<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.bwhpc.de/wiki/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=C+Mosch</id>
	<title>bwHPC Wiki - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.bwhpc.de/wiki/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=C+Mosch"/>
	<link rel="alternate" type="text/html" href="https://wiki.bwhpc.de/e/Special:Contributions/C_Mosch"/>
	<updated>2026-04-15T00:45:06Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.39.17</generator>
	<entry>
		<id>https://wiki.bwhpc.de/wiki/index.php?title=JUSTUS2/Policy_Agreement&amp;diff=15733</id>
		<title>JUSTUS2/Policy Agreement</title>
		<link rel="alternate" type="text/html" href="https://wiki.bwhpc.de/wiki/index.php?title=JUSTUS2/Policy_Agreement&amp;diff=15733"/>
		<updated>2026-02-16T15:37:13Z</updated>

		<summary type="html">&lt;p&gt;C Mosch: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== JUSTUS 2 Policy - Agreement - V3 ==&lt;br /&gt;
For all users of bwForCluster JUSTUS 2 for Computational Chemistry and Quantum Sciences the [https://www.uni-ulm.de/fileadmin/website_uni_ulm/kiz/wir_ueber_uns/kiz-bo.pdf terms of use for services of the Communication- and Information Center (kiz) of Ulm University] apply.&lt;br /&gt;
&lt;br /&gt;
When registering for the service, you comply with above mentioned terms of use. Additionally you ...&lt;br /&gt;
&lt;br /&gt;
*    agree to use the cluster only for research in accordance with DFG funding conditions&lt;br /&gt;
*    agree to acknowledge the bwForCluster JUSTUS 2 in your publications&lt;br /&gt;
*    agree to send us references to all publications with contributions by JUSTUS 2&lt;br /&gt;
*    comply with the terms of use of the software manufacturers&lt;br /&gt;
*    agree to report any problem that might endanger the cluster operations&lt;br /&gt;
*    agree to use the resources carefully (without wasting cores, memory or disk space)&lt;br /&gt;
*    accept that the system is monitored to prevent misuse&lt;br /&gt;
*    accept that job and software usage statistics are collected for improving the service and reporting to the DFG&lt;br /&gt;
*    assure that your compute activities comply with the German Foreign Trade Act (Außenwirtschaftsgesetz - AWG) und German Foreign Trade Regulations (Außenwirtschaftsverordnung - AWV), see https://www.bafa.de/DE/Aussenwirtschaft/Ausfuhrkontrolle/Academia/academia_node.html&lt;br /&gt;
*    agree to contribute to reports for the DFG&lt;br /&gt;
*    acknowledge that your home directory and work spaces will be deleted after expiration of your account (thus you are responsible to backup your files before your account expires)&lt;br /&gt;
*    will avoid swap file I/O operations or any other intense I/O to HOME - swap files of single-node jobs must use the node local disk space&lt;br /&gt;
*    will not run long cpu/memory intense calculations on login/vis nodes - those nodes are for interactive use, compiling and short tests only&lt;br /&gt;
*    will not store important results in workspaces, since they are not included in any backup&lt;br /&gt;
*    will not mass-submit very short (minutes) jobs to the batch system&lt;br /&gt;
*    will plan/submit calculations in such a way that those jobs fill entire nodes - since nodes are user-exclusive on JUSTUS 2&lt;br /&gt;
&lt;br /&gt;
Also see&lt;br /&gt;
&lt;br /&gt;
&amp;amp;rarr; [[.bashrc Do&#039;s and Don&#039;ts]]&lt;/div&gt;</summary>
		<author><name>C Mosch</name></author>
	</entry>
	<entry>
		<id>https://wiki.bwhpc.de/wiki/index.php?title=JUSTUS2/Policy_Agreement&amp;diff=15732</id>
		<title>JUSTUS2/Policy Agreement</title>
		<link rel="alternate" type="text/html" href="https://wiki.bwhpc.de/wiki/index.php?title=JUSTUS2/Policy_Agreement&amp;diff=15732"/>
		<updated>2026-02-16T14:29:44Z</updated>

		<summary type="html">&lt;p&gt;C Mosch: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== JUSTUS 2 Policy - Agreement - V3 ==&lt;br /&gt;
For all users of bwForCluster JUSTUS 2 for Computational Chemistry and Quantum Sciences the [https://www.uni-ulm.de/fileadmin/website_uni_ulm/kiz/wir_ueber_uns/kiz-bo.pdf terms of use for services of the Communication- and Information Center (kiz) of Ulm University] apply.&lt;br /&gt;
&lt;br /&gt;
When registering for the service, you comply with above mentioned terms of use. Additionally you ...&lt;br /&gt;
&lt;br /&gt;
*    agree to use the cluster only for research in accordance with DFG funding conditions&lt;br /&gt;
*    agree to acknowledge the bwForCluster JUSTUS 2 in your publications&lt;br /&gt;
*    agree to send us references to all publications with contributions by JUSTUS 2&lt;br /&gt;
*    comply with the terms of use of the software manufacturers&lt;br /&gt;
*    agree to report any problem that might endanger the cluster operations&lt;br /&gt;
*    agree to use the resources carefully (without wasting cores, memory or disk space)&lt;br /&gt;
*    accept that the system is monitored to prevent misuse&lt;br /&gt;
*    accept that job and software usage statistics are collected for improving the service and reporting to the DFG&lt;br /&gt;
*    assure that your compute activities comply with the German Foreign Trade Act (Außenwirtschaftsgesetz - AWG) und German Foreign Trade Regulations (Außenwirtschaftsverordnung - AWV), see https://www.bafa.de/DE/Aussenwirtschaft/Ausfuhrkontrolle/Academia/academia_node.html&lt;br /&gt;
*    agree to contribute to reports for the DFG&lt;br /&gt;
*    acknowledge that your home directory and work spaces will be deleted after expiration of your account (thus you are responsible to backup your files before your account expires)&lt;br /&gt;
*    will avoid swap file I/O operations or any other intense I/O to HOME - swap files of single-node jobs must use the node local disk space&lt;br /&gt;
*    will not run long cpu/memory intense calculations on login/vis nodes - those nodes are for interactive use, compiling and short tests only&lt;br /&gt;
*    will not store important results in workspaces, since they are not included in any backup&lt;br /&gt;
*    will not mass-submit very short (minutes) jobs to the batch system&lt;br /&gt;
*    will plan/submit calculations in such a way that those jobs fill entire nodes, since nodes are user-exclusive on JUSTUS 2&lt;br /&gt;
&lt;br /&gt;
Also see&lt;br /&gt;
&lt;br /&gt;
&amp;amp;rarr; [[.bashrc Do&#039;s and Don&#039;ts]]&lt;/div&gt;</summary>
		<author><name>C Mosch</name></author>
	</entry>
	<entry>
		<id>https://wiki.bwhpc.de/wiki/index.php?title=JUSTUS2/Policy_Agreement&amp;diff=15731</id>
		<title>JUSTUS2/Policy Agreement</title>
		<link rel="alternate" type="text/html" href="https://wiki.bwhpc.de/wiki/index.php?title=JUSTUS2/Policy_Agreement&amp;diff=15731"/>
		<updated>2026-02-16T14:10:00Z</updated>

