<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.open-e.com/index.php?action=history&amp;feed=atom&amp;title=Extension%3ATwo-Factor_Authentication_rev_01</id>
	<title>Extension:Two-Factor Authentication rev 01 - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.open-e.com/index.php?action=history&amp;feed=atom&amp;title=Extension%3ATwo-Factor_Authentication_rev_01"/>
	<link rel="alternate" type="text/html" href="https://wiki.open-e.com/default/wiki/index.php?title=Extension:Two-Factor_Authentication_rev_01&amp;action=history"/>
	<updated>2026-05-04T17:02:47Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.44.5</generator>
	<entry>
		<id>https://wiki.open-e.com/default/wiki/index.php?title=Extension:Two-Factor_Authentication_rev_01&amp;diff=12402&amp;oldid=prev</id>
		<title>Ai-B: Initial help article for the optional oe_2fa.lzm module (rev 01)</title>
		<link rel="alternate" type="text/html" href="https://wiki.open-e.com/default/wiki/index.php?title=Extension:Two-Factor_Authentication_rev_01&amp;diff=12402&amp;oldid=prev"/>
		<updated>2026-04-14T10:40:10Z</updated>

		<summary type="html">&lt;p&gt;Initial help article for the optional oe_2fa.lzm module (rev 01)&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;__NOTOC__&lt;br /&gt;
Two-Factor Authentication (2FA) adds an extra security layer to JovianDSS administrator accounts. When activated, the administrator must supply both a password and a 6-digit code from a smartphone authenticator app during login. This prevents unauthorized entry even if the password is compromised.&lt;br /&gt;
&lt;br /&gt;
&amp;#039;&amp;#039;&amp;#039;Note:&amp;#039;&amp;#039;&amp;#039; 2FA is delivered as an optional Small Update (the &amp;#039;&amp;#039;&amp;#039;oe_2fa&amp;#039;&amp;#039;&amp;#039; module). This article describes revision &amp;#039;&amp;#039;&amp;#039;01&amp;#039;&amp;#039;&amp;#039;. If your system was updated to a newer revision, refer to the matching &amp;#039;&amp;#039;Extension:Two-Factor_Authentication_rev_NN&amp;#039;&amp;#039; article.&lt;br /&gt;
&lt;br /&gt;
== Supported authentication method ==&lt;br /&gt;
&lt;br /&gt;
JovianDSS implements &amp;#039;&amp;#039;&amp;#039;TOTP&amp;#039;&amp;#039;&amp;#039; (Time-based One-Time Password):&lt;br /&gt;
&lt;br /&gt;
*Compatible with Google Authenticator, Microsoft Authenticator, Authy, FreeOTP, and any other TOTP-compatible app.&lt;br /&gt;
*Codes change every 30 seconds.&lt;br /&gt;
*Works offline &amp;amp;mdash; the authenticator app does not need internet access.&lt;br /&gt;
*SMS-based methods are intentionally not supported (TOTP is more secure).&lt;br /&gt;
&lt;br /&gt;
== Setting up 2FA ==&lt;br /&gt;
&lt;br /&gt;
#Navigate to &amp;#039;&amp;#039;&amp;#039;System Settings&amp;#039;&amp;#039;&amp;#039; &amp;amp;rarr; &amp;#039;&amp;#039;&amp;#039;Administration&amp;#039;&amp;#039;&amp;#039; &amp;amp;rarr; &amp;#039;&amp;#039;&amp;#039;Two-Factor Authentication&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
#Click &amp;#039;&amp;#039;&amp;#039;Enable Two-Factor Authentication&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
#Review the displayed QR code and secret key.&lt;br /&gt;
#In your authenticator app, either scan the QR code or manually enter the secret.&lt;br /&gt;
#Enter the current 6-digit code from the app to verify the setup and click &amp;#039;&amp;#039;&amp;#039;Verify and Enable&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
#The system generates &amp;#039;&amp;#039;&amp;#039;10 backup codes&amp;#039;&amp;#039;&amp;#039;. &amp;#039;&amp;#039;&amp;#039;Save these codes immediately&amp;#039;&amp;#039;&amp;#039; &amp;amp;mdash; they are shown only once.&lt;br /&gt;
&lt;br /&gt;
Store backup codes securely (password manager or printed copy kept in a safe place).&lt;br /&gt;
&lt;br /&gt;
== Logging in with 2FA ==&lt;br /&gt;
&lt;br /&gt;
#Enter the administrator password.&lt;br /&gt;
