Set up MFA KeePassXC as an alternative App (English)
Set up MFA via KeePassXC as an alternative application
Attention:
If a computer is used by several people, it is essential that each user has their own local user account.
No MFA login may be set up with a technical account.
Please note!
If you want to set up Passkey on another end device, first log in to the IAM portal on the end device on which you have already rolled up Passkey. Generate the confirmation code. And follow the instructions in the section Create Passkesy on antoher device on the new end device.
Passkey roll out
Create passkey on the first device
To roll out the passkey on your first computer, open the website https://getpasskey.iam.uni-bamberg.de/ with your BA-Number and the corresponding password.
After successfully registering, follow the instructions starting from the Roll out token.
Figure 1: Getpasskey registration via Shibboleth
Create passkey on another device
First log in to the IAM portal on the end device on which you have already rolled up Passkey. Generate the confirmation code.
The code matrix and the confirmation code should be displayed for selection as a registration option.
Please enter the previously copied confirmation code in the field provided on the Getpasskey page and click on Check.
Figure 2: Logging in to Passkey's Uni-Bamberg through Shibboleth
Roll out token
Select the menu item Roll out token.
As you have to roll out a passkey for each device, it is advisable to define a description.
Therefore, assign an appropriate name under Description, such as “Windows login”. Confirm this with Roll out token.
The temporary pop-up message “getpasskey.iam.uni-bamberg.de requests extended information...” will then be displayed. Please select the “Allow” option promptly. Otherwise the token will be deactivated and deleted.
Figure 3: Rolling out the token and confirming the notification
Login with passkey in the web browser
Please make sure that you first use your BA number and password when logging in to the Firefox web browser.
Figure 4: Login via Shibboleth with BA number
Figure 5: Confirm authentication in KeePassXC Desktop
Then confirm the process in KeepassXC by clicking the Authorization button.
If the passkey has been successfully stored, you will receive the message The token has been rolled out in the next window.
Figure 6: Passkey successfully rolled out
Manage passkey
Passkeys are managed via the IAM-Portal (iam.uni-bamberg.de). You can deactivate or delete your passkeys under the menu item Manage Passkeys. Please note that the corresponding passkey must be deleted immediately if the device is lost or stolen.