<?xml version="1.0" encoding="utf-8"?>







    <rss version="2.0"
         xmlns:content="http://purl.org/rss/1.0/modules/content/"
         xmlns:atom="http://www.w3.org/2005/Atom"
         xmlns:media="http://search.yahoo.com/mrss/">
        <channel>
            
                
                    <ttl>60</ttl>
                    <title>University of Bremen - Two-Factor Authentication</title>
                    <link>https://www.uni-bremen.de/en/dezernat8/basisdienste/other-it-services/security-and-pki/two-factor-authentication</link>
                    <description>[Translate to English:] Dokumentation der Zwei-Faktor-Authentifizierung an der Universität</description>
                    <language>en</language>
                    <copyright>University of Bremen</copyright>
                    <pubDate>Sat, 05 Sep 2026 01:38:06 +0200</pubDate>
                    <lastBuildDate>Sat, 05 Sep 2026 01:38:06 +0200</lastBuildDate>
                    <atom:link href="https://www.uni-bremen.de/en/dezernat8/basisdienste/other-it-services/security-and-pki/two-factor-authentication/rss.xml" rel="self" type="application/rss+xml"/>
                    <generator>University of Bremen</generator>
                
                
                    
                        <item>
                            <guid isPermaLink="false">content-639639</guid>
                            <pubDate>Thu, 27 Aug 2026 10:46:34 +0200</pubDate>
                            <title>Registering an App/Token</title>
                            <link>https://www.uni-bremen.de/en/dezernat8/basisdienste/other-it-services/security-and-pki/two-factor-authentication#c639639</link>
                            
                            <description>&amp;lt;p&amp;gt;If you want to use two-factor authentication, you need to e.g. install a corresponding app on a smartphone and then register it in the university system via self-service - a very simple procedure. After registration, if you log in to a service that has already been converted, you must enter a numerical code generated by the app in addition to your username and password, which changes every 30 seconds.&amp;lt;/p&amp;gt;
&amp;lt;h3&amp;gt;Step 1: Installing a TOTP-enabled App&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;The first step is to install a TOTP-enabled app on a smartphone. As the process is very simple, there are many such apps that you can simply download from your preferred app store. &amp;lt;strong&amp;gt;Aegis&amp;lt;/strong&amp;gt; or &amp;lt;strong&amp;gt;FreeOTP&amp;lt;/strong&amp;gt; are widely used. You don&amp;#039;t need to worry about data protection. These apps do not store any information in the cloud - they do not require network access.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Alternatively, some desktop applications, such as the password manager KeepassXC, can also manage TOTP access. It is generally possible to use hardware TOTP generators - however, as these devices have problems with the precise time required, we recommend using a smartphone.&amp;lt;/p&amp;gt;
&amp;lt;h3&amp;gt;Step 2: Registering your Smartphones&amp;lt;/h3&amp;gt;
&amp;lt;p&amp;gt;Once you have installed the application, go to &amp;lt;a class=&amp;quot;externalLink&amp;quot; href=&amp;quot;https://onlinetools.uni-bremen.de&amp;quot; title=&amp;quot;Opens external link in new window&amp;quot; target=&amp;quot;_blank&amp;quot;&amp;gt;the onlinetools&amp;lt;/a&amp;gt; and select the &amp;#039;Two-factor authentication&amp;#039; page. Select the item &amp;#039;Add TOTP token&amp;#039;.&amp;amp;nbsp; On the following page, you will see a QR code that you scan with the app you installed earlier. This completes the registration process.&amp;lt;/p&amp;gt;</description>
                            
                            <category>Content</category>
                            
                            
                        </item>
                    
                
                    
                        <item>
                            <guid isPermaLink="false">content-639640</guid>
                            <pubDate>Thu, 27 Aug 2026 10:47:18 +0200</pubDate>
                            <title>Token lost?</title>
                            <link>https://www.uni-bremen.de/en/dezernat8/basisdienste/other-it-services/security-and-pki/two-factor-authentication#c639640</link>
                            
