_2fa/&#34;&gt;earlier news item&lt;/a&gt;, we&amp;rsquo;ve finished the tests and reached the following conclusions:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Anyone with a Science account can enable 2FA in DIY using &lt;a href=&#34;https://cncz.science.ru.nl/en/howto/diy/#2fa&#34; target=&#34;_blank&#34;&gt;this procedure&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;For about 6 weeks you can enable 2FA in DIY. You must have activated 2FA by the &lt;strong&gt;20&lt;sup&gt;th&lt;/sup&gt;
 of May 2025&lt;/strong&gt; if you want to use: DIY, Roundcube or SSH on the &lt;a href=&#34;https://cncz.science.ru.nl/en/howto/hardware-servers/#linux-login-servers&#34;&gt;login servers&lt;/a&gt;.&lt;/p&gt;</description>
    </item>
    
    <item>
      <title>Multifactor authentication for Science accounts</title>
      <link>https://cncz.science.ru.nl/en/news/2025-01-15_2fa/</link>
      <pubDate>Mon, 27 Jan 2025 00:00:00 +0100</pubDate>
      <author></author>
      <guid>https://cncz.science.ru.nl/en/news/2025-01-15_2fa/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://cncz.science.ru.nl/en/news/2024-12-11_science-services-vpn/&#34;&gt;At the end of last year&lt;/a&gt; we&amp;rsquo;ve promised an update on how
we are planning to make access to our services more secure. In this post we expand on those plans.&lt;/p&gt;
&lt;p&gt;In short: we are going to deploy 2FA on Science accounts and make it &lt;em&gt;mandatory&lt;/em&gt; for services that are
reachable from the internet.&lt;/p&gt;
&lt;p&gt;How this all works from an organizational standpoint is, at this point, not complete clear yet. Do
we need a &amp;ldquo;in-person&amp;rdquo; &lt;em&gt;vetting&lt;/em&gt; procedure? Or do we allow users to enable this themselves in DIY?
Ideas on this will surface after the test period.&lt;/p&gt;</description>
    </item>
    
  </channel>
</rss>