#When prompted &amp;amp;mdash; &amp;#039;&amp;#039;&amp;quot;Two-factor authentication is enabled. Please enter your authentication code.&amp;quot;&amp;#039;&amp;#039; &amp;amp;mdash; enter the current 6-digit code from the authenticator app.&lt;br /&gt;
#Click &amp;#039;&amp;#039;&amp;#039;Log in&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
&lt;br /&gt;
The system allows a small time tolerance (&amp;amp;plusmn;30 seconds) to cope with minor clock drift.&lt;br /&gt;
&lt;br /&gt;
=== Using a backup code ===&lt;br /&gt;
&lt;br /&gt;
If the authenticator app is unavailable, enter one of the saved backup codes in the authentication code field instead of a TOTP code. Each backup code works only once and is invalidated after use.&lt;br /&gt;
&lt;br /&gt;
== Managing 2FA ==&lt;br /&gt;
&lt;br /&gt;
=== Checking status ===&lt;br /&gt;
&lt;br /&gt;
Open &amp;#039;&amp;#039;&amp;#039;System Settings&amp;#039;&amp;#039;&amp;#039; &amp;amp;rarr; &amp;#039;&amp;#039;&amp;#039;Administration&amp;#039;&amp;#039;&amp;#039; &amp;amp;rarr; &amp;#039;&amp;#039;&amp;#039;Two-Factor Authentication&amp;#039;&amp;#039;&amp;#039; to see the current status and the number of remaining backup codes (for example: &amp;#039;&amp;#039;7 / 10 backup codes available&amp;#039;&amp;#039;).&lt;br /&gt;
&lt;br /&gt;
=== Regenerating backup codes ===&lt;br /&gt;
&lt;br /&gt;
#Click &amp;#039;&amp;#039;&amp;#039;Regenerate Backup Codes&amp;#039;&amp;#039;&amp;#039;.&lt;br /&gt;
#Enter the current 6-digit authenticator code to confirm.&lt;br /&gt;
#A new set of 10 codes is generated. All previous codes (used and unused) are invalidated.&lt;br /&gt;
#Save the refreshed codes immediately.&lt;br /&gt;
&lt;br /&gt;
=== Disabling 2FA ===&lt;br /&gt;
&lt;br /&gt;
#Click &amp;#039;&amp;#039;&amp;#039;Disable Two-Factor Authentication&amp;#039;&amp;#039;&amp;#039; and confirm.&lt;br /&gt;
#2FA is deactivated and the stored secret and backup codes are removed.&lt;br /&gt;
#Re-enabling requires complete reconfiguration (new QR code, new backup codes).&lt;br /&gt;
&lt;br /&gt;
== Recovery ==&lt;br /&gt;
&lt;br /&gt;
=== Lost or broken phone &amp;amp;mdash; backup codes available ===&lt;br /&gt;
&lt;br /&gt;
#Log in using a backup code.&lt;br /&gt;
#Disable 2FA in System Settings.&lt;br /&gt;
#Set up 2FA again on the replacement device.&lt;br /&gt;
&lt;br /&gt;
=== Lost phone and no backup codes ===&lt;br /&gt;
&lt;br /&gt;
#Contact the system administrator.&lt;br /&gt;
#The administrator disables 2FA on the account.&lt;br /&gt;
#Log in with password only.&lt;br /&gt;
#Set up 2FA again on the replacement device.&lt;br /&gt;
&lt;br /&gt;
=== Moving to a new phone ===&lt;br /&gt;
&lt;br /&gt;
Most authenticator apps support transfer:&lt;br /&gt;
&lt;br /&gt;
*&amp;#039;&amp;#039;&amp;#039;Google Authenticator&amp;#039;&amp;#039;&amp;#039; &amp;amp;mdash; account transfer feature.&lt;br /&gt;
*&amp;#039;&amp;#039;&amp;#039;Microsoft Authenticator&amp;#039;&amp;#039;&amp;#039; &amp;amp;mdash; optional cloud backup.&lt;br /&gt;
*&amp;#039;&amp;#039;&amp;#039;Authy&amp;#039;&amp;#039;&amp;#039; &amp;amp;mdash; automatic sync across linked devices.&lt;br /&gt;
&lt;br /&gt;
Alternatively: disable 2FA on the old device, then re-enable it and scan the QR code on the new device.&lt;br /&gt;
&lt;br /&gt;
== Best practices ==&lt;br /&gt;
&lt;br /&gt;
*Save backup codes immediately after setup &amp;amp;mdash; store them in a password manager or a secure physical location.&lt;br /&gt;
*Keep the phone&amp;#039;s time synchronized (usually automatic).&lt;br /&gt;
*Do not share codes, secret keys, or backup codes with anyone.&lt;br /&gt;
*Regenerate backup codes periodically after heavy use.&lt;br /&gt;
*Consider disabling 2FA before planned device transitions.&lt;br /&gt;
&lt;br /&gt;
[[Category:Help topics]]&lt;br /&gt;
[[Category:Extensions]]&lt;/div&gt;</summary>
		<author><name>Ai-B</name></author>
	</entry>
</feed>