		<summary type="html">&lt;p&gt;C Mosch: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== JUSTUS 2 Policy - Agreement - V3 ==&lt;br /&gt;
For all users of bwForCluster JUSTUS 2 for Computational Chemistry and Quantum Sciences the [https://www.uni-ulm.de/fileadmin/website_uni_ulm/kiz/wir_ueber_uns/kiz-bo.pdf terms of use for services of the Communication- and Information Center (kiz) of Ulm University] apply.&lt;br /&gt;
&lt;br /&gt;
When registering for the service, you comply with above mentioned terms of use. Additionally you ...&lt;br /&gt;
&lt;br /&gt;
*    agree to use the cluster only for research in accordance with DFG funding conditions&lt;br /&gt;
*    agree to acknowledge the bwForCluster JUSTUS 2 in your publications&lt;br /&gt;
*    agree to send us references to all publications with contributions by JUSTUS 2&lt;br /&gt;
*    comply with the terms of use of the software manufacturers&lt;br /&gt;
*    agree to report any problem that might endanger the cluster operations&lt;br /&gt;
*    agree to use the resources carefully (without wasting cores, memory or disk space)&lt;br /&gt;
*    accept that the system is monitored to prevent misuse&lt;br /&gt;
*    accept that job and software usage statistics are collected for improving the service and reporting to the DFG&lt;br /&gt;
*    assure that your compute activities comply with the German Foreign Trade Act (Außenwirtschaftsgesetz - AWG) und German Foreign Trade Regulations (Außenwirtschaftsverordnung - AWV), see https://www.bafa.de/DE/Aussenwirtschaft/Ausfuhrkontrolle/Academia/academia_node.html&lt;br /&gt;
*    agree to contribute to reports for the DFG&lt;br /&gt;
*    acknowledge that your home directory and work spaces will be deleted after expiration of your account (thus you are responsible to backup your files before your account expires)&lt;br /&gt;
*    will cause no constant file writes from jobs to $HOME: Any calculation swap file has  to stay on the local node. Multinode-jobs that must use a common filesystem use workspaces.&lt;br /&gt;
*    no long cpu/memory intense calculations on login/vis nodes. Those nodes are for interactive use, compiling and short tests.&lt;br /&gt;
*    no storage of important results in workspaces (there are no backups!)&lt;br /&gt;
*    no mass-flooding the batch manager with very short (minutes) jobs&lt;br /&gt;
*    plan/submit calculations so you can fill nodes (nodes are user-exclusive on J2, only your jobs can run on a node you use)&lt;br /&gt;
&lt;br /&gt;
Also see&lt;br /&gt;
&lt;br /&gt;
&amp;amp;rarr; [[.bashrc Do&#039;s and Don&#039;ts]]&lt;/div&gt;</summary>
		<author><name>C Mosch</name></author>
	</entry>
	<entry>
		<id>https://wiki.bwhpc.de/wiki/index.php?title=JUSTUS2/Policy_Agreement&amp;diff=15728</id>
		<title>JUSTUS2/Policy Agreement</title>
		<link rel="alternate" type="text/html" href="https://wiki.bwhpc.de/wiki/index.php?title=JUSTUS2/Policy_Agreement&amp;diff=15728"/>
		<updated>2026-02-09T16:03:04Z</updated>

		<summary type="html">&lt;p&gt;C Mosch: /* JUSTUS 2 Policy - Agreement - V2 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== JUSTUS 2 Policy - Agreement - V3 ==&lt;br /&gt;
For all users of bwForCluster JUSTUS 2 for Computational Chemistry and Quantum Sciences the [https://www.uni-ulm.de/fileadmin/website_uni_ulm/kiz/wir_ueber_uns/kiz-bo.pdf|terms of use for services of the Communication- and Information Center (kiz) of Ulm University] apply.&lt;br /&gt;
When registering for the service, you comply with above mentioned terms of use. Additionally you ...&lt;br /&gt;
&lt;br /&gt;
*    agree to use the cluster only for research in accordance with DFG funding conditions&lt;br /&gt;
*    agree to acknowledge the bwForCluster JUSTUS 2 in your publications&lt;br /&gt;
*    agree to send us references to all publications with contributions by JUSTUS 2&lt;br /&gt;
*    comply with the terms of use of the software manufacturers&lt;br /&gt;
*    agree to report any problem that might endanger the cluster operations&lt;br /&gt;
*    agree to use the resources carefully (without wasting cores, memory or disk space)&lt;br /&gt;
*    accept that the system is monitored to prevent misuse&lt;br /&gt;
*    accept that job and software usage statistics are collected for improving the service and reporting to the DFG&lt;br /&gt;
*    assure that your compute activities comply with the German Foreign Trade Act (Außenwirtschaftsgesetz - AWG) und German Foreign Trade Regulations (Außenwirtschaftsverordnung - AWV), see https://www.bafa.de/DE/Aussenwirtschaft/Ausfuhrkontrolle/Academia/academia_node.html&lt;br /&gt;
*    agree to contribute to reports for the DFG&lt;br /&gt;
*    acknowledge that your home directory and work spaces will be deleted after expiration of your account (thus you are responsible to backup your files before your account expires)&lt;br /&gt;
*    will cause no constant file writes from jobs to $HOME: Any calculation swap file has  to stay on the local node. Multinode-jobs that must use a common filesystem use workspaces.&lt;br /&gt;
*    no long cpu/memory intense calculations on login/vis nodes. Those nodes are for interactive use, compiling and short tests.&lt;br /&gt;
*    no storage of important results in workspaces (there are no backups!)&lt;br /&gt;
*    no mass-flooding the batch manager with very short (minutes) jobs&lt;br /&gt;
*    plan/submit calculations so you can fill nodes (nodes are user-exclusive on J2, only your jobs can run on a node you use)&lt;br /&gt;
&lt;br /&gt;
Also see&lt;br /&gt;
&lt;br /&gt;
&amp;amp;rarr; [[.bashrc Do&#039;s and Don&#039;ts]]&lt;/div&gt;</summary>
		<author><name>C Mosch</name></author>
	</entry>
	<entry>
		<id>https://wiki.bwhpc.de/wiki/index.php?title=JUSTUS2/Policy_Agreement&amp;diff=15727</id>
		<title>JUSTUS2/Policy Agreement</title>
		<link rel="alternate" type="text/html" href="https://wiki.bwhpc.de/wiki/index.php?title=JUSTUS2/Policy_Agreement&amp;diff=15727"/>
		<updated>2026-02-09T16:02:49Z</updated>

		<summary type="html">&lt;p&gt;C Mosch: /* JUSTUS 2 Policy - Agreement */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== JUSTUS 2 Policy - Agreement - V2 ==&lt;br /&gt;
For all users of bwForCluster JUSTUS 2 for Computational Chemistry and Quantum Sciences the [https://www.uni-ulm.de/fileadmin/website_uni_ulm/kiz/wir_ueber_uns/kiz-bo.pdf|terms of use for services of the Communication- and Information Center (kiz) of Ulm University] apply.&lt;br /&gt;
When registering for the service, you comply with above mentioned terms of use. Additionally you ...&lt;br /&gt;
&lt;br /&gt;
*    agree to use the cluster only for research in accordance with DFG funding conditions&lt;br /&gt;
*    agree to acknowledge the bwForCluster JUSTUS 2 in your publications&lt;br /&gt;
*    agree to send us references to all publications with contributions by JUSTUS 2&lt;br /&gt;
*    comply with the terms of use of the software manufacturers&lt;br /&gt;
*    agree to report any problem that might endanger the cluster operations&lt;br /&gt;
*    agree to use the resources carefully (without wasting cores, memory or disk space)&lt;br /&gt;
*    accept that the system is monitored to prevent misuse&lt;br /&gt;
*    accept that job and software usage statistics are collected for improving the service and reporting to the DFG&lt;br /&gt;
*    assure that your compute activities comply with the German Foreign Trade Act (Außenwirtschaftsgesetz - AWG) und German Foreign Trade Regulations (Außenwirtschaftsverordnung - AWV), see https://www.bafa.de/DE/Aussenwirtschaft/Ausfuhrkontrolle/Academia/academia_node.html&lt;br /&gt;
*    agree to contribute to reports for the DFG&lt;br /&gt;
*    acknowledge that your home directory and work spaces will be deleted after expiration of your account (thus you are responsible to backup your files before your account expires)&lt;br /&gt;
*    will cause no constant file writes from jobs to $HOME: Any calculation swap file has  to stay on the local node. Multinode-jobs that must use a common filesystem use workspaces.&lt;br /&gt;
*    no long cpu/memory intense calculations on login/vis nodes. Those nodes are for interactive use, compiling and short tests.&lt;br /&gt;
*    no storage of important results in workspaces (there are no backups!)&lt;br /&gt;
*    no mass-flooding the batch manager with very short (minutes) jobs&lt;br /&gt;
*    plan/submit calculations so you can fill nodes (nodes are user-exclusive on J2, only your jobs can run on a node you use)&lt;br /&gt;
&lt;br /&gt;
Also see&lt;br /&gt;
&lt;br /&gt;
&amp;amp;rarr; [[.bashrc Do&#039;s and Don&#039;ts]]&lt;/div&gt;</summary>
		<author><name>C Mosch</name></author>
	</entry>
	<entry>
		<id>https://wiki.bwhpc.de/wiki/index.php?title=JUSTUS2/Support&amp;diff=14338</id>
		<title>JUSTUS2/Support</title>
		<link rel="alternate" type="text/html" href="https://wiki.bwhpc.de/wiki/index.php?title=JUSTUS2/Support&amp;diff=14338"/>
		<updated>2025-03-12T14:04:44Z</updated>

