MFA and passkey on Linux

Attention:

  • If a computer is used by several people, it is essential that each user has their own local user account.
  • MFA login cannot be set up with a technical account.

Please note!

If you want to set up Passkey on another end device, first log in to the IAM portal on the end device on which you have already rolled up Passkey. Generate the confirmation code. And follow the instructions in the section Create Passkesy on antoher device on the new end device.

Roll out passkey

Create passkey on the first device

To roll out the passkey on your first computer, open the website https://getpasskey.iam.uni-bamberg.de/ with your BA-Number and the corresponding password.

After successfully registering, follow the instructions starting from the Roll out token.

Create passkey on another device

First log in to the IAM portal on the end device on which you have already rolled up Passkey. Generate the confirmation code.

Then follow the link to unroll the passkey: https://getpasskey.iam.uni-bamberg.de.

The code matrix and the confirmation code should be displayed for selection as a registration option.

Please enter the previously copied confirmation code in the field provided on the Getpasskey page and click on Check.

Roll out token

Select the Roll out token menu item there.

Since you have to roll out a passkey for each device, it is advisable to define a description accordingly.

Therefore, assign an appropriate name under Description, such as “Linux login.” Confirm this by clicking Roll out token.

The temporary pop-up message “getpasskey.iam.uni-bamberg.de requests additional information...” will then be displayed. Please select the “Allow” option promptly. Otherwise, the token will be deactivated and deleted.

Please ensure that you first use your BA number and corresponding password when logging in to the Firefox web browser.

Then confirm the process in KeepassXC by clicking the Authenticate button.

If the passkey has been successfully stored, you will see the message “The token has been rolled out” in the next window.

Manage passkey

Passkeys are managed via the IAM-Portal (iam.uni-bamberg.de). You can deactivate or delete your passkeys under the menu item Manage passkeys. Please note that the corresponding passkey must be deleted immediately if the device is lost or stolen.

Do you have any questions?

IT-Support
Telephone: +49 951 863-1333
E-Mail: it-support(at)uni-bamberg.de