                            <description>&amp;lt;p&amp;gt;If you no longer have access to the access codes, for example because your smartphone has been stolen or broken, you will no longer be able to log in to services that are secured with a second factor and will have to start a comparatively cumbersome process to reset your access.&amp;lt;/p&amp;gt;
&amp;lt;blockquote&amp;gt;&amp;lt;p&amp;gt;⭐ It is therefore advisable to register two devices as explained above if possible. If one of the devices is lost, you can log in with the second device, block access via the lost device and continue working without interruption.&amp;lt;/p&amp;gt;&amp;lt;/blockquote&amp;gt;
&amp;lt;p&amp;gt;If there is no second device, you must reset your access by resetting your password. Resetting the password also allows you to log in with a temporary access code. You can then access your settings and add new tokens accordingly.&amp;lt;/p&amp;gt;</description>
                            
                            <category>Content</category>
                            
                            
                        </item>
                    
                
                    
                        <item>
                            <guid isPermaLink="false">content-639641</guid>
                            <pubDate>Thu, 27 Aug 2026 10:49:28 +0200</pubDate>
                            <title>Supported Services</title>
                            <link>https://www.uni-bremen.de/en/dezernat8/basisdienste/other-it-services/security-and-pki/two-factor-authentication#c639641</link>
                            
                            <description>&amp;lt;p&amp;gt;The services offered by the university will be gradually supplemented by authentication with a second factor where possible. The following have already been converted (not exhaustive):&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt; 	&amp;lt;li&amp;gt;All services secured via the central single sign-on (Shibboleth). This includes, for example, Nextcloud and the central self-service portal (onlinetools), but also all external services within the DFN-AAI (e.g. publisher access).&amp;lt;/li&amp;gt; &amp;lt;/ul&amp;gt;
&amp;lt;p&amp;gt;In the near future, the following services will also be secured with the second factor:&amp;lt;/p&amp;gt;
&amp;lt;ul&amp;gt; 	&amp;lt;li&amp;gt;Stud.IP (Converted to Shibboleth)&amp;lt;/li&amp;gt; 	&amp;lt;li&amp;gt;VPN&amp;lt;/li&amp;gt; 	&amp;lt;li&amp;gt;Webmail&amp;lt;/li&amp;gt; &amp;lt;/ul&amp;gt;
&amp;lt;p&amp;gt;Services where the login is automated by an accessing program (e.g. e-mail) are more difficult to provide with a second factor due to the principle. We will add these at a later date.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Of course, you can continue to use services that do not yet support 2FA even after registering for the second factor - the second factor will be ignored for these services and you will continue to log in with just your user name and password.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;Are you the &amp;lt;strong&amp;gt;administrator of your own service&amp;lt;/strong&amp;gt; at the university and would like to use the central authentication services (and therefore also 2FA)? The best way to do this depends heavily on your application. Ideally, your service supports either OpenId Connect (OIDC) or SAML and can therefore be connected via OpenId or Shibboleth. Contact us at &amp;lt;a class=&amp;quot;mail&amp;quot; href=&amp;quot;mailto:campusserver@uni-bremen.de&amp;quot; title=&amp;quot;Öffnet ein Fenster zum Versenden der E-Mail&amp;quot;&amp;gt;campusserver@uni-bremen.de&amp;lt;/a&amp;gt;, to find the optimal solution and discuss the next steps.&amp;lt;/p&amp;gt;</description>
                            
                            <category>Content</category>
                            
                            
                        </item>
                    
                
                    
                        <item>
                            <guid isPermaLink="false">content-639642</guid>
                            <pubDate>Mon, 13 Jul 2026 11:44:05 +0200</pubDate>
                            <title>Data protection</title>
                            <link>https://www.uni-bremen.de/en/dezernat8/basisdienste/other-it-services/security-and-pki/two-factor-authentication#c639642</link>
                            
                            <description>&amp;lt;p&amp;gt;No additional personal data is stored for the procedure.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;As part of the registration process, a random character string (so-called shared secret) is generated and stored both in your smartphone app and in the central user database. By linking this shared secret and the current time, a mathematical procedure generates the numerical code that you enter when you log in.&amp;lt;/p&amp;gt;
&amp;lt;p&amp;gt;There are no additional monitoring opportunities resulting from the use of this system.&amp;lt;/p&amp;gt;</description>
                            
                            <category>Content</category>
                            
                            
                        </item>
                    
                
            
        </channel>
    </rss>