		<summary type="html">&lt;p&gt;C Mosch: /* Registration and HPC Support */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Entitlement==&lt;br /&gt;
&lt;br /&gt;
In case of questions or problems regarding your entitlement for using any bwForCluster, please&lt;br /&gt;
contact your local university first level help desk.&lt;br /&gt;
&lt;br /&gt;
==Registration and HPC Support==&lt;br /&gt;
&lt;br /&gt;
In case of registration problems or questions about using JUSTUS 2, please submit a trouble ticket at the [https://www.bwhpc.de/supportportal bwSupport Portal] (use the &amp;quot;+&amp;quot; sign to create a new ticket) and assign it&lt;br /&gt;
to support unit &#039;&#039;&#039;GROUP =&amp;gt; bwHPC - Support (green arrow on right side) =&amp;gt; bwForCluster JUSTUS&#039;&#039;&#039;.&lt;/div&gt;</summary>
		<author><name>C Mosch</name></author>
	</entry>
	<entry>
		<id>https://wiki.bwhpc.de/wiki/index.php?title=JUSTUS2/Support&amp;diff=14336</id>
		<title>JUSTUS2/Support</title>
		<link rel="alternate" type="text/html" href="https://wiki.bwhpc.de/wiki/index.php?title=JUSTUS2/Support&amp;diff=14336"/>
		<updated>2025-03-12T13:59:51Z</updated>

		<summary type="html">&lt;p&gt;C Mosch: /* Registration and HPC Support */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Entitlement==&lt;br /&gt;
&lt;br /&gt;
In case of questions or problems regarding your entitlement for using any bwForCluster, please&lt;br /&gt;
contact your local university first level help desk.&lt;br /&gt;
&lt;br /&gt;
==Registration and HPC Support==&lt;br /&gt;
&lt;br /&gt;
In case of registration problems or questions about using JUSTUS 2, please submit a trouble ticket at the [https://www.bwhpc.de/supportportal bwSupport Portal] and assign it&lt;br /&gt;
to support unit &#039;&#039;&#039;GROUP =&amp;gt; bwHPC - Support (green arrow on right side) =&amp;gt; bwForCluster JUSTUS&#039;&#039;&#039;.&lt;/div&gt;</summary>
		<author><name>C Mosch</name></author>
	</entry>
	<entry>
		<id>https://wiki.bwhpc.de/wiki/index.php?title=Registration/2FA&amp;diff=12475</id>
		<title>Registration/2FA</title>
		<link rel="alternate" type="text/html" href="https://wiki.bwhpc.de/wiki/index.php?title=Registration/2FA&amp;diff=12475"/>
		<updated>2023-11-22T13:56:49Z</updated>

		<summary type="html">&lt;p&gt;C Mosch: /* andOTP is not developed anymore (https://xdaforums.com/t/unmaintained-app-4-4-open-source-andotp-open-source-two-factor-authentication-for-android.3636993/page-6#post-87021655) and has vanished from F-Droid. */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Generate a Second Factor (2FA) =&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
You or your group must take care of the hardware for the second factor yourself. We do not provide hardware keys or mobile devices.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
To improve security a &#039;&#039;&#039;2-factor authentication mechanism (2FA)&#039;&#039;&#039; is being enforced for logins to bwUniCluster/bwForClusters. In addition to the service password a second value, the &#039;&#039;&#039;second factor&#039;&#039;&#039;, has to be entered on every login.&lt;br /&gt;
&lt;br /&gt;
If you only have a mobile device, you can use software-based solutions as a second factor. If you don&#039;t want to use a smartphone app, we recommend using a hardware token such as Yubikey. The Pros and Cons of the various solutions can be found at the end of this [[Registration/2FA#Pros_and_Cons_of_the_different_Solutions|wiki]].&lt;br /&gt;
&lt;br /&gt;
== 2FA Questions and FAQ ==&lt;br /&gt;
&lt;br /&gt;
If you have any questions about 2FA, please read the [[Registration/2FA/FAQ|FAQs]], and if your question remains unanswered, please submit a support ticket&lt;br /&gt;
&lt;br /&gt;
== How 2FA works on the bwHPC Clusters ==&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
It is very important that the device that generates the One-Time Passwords and the device which is used to log into the bwUniCluster/bwForClusters are not the same.&lt;br /&gt;
Otherwise an attacker who gains access to your system can steal both the service password and the secret key of the Software Token application, which allows them to generate One-Time Passwords and log into the HPC system without your knowledge.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
[[File:2fa token code.jpg|right|200px|thumb|Hardware Token for TOTP]]&lt;br /&gt;
On the bwUniCluster/bwForClusters we use either six-digit, auto-generated, time-dependent &#039;&#039;&#039;one-time passwords&#039;&#039;&#039; (TOTP) or Yubico OTP.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;TOTPs&#039;&#039;&#039; are generated by a piece of software which is part of a special hardware device (a &#039;&#039;&#039;hardware token&#039;&#039;&#039;) or of a normal application running on a common device (a &#039;&#039;&#039;software token&#039;&#039;&#039;).&lt;br /&gt;
&lt;br /&gt;
The Token has to be synchronized with a central server before it can be used for authentication and then generates an endless stream of six-digit values (TOTPs) which can only be used once and are only valid during a very short interval of time. This makes it much harder for potential attackers to access the HPC system, even if they know the regular service password.&lt;br /&gt;
&lt;br /&gt;
Typically a new TOTP value is generated every 30 seconds. When the current TOTP value has once been used successfully for a login, it is depleted and one has to wait up to 30 seconds for the next TOTP value. If you don&#039;t want to use a smartphone, we recommend using a hardware token, such as Yubikey or another TOTP-compatible device.&lt;br /&gt;
We do not recommend the use of TOTP generators for PCs. If the second factor is generated on the same computer on which the login takes place, it is no longer a second factor.&lt;br /&gt;
&lt;br /&gt;
[[File:Otpapp.png|right|150px|thumb|Source: https://getaegis.app]]&lt;br /&gt;
&lt;br /&gt;
The most common solution is to use a mobile device (e.g. your smartphone or tablet) as a Software Token by installing one of the following apps:&lt;br /&gt;
* 2FAS for [https://play.google.com/store/apps/details?id=com.twofasapp Android] or [https://apps.apple.com/us/app/2fa-authenticator-2fas/id1217793794 iOS] ([https://2fas.com/ Web Page] and [https://github.com/twofas GitHub], &#039;&#039;Apple and Google Cloud can be used for backups depending on the operating system.&#039;&#039;)&lt;br /&gt;
* Google Authenticator for [https://play.google.com/store/apps/details?id=com.google.android.apps.authenticator2 Android] or [https://apps.apple.com/de/app/google-authenticator/id388497605 iOS] (&#039;&#039;Google Cloud can be used for backups, but these backups are not encrypted and can therefore be read by Google!&#039;&#039;)&lt;br /&gt;
* Microsoft Authenticator for [https://play.google.com/store/apps/details?id=com.azure.authenticator Android] or [https://apps.apple.com/de/app/microsoft-authenticator/id983156458 iOS] ([https://www.microsoft.com/de-de/security/mobile-authenticator-app Web Page])&lt;br /&gt;
* LastPass Authenticator for [https://play.google.com/store/apps/details?id=com.lastpass.authenticator Android], [https://apps.apple.com/us/app/lastpass-authenticator/id1079110004 iOS] or [https://lastpass.com/auth/ Windows]&lt;br /&gt;
* Aegis Authenticator for [https://play.google.com/store/apps/details?id=com.beemdevelopment.aegis Android (Google Play)] or [https://f-droid.org/en/packages/com.beemdevelopment.aegis/ Android (F-Droid)] ([https://getaegis.app/ Web Page])&lt;br /&gt;
* OTP Auth for [https://apps.apple.com/app/otp-auth/id659877384 iOS]&lt;br /&gt;
* (&#039;&#039;Authy for [https://play.google.com/store/apps/details?id=com.authy.authy Android], [https://apps.apple.com/us/app/authy/id494168017 iOS], [https://authy.com/download/ Mac, Windows or Linux], requires account&#039;&#039;)&lt;br /&gt;
(&#039;&#039;These are only suggestions. You can use any application compatible with the [https://tools.ietf.org/html/rfc6238 TOTP] standard.&#039;&#039;)&lt;br /&gt;
&lt;br /&gt;
[https://www.yubico.com/resources/glossary/yubico-otp/ &#039;&#039;&#039;Yubico OTP&#039;&#039;&#039;] is also supported if you want to use your Yubikey without depending on having a six-digit code displayed.&lt;br /&gt;
&lt;br /&gt;
= Token Management =&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
* Create at least two separate tokens: &#039;&#039;&#039;FIRST&#039;&#039;&#039; set up a software/hardware TOTP token. &#039;&#039;&#039;THEN&#039;&#039;&#039; create and print a &amp;quot;backup TAN list&amp;quot;. Never create the &amp;quot;backup TAN list&amp;quot; first.&lt;br /&gt;
* If you lose access to all your tokens, you will not be able to create new tokens and support will have to reset your tokens manually.&lt;br /&gt;
* The &amp;quot;backup TAN list&amp;quot; should always be created and printed in a &#039;&#039;&#039;second step&#039;&#039;&#039;. The printout should be kept in a separate place for emergencies.&lt;br /&gt;
* Please clean up your second factors as soon as you have created new tokens. Tokens that can no longer be used (e.g. because not initialized, smartphone/Yubikey lost, etc.) or an old backup TAN list where you have already used all TANs or there is no printout should be deactivated and deleted.&lt;br /&gt;
* Returning users who have already activated one or more tokens must first verify their token before they can create new tokens, see section [[Registration/2FA#Returning_Users|Returning Users]].&lt;br /&gt;
* &#039;&#039;&#039;Please disable all privacy tools, ad blockers and further add-ons when registering new tokens.&#039;&#039;&#039; These tools prevent the registration website from generating new security tokens. When the problems remains (you can not generate the QR code or can not confirm it by clicking CHECK), please try once more with an entirely new unmodified web browser profile.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;bwUniCluster/bwForCluster Tokens&#039;&#039;&#039; are generally managed via the &#039;&#039;&#039;Index -&amp;gt; My Tokens&#039;&#039;&#039; menu entry on the registration pages for the clusters. Here you can register, activate, deactivate and delete tokens.&lt;br /&gt;
&lt;br /&gt;
To activate the second factor, &#039;&#039;&#039;please perform the following steps:&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
1. &#039;&#039;&#039;Select the registration server of the cluster&#039;&#039;&#039; for which you want to create a second factor and login to it:&amp;lt;/br&amp;gt; &amp;amp;rarr; [https://login.bwidm.de/user/twofa.xhtml Registration server for &#039;&#039;&#039;bwUniCluster 2.0&#039;&#039;&#039;, &#039;&#039;&#039;bwForCluster JUSTUS 2&#039;&#039;&#039; and &#039;&#039;&#039;bwForCluster NEMO&#039;&#039;&#039;] (2FA tokens are valid for all three clusters; KIT members can reuse their existing hardware and software tokens)&amp;lt;/br&amp;gt; &amp;amp;rarr; [https://bwservices.uni-heidelberg.de//user/twofa.xhtml Registration server for &#039;&#039;&#039;bwForCluster Helix&#039;&#039;&#039;]&lt;br /&gt;
[[File:BwIDM-twofa.png|center|600px|thumb|My Tokens]]&lt;br /&gt;
&lt;br /&gt;
2. &#039;&#039;&#039;Register a new &amp;quot;[[Registration/2FA#Registering_a_new_Software_Token_using_a_Mobile_APP|Smartphone Token]]&amp;quot;&#039;&#039;&#039; or if you own a [https://www.yubico.com/ Yubikey]&#039;&#039;&#039; register a new &amp;quot;[[Registration/2FA#Registering_a_new_Yubikey_OTP_Token|Yubikey Token]]&amp;quot;&#039;&#039;&#039; or &#039;&#039;&#039;&amp;quot;[[Registration/2FA#Registering_a_new_Yubikey_OATH_TOTP_Token|Yubikey OATH TOTP Token]]&amp;quot;&#039;&#039;&#039; ([[Registration/2FA#Pros_and_Cons_of_the_different_Solutions|pros ans cons]]).&lt;br /&gt;
&lt;br /&gt;
3. &#039;&#039;&#039;Register a new &amp;quot;[[Registration/2FA#Backup_TAN_List|TAN List]]&amp;quot; (backup TAN list)&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
4. Repeat step 2. for additional tokens.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Registering a new Software Token using a Mobile APP ==&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
Please disable all privacy tools, ad blockers and further add-ons when registering new tokens.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
1. Select the [[Registration/2FA#Token_Management|registration server]] of the cluster for which you want to create a second factor and login to it.&lt;br /&gt;
&lt;br /&gt;
2. Registering a new Token starts with a click &#039;&#039;&#039;NEW SMARTPHONE TOKEN&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-token.png|center|600px|thumb|Create a new Token]]&lt;br /&gt;
&lt;br /&gt;
3. A new window opens. Click &#039;&#039;&#039;Start&#039;&#039;&#039; to generate a new &#039;&#039;&#039;QR code&#039;&#039;&#039;.&lt;br /&gt;
This may take a while.&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
The QR code contains a key which has to remain secret.&lt;br /&gt;
Only use the QR code to link your software token app with bwIDM/bwServices in the next step.&lt;br /&gt;
Do not save the QR code, print it out or share it with someone else.&lt;br /&gt;
|}&lt;br /&gt;
[[File:BwIDM-qr.png|center|600px|thumb|QR Code for Mobile App]]&lt;br /&gt;
&lt;br /&gt;
4. Start the software token app on your separate device and scan the QR code.&lt;br /&gt;
The exact process is a little bit different in every app, but is usually started by pressing on a button with a plus (+) sign or an icon of a QR code.&lt;br /&gt;
&lt;br /&gt;
5. Once the QR code has been loaded into your Software Token app there should be a new entry called &#039;&#039;&#039;bwIDM&#039;&#039;&#039; (bwUniCluster, JUSTUS 2 and NEMO) or &#039;&#039;&#039;bwServices&#039;&#039;&#039; (Helix).&lt;br /&gt;
Generate an One-Time-Password by pressing on this entry or selecting the appropriate button/menu item.&lt;br /&gt;
You will receive a six-digit code.&lt;br /&gt;
Enter this code into the field labeled &amp;quot;Current code:&amp;quot; in your bwIDM browser window to prove that the connection has worked and then click &#039;&#039;&#039;CHECK&#039;&#039;&#039;.&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
If you do not confirm the token by entering the six-digit code in the &amp;quot;Current code:&amp;quot; field, the token will &#039;&#039;&#039;NOT&#039;&#039;&#039; be initialized!&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
6. If everything worked as expected, you will be returned to the &#039;&#039;&#039;My Tokens&#039;&#039;&#039; screen and there will be a new entry for your software token.&lt;br /&gt;
[[File:BwIDM-app.png|center|400px|thumb|Success]]&lt;br /&gt;
&lt;br /&gt;
7. Repeat the process to register additional tokens.&lt;br /&gt;
Please register at least the &amp;quot;Backup TAN list&amp;quot; in addition to the hardware/software token you plan to use regularly.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Registering a new Yubikey OTP Token ==&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
Please disable all privacy tools, ad blockers and further add-ons when registering new tokens.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
[https://developers.yubico.com/OTP/OTPs_Explained.html Yubikey OTP] is even easier and you don&#039;t need a device that displays the six-digit code or extra software.&lt;br /&gt;
New Yubikeys are already configured to provide Yubikey OTP in slot 1.&lt;br /&gt;
If you need to configure your Yubikey, read this [[Registration/2FA/Yubikey|documentation]].&lt;br /&gt;
&lt;br /&gt;
1. Select the [[Registration/2FA#Token_Management|registration server]] of the cluster for which you want to create a second factor and login to it.&lt;br /&gt;
&lt;br /&gt;
2. If you want to use [https://www.yubico.com/resources/glossary/yubico-otp/ Yubico OTP], you can click &#039;&#039;&#039;NEW YUBIKEY TOKEN&#039;&#039;&#039; instead.&lt;br /&gt;
[[File:BwIDM-token.png|center|600px|thumb|Generate Yubikey OTP]]&lt;br /&gt;
&lt;br /&gt;
3. Yubikey OTP is configured to slot 1 on new Yubikeys, so you only need to click in the text box and then touch the metal part of your Yubikey.&lt;br /&gt;
Please refer to this [[Registration/2FA/Yubikey|documentation]] on how to configure your Yubikey.&lt;br /&gt;
[[File:BwIDM-yubikey.png|center|400px|thumb|Yubikey OTP]]&lt;br /&gt;
&lt;br /&gt;
4. If everything worked as expected, you will be returned to the &#039;&#039;&#039;My Tokens&#039;&#039;&#039; screen and there will be a new entry for your Yubikey.&lt;br /&gt;
[[File:BwIDM-yubikey2.png|center|400px|thumb|Success]]&lt;br /&gt;
&lt;br /&gt;
5. Repeat the process to register additional tokens.&lt;br /&gt;
Please register at least the &amp;quot;Backup TAN list&amp;quot; in addition to the hardware/software token you plan to use regularly.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Registering a new Yubikey OATH TOTP Token ==&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
Please disable all privacy tools, ad blockers and further add-ons when registering new tokens.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
[https://developers.yubico.com/OATH/ Yubikey OATH TOTP] generates the TANs on your Yubikey and therefore you can use different computers and phones to generate these codes.&lt;br /&gt;
Please download and install [https://developers.yubico.com/OATH/YubiKey_OATH_software.html Yubico Authenticator] for desktop (or Android/iOS) first.&lt;br /&gt;
Insert your Yubikey in your computer.&lt;br /&gt;
&amp;quot;Yubikey OTP&amp;quot; (not &amp;quot;Yubikey OATH TOTP&amp;quot;) is even easier and you don&#039;t need a device that displays the six-digit code or extra software (go to step [[Registration/2FA#Yubikey_OTP|Yubikey OTP]]).&lt;br /&gt;
&lt;br /&gt;
1. Select the [[Registration/2FA#Token_Management|registration server]] of the cluster for which you want to create a second factor and login to it.&lt;br /&gt;
&lt;br /&gt;
2. Registering a new Token starts with a click &#039;&#039;&#039;NEW SMARTPHONE TOKEN&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-token.png|center|600px|thumb|Create a new Token]]&lt;br /&gt;
&lt;br /&gt;
3. A new window opens. Click &#039;&#039;&#039;Start&#039;&#039;&#039; to generate a new &#039;&#039;&#039;QR code&#039;&#039;&#039;.&lt;br /&gt;
This may take a while.&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
The QR code contains a key which has to remain secret.&lt;br /&gt;
Only use the QR code to link your software token app with bwIDM/bwServices in the next step.&lt;br /&gt;
Do not save the QR code, print it out or share it with someone else.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
4. Start the Yubico Authenticator on your OS, click the three vertical dots in the upper right corner and select &#039;&#039;&#039;Scan QR code&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-yubi1.png|center|600px|thumb|QR Code and Yubico Authenticator on Linux]]&lt;br /&gt;
&lt;br /&gt;
5. Yubico Authenticator automatically translates the QR code to a new entry called &#039;&#039;&#039;bwIDM&#039;&#039;&#039; or &#039;&#039;&#039;bwServices&#039;&#039;&#039; (Helix).&lt;br /&gt;
Click &#039;&#039;&#039;Add account&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-yubi2.png|center|600px|thumb|Create new TOTP on Yubico Authenticator]]&lt;br /&gt;
&lt;br /&gt;
6. You will receive a six-digit code.&lt;br /&gt;
Enter this code into the field labeled &amp;quot;Current code:&amp;quot; in your bwIDM browser window to prove that the connection has worked and then click &#039;&#039;&#039;CHECK&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-yubi3.png|center|600px|thumb|Verify TOTP]]&lt;br /&gt;
&lt;br /&gt;
7. If everything worked as expected, you will be returned to the &#039;&#039;&#039;My Tokens&#039;&#039;&#039; screen and there will be a new entry for your software token.&lt;br /&gt;
[[File:BwIDM-app.png|center|400px|thumb|Success]]&lt;br /&gt;
&lt;br /&gt;
8. Repeat the process to register additional tokens.&lt;br /&gt;
Please register at least the &amp;quot;Backup TAN list&amp;quot; in addition to the hardware/software token you plan to use regularly.&lt;br /&gt;
&lt;br /&gt;
== Backup TAN List ==&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
Passwords from the &amp;quot;Backup TAN list&amp;quot; should only be used if no other token is left.&lt;br /&gt;
Please do not use the Backup TANs for regular cluster login, because you have only a limited number of TANs.&lt;br /&gt;
Each TAN can only be used once.&lt;br /&gt;
Please disable all privacy tools, ad blockers and further add-ons when registering a new Backup TAN list.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
1. Select the [[Registration/2FA#Token_Management|registration server]] of the cluster for which you want to create a second factor and login to it.&lt;br /&gt;
&lt;br /&gt;
2. Please create at least one &amp;quot;Backup TAN list&amp;quot; by clicking &#039;&#039;&#039;CREATE NEW TAN LIST&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-token.png|center|600px|thumb|Generate Backup TAN list]]&lt;br /&gt;
&lt;br /&gt;
3. Click &#039;&#039;&#039;START&#039;&#039;&#039;. You will be redirected to the &#039;&#039;&#039;My Tokens&#039;&#039;&#039; screen and there will be a new entry for your backup TANs.&lt;br /&gt;
[[File:BwIDM-tan.png|center|400px|thumb|Success]]&lt;br /&gt;
&lt;br /&gt;
4. Click &#039;&#039;&#039;SHOW TANS&#039;&#039;&#039;, print the codes and keep then in a separate place for emergencies.&lt;br /&gt;
[[File:JUSTUS-2-2FA-backup-TAN-list.png|center|800px|thumb|Print Backup TAN List]]&lt;br /&gt;
&lt;br /&gt;
5. Repeat the process to register additional tokens.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Deactivating a Token ==&lt;br /&gt;
&lt;br /&gt;
Click &#039;&#039;&#039;Disable&#039;&#039;&#039; next to the Token entry on the &#039;&#039;&#039;My Tokens&#039;&#039;&#039; screen.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Deleting a Token ==&lt;br /&gt;
&lt;br /&gt;
After a Token has been disabled a new button labeled &#039;&#039;&#039;Delete&#039;&#039;&#039; will appear. Click on it to delete the token.&lt;br /&gt;
&lt;br /&gt;
= Returning Users =&lt;br /&gt;
&lt;br /&gt;
Returning users who have already activated one or more tokens must first verify their token before they can create new tokens or deactivate/delete old ones.&lt;br /&gt;
If you no longer have valid tokens, you will not be able to create or manage tokens. &lt;br /&gt;
In this case, read the section [[Registration/2FA#Lost_Token|Lost Token]].&lt;br /&gt;
[[File:BwIDM-totp.png|center|400px|thumb|Returning users must first verify their token.]]&lt;br /&gt;
&lt;br /&gt;
= Lost Token =&lt;br /&gt;
&lt;br /&gt;
If you change your phone, please migrate your tokens first or register your new mobile app under &amp;quot;My Tokens&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;If you no longer have valid tokens (mobile app, hardware token, Yubikey or backup TAN, i.e. lost or broken smartphone), you can not access the section &amp;quot;My Tokens&amp;quot; anymore.&lt;br /&gt;
In this case you will need to contact the [https://bw-support.scc.kit.edu/ ticket system].&#039;&#039;&#039;&lt;br /&gt;
Open a ticket, include your user name, the name of the bwHPC cluster and ask for a reset of your 2FA tokens.&lt;br /&gt;
Please note that this process may take some time and also means additional work for the operators.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Pros and Cons of the different Solutions =&lt;br /&gt;
&lt;br /&gt;
This section briefly describes the differences between the above solutions.&lt;br /&gt;
&lt;br /&gt;
== Mobile App ==&lt;br /&gt;
&lt;br /&gt;
This sections describes the pros and cons of an app on your mobile device (phone or tablet).&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Pros:&#039;&#039;&#039;&lt;br /&gt;
* Can be used at no extra cost if you have a mobile device.&lt;br /&gt;
* When using your cell phone, you always have the second factor at your fingertips.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Cons:&#039;&#039;&#039;&lt;br /&gt;
* You need a mobile device.&lt;br /&gt;
* If your device is lost or damaged, you will lose your second factor. (&#039;&#039;Some services offer cloud synchronization, but you usually need an account and Google Authenticator does not encrypt your TOTP secret keys when storing them in the cloud.&#039;&#039;)&lt;br /&gt;
&lt;br /&gt;
== Yubico OTP ==&lt;br /&gt;
&lt;br /&gt;
This sections describes the pros and cons of Yubico OTP. For Yubico OTP to work, you need a Yubikey with Yubico OTP support.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Pros:&#039;&#039;&#039;&lt;br /&gt;
* You do not need a mobile device. All you need is a USB port.&lt;br /&gt;
* Simple and fast: The Yubikeys are preconfigured for Yubico OTP. All you need to do is touch the metal plate on the device when prompted.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Cons:&#039;&#039;&#039;&lt;br /&gt;
* You have to spend money on a Yubikey.&lt;br /&gt;
* If you lose the device, you will lose the second factor (it is recommended to buy at least two Yubikeys).&lt;br /&gt;
* If you do not have your Yubikey with you, you cannot log in to the clusters.&lt;br /&gt;
* In bwHPC, the Yubicloud is used to synchronize the Yubico OTP keys (third-party provider).&lt;br /&gt;
&lt;br /&gt;
== Yubikey OATH TOTP ==&lt;br /&gt;
&lt;br /&gt;
This sections describes the pros and cons of Yubikey OATH TOTP. For Yubikey OATH TOTP to work, you need a Yubikey with OATH TOTP support. This solution is similar to the one for mobile apps, but an external pin generator is used.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Pros:&#039;&#039;&#039;&lt;br /&gt;
* You do not need a mobile device. All you need is a USB port.&lt;br /&gt;
* You can use multiple devices such as phones and tablets (via USB, Lightning or NFC) or even your computer(s).&lt;br /&gt;
* Since the TOTP is calculated on the Yubikey and the computer/mobile device is only used for displaying the TOTP and time synchronization, you can use the same device you use for login.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;Cons:&#039;&#039;&#039;&lt;br /&gt;
* You have to spend money on a Yubikey.&lt;br /&gt;
* If you lose the device, you will lose the second factor (it is recommended to buy at least two Yubikeys).&lt;br /&gt;
* If you do not have your Yubikey with you, you cannot log in to the clusters.&lt;/div&gt;</summary>
		<author><name>C Mosch</name></author>
	</entry>
	<entry>
		<id>https://wiki.bwhpc.de/wiki/index.php?title=Registration/bwForCluster/Service&amp;diff=12424</id>
		<title>Registration/bwForCluster/Service</title>
		<link rel="alternate" type="text/html" href="https://wiki.bwhpc.de/wiki/index.php?title=Registration/bwForCluster/Service&amp;diff=12424"/>
		<updated>2023-11-08T16:52:49Z</updated>

		<summary type="html">&lt;p&gt;C Mosch: /* Step C: bwForCluster Account Creation */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Prerequisites for Step C =&lt;br /&gt;
&lt;br /&gt;
Prerequisites for successful account creation:&lt;br /&gt;
* &#039;&#039;&#039;[[Registration/bwForCluster/Entitlement|Step A: bwForCluster Entitlement]]&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;[[Registration/bwForCluster/RV|Step B: Apply for a Rechenvorhaben/project]].&lt;br /&gt;
&lt;br /&gt;
Once you have registered your own RV (&#039;&#039;Rechenvorhaben&#039;&#039;) or a membership in an RV, you will receive an email with a website to create an account for yourself on that cluster.&lt;br /&gt;
&lt;br /&gt;
= Step C: bwForCluster Registration (Account Creation) =&lt;br /&gt;
&lt;br /&gt;
To finish the registration procedure select the cluster your RV was assigned to:&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;[[Registration/bwForCluster/BINAC|bwForCluster BINAC]]&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;[[Registration/bwForCluster/JUSTUS2|bwForCluster JUSTUS 2]]&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;[[Registration/bwForCluster/Helix|bwForCluster Helix]]&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;[[Registration/bwForCluster/NEMO|bwForCluster NEMO]]&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p style=&amp;quot;text-align:right;&amp;quot;&amp;gt;[[Registration/bwForCluster| Go back to bwForCluster Registration Home]]&amp;lt;/p&amp;gt;&lt;/div&gt;</summary>
		<author><name>C Mosch</name></author>
	</entry>
	<entry>
		<id>https://wiki.bwhpc.de/wiki/index.php?title=Registration/bwForCluster&amp;diff=12423</id>
		<title>Registration/bwForCluster</title>
		<link rel="alternate" type="text/html" href="https://wiki.bwhpc.de/wiki/index.php?title=Registration/bwForCluster&amp;diff=12423"/>
		<updated>2023-11-08T16:52:11Z</updated>

		<summary type="html">&lt;p&gt;C Mosch: /* Three Steps for Registration */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Registration bwForCluster =&lt;br /&gt;
&lt;br /&gt;
A bwForCluster is a cluster for a specific [https://www.bwhpc.de/cluster.php research area].&lt;br /&gt;
You can apply for a bwForCluster and the &amp;quot;cluster assignment team&amp;quot; will assign you to the appropriate cluster for your research area, taking into account your specific hardware/software needs.&lt;br /&gt;
bwForClusters are funded by the German Research Foundation (DFG) and the Ministry of Science, Research and the Arts of Baden-Württemberg on the basis of grant applications (cf. proposals application guidelines according to Art. 91b GG).&lt;br /&gt;
&lt;br /&gt;
All members of the universities in Baden-Württemberg can apply for an account.&lt;br /&gt;
&lt;br /&gt;
The use of the bwForClusters is free of charge.&lt;br /&gt;
&lt;br /&gt;
== Three Steps for Registration ==&lt;br /&gt;
&lt;br /&gt;
The registration process for a bwForCluster is divided into three steps, whereby step A+B can be performed in parallel.&lt;br /&gt;
When both are completed, you can perform step C.&lt;br /&gt;
To which cluster you get access depends on your research area and will be decided in step B.&lt;br /&gt;
&lt;br /&gt;
* Step A: You need to get the &#039;&#039;&#039;bwForCluster Entitlement&#039;&#039;&#039; from your university/college.&amp;lt;br /&amp;gt;&amp;amp;rarr; &#039;&#039;&#039;[[Registration/bwForCluster/Entitlement|bwForCluster User Access Step A]]&#039;&#039;&#039;&lt;br /&gt;
* Step B: You need to &#039;&#039;&#039;apply for a Rechenvorhaben/project&#039;&#039;&#039; on the &amp;quot;central application site&amp;quot; (ZAS).&amp;lt;br /&amp;gt;&amp;amp;rarr; &#039;&#039;&#039;[[Registration/bwForCluster/RV|bwForCluster User Access Step B]]&#039;&#039;&#039;&lt;br /&gt;
* Step C: You need to &#039;&#039;&#039;register for a bwForCluster&#039;&#039;&#039; (create an account on the cluster).&amp;lt;br /&amp;gt;&amp;amp;rarr; &#039;&#039;&#039;[[Registration/bwForCluster/Service|bwForCluster User Access Step C]]&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
After registering, please refer further to &#039;&#039;&#039;[[Registration/bwForCluster#Information_for_already_registered_users|Information for already registered users]]&#039;&#039;&#039; at the bottom of the page and to the cluster-specific pages below &#039;&#039;&#039;bwHPC Systems&#039;&#039;&#039; in the menu on the left.&lt;br /&gt;
&lt;br /&gt;
[[File:bwForCluster-Registration.png|center|bwForCluster Registration Process]]&lt;br /&gt;
&lt;br /&gt;
== Information for already registered users ==&lt;br /&gt;
&lt;br /&gt;
* If you want to &#039;&#039;&#039;login&#039;&#039;&#039; to one of the bwForClusters, please refer to the general &amp;lt;br /&amp;gt; &amp;amp;rarr; &#039;&#039;&#039;[[Registration/Login|Login Guide]]&#039;&#039;&#039;&lt;br /&gt;
* If you want to &#039;&#039;&#039;create a second factor&#039;&#039;&#039;, please refer to &amp;lt;br /&amp;gt; &amp;amp;rarr; &#039;&#039;&#039;[[Registration/2FA|Generate a Second Factor (2FA)]]&#039;&#039;&#039; (only Justus 2 and Helix)&lt;br /&gt;
* If you need to &#039;&#039;&#039;change or forgot your password&#039;&#039;&#039; for a bwForCluster, please refer to the general &amp;lt;br /&amp;gt; &amp;amp;rarr; &#039;&#039;&#039;[[Registration/Password|Password Guide]]&#039;&#039;&#039;&lt;br /&gt;
* If you want to &#039;&#039;&#039;use SSH keys&#039;&#039;&#039; on a bwForCluster, please refer to &amp;lt;br /&amp;gt; &amp;amp;rarr; &#039;&#039;&#039;[[Registration/SSH|Registering SSH Keys with your Cluster]]&#039;&#039;&#039; (only Helix)&lt;br /&gt;
* If you want do &#039;&#039;&#039;de-register your user account&#039;&#039;&#039; from a bwForCluster, please refer to the general &amp;lt;br /&amp;gt;&amp;amp;rarr; &#039;&#039;&#039;[[Registration/Deregistration|De-registration Guide]]&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
[[Category:Feedback]]&lt;/div&gt;</summary>
		<author><name>C Mosch</name></author>
	</entry>
	<entry>
		<id>https://wiki.bwhpc.de/wiki/index.php?title=Registration/bwForCluster/Service&amp;diff=12422</id>
		<title>Registration/bwForCluster/Service</title>
		<link rel="alternate" type="text/html" href="https://wiki.bwhpc.de/wiki/index.php?title=Registration/bwForCluster/Service&amp;diff=12422"/>
		<updated>2023-11-08T16:51:10Z</updated>

		<summary type="html">&lt;p&gt;C Mosch: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Prerequisites for Step C =&lt;br /&gt;
&lt;br /&gt;
Prerequisites for successful account creation:&lt;br /&gt;
* &#039;&#039;&#039;[[Registration/bwForCluster/Entitlement|Step A: bwForCluster Entitlement]]&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;[[Registration/bwForCluster/RV|Step B: Apply for a Rechenvorhaben/project]].&lt;br /&gt;
&lt;br /&gt;
Once you have registered your own RV (&#039;&#039;Rechenvorhaben&#039;&#039;) or a membership in an RV, you will receive an email with a website to create an account for yourself on that cluster.&lt;br /&gt;
&lt;br /&gt;
= Step C: bwForCluster Account Creation =&lt;br /&gt;
&lt;br /&gt;
To finish the registration procedure select the cluster your RV was assigned to:&lt;br /&gt;
&lt;br /&gt;
* &#039;&#039;&#039;[[Registration/bwForCluster/BINAC|bwForCluster BINAC]]&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;[[Registration/bwForCluster/JUSTUS2|bwForCluster JUSTUS 2]]&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;[[Registration/bwForCluster/Helix|bwForCluster Helix]]&#039;&#039;&#039;&lt;br /&gt;
* &#039;&#039;&#039;[[Registration/bwForCluster/NEMO|bwForCluster NEMO]]&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p style=&amp;quot;text-align:right;&amp;quot;&amp;gt;[[Registration/bwForCluster| Go back to bwForCluster Registration Home]]&amp;lt;/p&amp;gt;&lt;/div&gt;</summary>
		<author><name>C Mosch</name></author>
	</entry>
	<entry>
		<id>https://wiki.bwhpc.de/wiki/index.php?title=Registration/bwForCluster/JUSTUS2&amp;diff=11914</id>
		<title>Registration/bwForCluster/JUSTUS2</title>
		<link rel="alternate" type="text/html" href="https://wiki.bwhpc.de/wiki/index.php?title=Registration/bwForCluster/JUSTUS2&amp;diff=11914"/>
		<updated>2023-04-17T07:59:24Z</updated>

		<summary type="html">&lt;p&gt;C Mosch: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=  Registration at the bwForCluster JUSTUS 2 = &lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
You can return to the registration website at any time, in order to review your registration details, change/reset your service password or de-register from the service by yourself.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
After having completed steps A+B please visit the &#039;&#039;&#039;[https://login.bwidm.de bwForCluster JUSTUS 2 registration page]&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
Do the following steps to complete registration:&lt;br /&gt;
&lt;br /&gt;
1. Select your home organization from the list on the main page and click &#039;&#039;&#039;Proceed&#039;&#039;&#039; or &#039;&#039;&#039;Fortfahren&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-login.png|center|600px|thumb|Select your home organization]]&lt;br /&gt;
&lt;br /&gt;
2. You will be directed to the &#039;&#039;Identity Provider&#039;&#039; of your home organization.&lt;br /&gt;
Enter the username and password of your &#039;&#039;&#039;home organization&#039;&#039;&#039; (usually these credentials are also used for other services like email) and click &#039;&#039;&#039;Login/Einloggen&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
3. You will be redirected back to the registration page &#039;&#039;&#039;https://login.bwidm.de&#039;&#039;&#039;.&lt;br /&gt;
When you log in to bwIDM for the first time, an overview will appear, with the account information that your home institution submits to the system.&lt;br /&gt;
Please verify that all data is valid and then click &#039;&#039;&#039;Continue/Weiter&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
4. After you have successfully logged into the bwIDM system, you will be greeted by a welcome screen that displays all the statewide services you have access to.&lt;br /&gt;
There you will find a field labeled &#039;&#039;&#039;bwForCluster JUSTUS 2&#039;&#039;&#039;.&lt;br /&gt;
Click &#039;&#039;&#039;Register/Registrieren&#039;&#039;&#039; to start the registration process.&lt;br /&gt;
[[File:BwIDM-reg.png|center|frame|Register for JUSTUS 2]]&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
* If the service JUSTUS 2 &#039;&#039;&#039;is not visible&#039;&#039;&#039;, then you are probably missing the necessary entitlement. Go to [[Registration/bwForCluster/Entitlement|step A]] to check this.&lt;br /&gt;
* By clicking on &#039;&#039;&#039;Register&#039;&#039;&#039; you automatically subscribe to the &#039;&#039;&#039;justus2-users&#039;&#039;&#039; mailing list. The list provides news and information related to the bwForCluster JUSTUS 2 for computational chemistry and quantum sciences in Ulm.&lt;br /&gt;
* When you &#039;&#039;&#039;de-register&#039;&#039;&#039; your account from the cluster, you automatically unsubscribe from the list.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
5. JUSTUS 2 uses a &#039;&#039;&#039;2-factor authentication&#039;&#039;&#039; (2FA) mechanism to increase security.&lt;br /&gt;
If you have never registered a 2FA token on bwIDM, the following error message will appear:&lt;br /&gt;
[[File:Bwidm-3-red.png|center|600px|thumb|Second factor missing.]]&lt;br /&gt;
&lt;br /&gt;
Use this &#039;&#039;&#039;[https://login.bwidm.de/user/twofa.xhtml link]&#039;&#039;&#039; or select &#039;&#039;&#039;Index -&amp;gt; My Tokens&#039;&#039;&#039; in the main menu.&lt;br /&gt;
To register a new token, please follow these &#039;&#039;&#039;[[Registration/2FA|instructions]]&#039;&#039;&#039;.&lt;br /&gt;
Please complete this step before continuing.&lt;br /&gt;
&lt;br /&gt;
6. Read the Terms of Use (&#039;&#039;&#039;Nutzungsbedingungen und -richtlinien&#039;&#039;&#039;), place a check mark next to &#039;&#039;&#039;I have read and accepted the terms of use&#039;&#039;&#039; and click &#039;&#039;&#039;Register/Registrieren&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
7. Set a service password for JUSTUS 2 and click &#039;&#039;&#039;Save/Speichern&#039;&#039;&#039;.&lt;br /&gt;
Be sure to use a secure password that is different from any other passwords you currently use or have used on other systems.&lt;br /&gt;
[[File:BwIDM-passwd.png|center|800px|Set service password]]&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
Setting a service password is mandatory for access to any bwForCluster.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p style=&amp;quot;text-align:right;&amp;quot;&amp;gt;[[Registration/bwForCluster| Go back to bwForCluster Registration Home]]&amp;lt;/p&amp;gt;&lt;/div&gt;</summary>
		<author><name>C Mosch</name></author>
	</entry>
	<entry>
		<id>https://wiki.bwhpc.de/wiki/index.php?title=Registration/bwForCluster/JUSTUS2&amp;diff=11908</id>
		<title>Registration/bwForCluster/JUSTUS2</title>
		<link rel="alternate" type="text/html" href="https://wiki.bwhpc.de/wiki/index.php?title=Registration/bwForCluster/JUSTUS2&amp;diff=11908"/>
		<updated>2023-04-05T18:28:08Z</updated>

		<summary type="html">&lt;p&gt;C Mosch: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=  Registration at the bwForCluster JUSTUS 2 = &lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
You can return to the registration website at any time, in order to review your registration details, change/reset your service password or de-register from the service by yourself.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
After having completed steps A+B please visit the &#039;&#039;&#039;[https://login.bwidm.de bwForCluster JUSTUS 2 registration page]&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
Do the following steps to complete registration:&lt;br /&gt;
&lt;br /&gt;
1. Select your home organization from the list on the main page and click &#039;&#039;&#039;Proceed&#039;&#039;&#039; or &#039;&#039;&#039;Fortfahren&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-login.png|center|600px|thumb|Select your home organization]]&lt;br /&gt;
&lt;br /&gt;
2. You will be directed to the &#039;&#039;Identity Provider&#039;&#039; of your home organization.&lt;br /&gt;
Enter the username and password of your &#039;&#039;&#039;home organization&#039;&#039;&#039; (usually these credentials are also used for other services like email) and click &#039;&#039;&#039;Login/Einloggen&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
3. You will be redirected back to the registration page &#039;&#039;&#039;https://login.bwidm.de&#039;&#039;&#039;.&lt;br /&gt;
When you log in to bwIDM for the first time, an overview will appear, with the account information that your home institution submits to the system.&lt;br /&gt;
Please verify that all data is valid and then click &#039;&#039;&#039;Continue/Weiter&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
4. After you have successfully logged into the bwIDM system, you will be greeted by a welcome screen that displays all the statewide services you have access to.&lt;br /&gt;
There you will find a field labeled &#039;&#039;&#039;bwForCluster JUSTUS 2&#039;&#039;&#039;.&lt;br /&gt;
Click &#039;&#039;&#039;Register/Registrieren&#039;&#039;&#039; to start the registration process.&lt;br /&gt;
[[File:BwIDM-reg.png|center|frame|Register for JUSTUS 2]]&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
* If the service JUSTUS 2 &#039;&#039;&#039;is not visible&#039;&#039;&#039;, then you are probably missing the necessary entitlement. Go to [[Registration/bwForCluster/Entitlement|step A]] to check this.&lt;br /&gt;
* By clicking on &#039;&#039;&#039;Register&#039;&#039;&#039; you automatically subscribe to the &#039;&#039;&#039;[https://imap.uni-ulm.de/lists/info/justus2-users justus2-users]&#039;&#039;&#039; mailing list. The list provides news and information related to the bwForCluster JUSTUS 2 for computational chemistry and quantum sciences in Ulm.&lt;br /&gt;
* When you &#039;&#039;&#039;de-register&#039;&#039;&#039; your account from the cluster, you automatically unsubscribe from the list.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
5. JUSTUS 2 uses a &#039;&#039;&#039;2-factor authentication&#039;&#039;&#039; (2FA) mechanism to increase security.&lt;br /&gt;
If you have never registered a 2FA token on bwIDM, the following error message will appear:&lt;br /&gt;
[[File:Bwidm-3-red.png|center|600px|thumb|Second factor missing.]]&lt;br /&gt;
&lt;br /&gt;
Use this &#039;&#039;&#039;[https://login.bwidm.de/user/twofa.xhtml link]&#039;&#039;&#039; or select &#039;&#039;&#039;Index -&amp;gt; My Tokens&#039;&#039;&#039; in the main menu.&lt;br /&gt;
To register a new token, please follow these &#039;&#039;&#039;[[Registration/2FA|instructions]]&#039;&#039;&#039;.&lt;br /&gt;
Please complete this step before continuing.&lt;br /&gt;
&lt;br /&gt;
6. Read the Terms of Use (&#039;&#039;&#039;Nutzungsbedingungen und -richtlinien&#039;&#039;&#039;), place a check mark next to &#039;&#039;&#039;I have read and accepted the terms of use&#039;&#039;&#039; and click &#039;&#039;&#039;Register/Registrieren&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
7. Set a service password for JUSTUS 2 and click &#039;&#039;&#039;Save/Speichern&#039;&#039;&#039;.&lt;br /&gt;
Be sure to use a secure password that is different from any other passwords you currently use or have used on other systems.&lt;br /&gt;
[[File:BwIDM-passwd.png|center|800px|Set service password]]&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
Setting a service password is mandatory for access to any bwForCluster.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p style=&amp;quot;text-align:right;&amp;quot;&amp;gt;[[Registration/bwForCluster| Go back to bwForCluster Registration Home]]&amp;lt;/p&amp;gt;&lt;/div&gt;</summary>
		<author><name>C Mosch</name></author>
	</entry>
	<entry>
		<id>https://wiki.bwhpc.de/wiki/index.php?title=Registration/bwForCluster/JUSTUS2&amp;diff=11907</id>
		<title>Registration/bwForCluster/JUSTUS2</title>
		<link rel="alternate" type="text/html" href="https://wiki.bwhpc.de/wiki/index.php?title=Registration/bwForCluster/JUSTUS2&amp;diff=11907"/>
		<updated>2023-04-05T18:27:14Z</updated>

		<summary type="html">&lt;p&gt;C Mosch: /* Registration at the bwForCluster JUSTUS 2 */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=  Registration at the bwForCluster JUSTUS 2 = &lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
You can return to the registration website at any time, in order to review your registration details, change/reset your service password or de-register from the service by yourself.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
After having completed steps A+B please visit the &#039;&#039;&#039;[https://login.bwidm.de bwForCluster JUSTUS 2 registration page]&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
Do the following steps to complete registration:&lt;br /&gt;
&lt;br /&gt;
1. Select your home organization from the list on the main page and click &#039;&#039;&#039;Proceed&#039;&#039;&#039; or &#039;&#039;&#039;Fortfahren&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-login.png|center|600px|thumb|Select your home organization]]&lt;br /&gt;
&lt;br /&gt;
2. You will be directed to the &#039;&#039;Identity Provider&#039;&#039; of your home organization.&lt;br /&gt;
Enter the username and password of your &#039;&#039;&#039;home organization&#039;&#039;&#039; (usually these credentials are also used for other services like email) and click &#039;&#039;&#039;Login/Einloggen&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
3. You will be redirected back to the registration page &#039;&#039;&#039;https://login.bwidm.de&#039;&#039;&#039;.&lt;br /&gt;
When you log in to bwIDM for the first time, an overview will appear, with the account information that your home institution submits to the system.&lt;br /&gt;
Please verify that all data is valid and then click &#039;&#039;&#039;Continue/Weiter&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
4. After you have successfully logged into the bwIDM system, you will be greeted by a welcome screen that displays all the statewide services you have access to.&lt;br /&gt;
There you will find a field labeled &#039;&#039;&#039;bwForCluster JUSTUS 2&#039;&#039;&#039;.&lt;br /&gt;
Click &#039;&#039;&#039;Register/Registrieren&#039;&#039;&#039; to start the registration process.&lt;br /&gt;
[[File:BwIDM-reg.png|center|frame|Register for JUSTUS 2]]&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
* If the service JUSTUS 2 &#039;&#039;&#039;is not visible&#039;&#039;&#039;, then you are probably missing the necessary entitlement. Go to [[Registration/bwForCluster/Entitlement|step A]] to check this.&lt;br /&gt;
* By clicking on &#039;&#039;&#039;Register&#039;&#039;&#039; you automatically subscribe to the &#039;&#039;&#039;[https://imap.uni-ulm.de/lists/info/justus2-users justus2-users]&#039;&#039;&#039; mailing list. The list provides news and information related to the bwForCluster JUSTUS 2 for computational chemistry and quantum sciences in Ulm.&lt;br /&gt;
* When you &#039;&#039;&#039;De-Register&#039;&#039;&#039; your account from the cluster, you automatically unsubscribe from the list.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
5. JUSTUS 2 uses a &#039;&#039;&#039;2-factor authentication&#039;&#039;&#039; (2FA) mechanism to increase security.&lt;br /&gt;
If you have never registered a 2FA token on bwIDM, the following error message will appear:&lt;br /&gt;
[[File:Bwidm-3-red.png|center|600px|thumb|Second factor missing.]]&lt;br /&gt;
&lt;br /&gt;
Use this &#039;&#039;&#039;[https://login.bwidm.de/user/twofa.xhtml link]&#039;&#039;&#039; or select &#039;&#039;&#039;Index -&amp;gt; My Tokens&#039;&#039;&#039; in the main menu.&lt;br /&gt;
To register a new token, please follow these &#039;&#039;&#039;[[Registration/2FA|instructions]]&#039;&#039;&#039;.&lt;br /&gt;
Please complete this step before continuing.&lt;br /&gt;
&lt;br /&gt;
6. Read the Terms of Use (&#039;&#039;&#039;Nutzungsbedingungen und -richtlinien&#039;&#039;&#039;), place a check mark next to &#039;&#039;&#039;I have read and accepted the terms of use&#039;&#039;&#039; and click &#039;&#039;&#039;Register/Registrieren&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
7. Set a service password for JUSTUS 2 and click &#039;&#039;&#039;Save/Speichern&#039;&#039;&#039;.&lt;br /&gt;
Be sure to use a secure password that is different from any other passwords you currently use or have used on other systems.&lt;br /&gt;
[[File:BwIDM-passwd.png|center|800px|Set service password]]&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
Setting a service password is mandatory for access to any bwForCluster.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p style=&amp;quot;text-align:right;&amp;quot;&amp;gt;[[Registration/bwForCluster| Go back to bwForCluster Registration Home]]&amp;lt;/p&amp;gt;&lt;/div&gt;</summary>
		<author><name>C Mosch</name></author>
	</entry>
	<entry>
		<id>https://wiki.bwhpc.de/wiki/index.php?title=Registration/bwForCluster/JUSTUS2&amp;diff=11906</id>
		<title>Registration/bwForCluster/JUSTUS2</title>
		<link rel="alternate" type="text/html" href="https://wiki.bwhpc.de/wiki/index.php?title=Registration/bwForCluster/JUSTUS2&amp;diff=11906"/>
		<updated>2023-04-05T18:22:00Z</updated>

		<summary type="html">&lt;p&gt;C Mosch: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=  Registration at the bwForCluster JUSTUS 2 = &lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
You can return to the registration website at any time, in order to review your registration details, change/reset your service password or de-register from the service by yourself.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
After having completed steps A+B please visit the &#039;&#039;&#039;[https://login.bwidm.de bwForCluster JUSTUS 2 registration page]&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
Do the following steps to complete registration:&lt;br /&gt;
&lt;br /&gt;
1. Select your home organization from the list on the main page and click &#039;&#039;&#039;Proceed&#039;&#039;&#039; or &#039;&#039;&#039;Fortfahren&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-login.png|center|600px|thumb|Select your home organization]]&lt;br /&gt;
&lt;br /&gt;
2. You will be directed to the &#039;&#039;Identity Provider&#039;&#039; of your home organization.&lt;br /&gt;
Enter the username and password of your &#039;&#039;&#039;home organization&#039;&#039;&#039; (usually these credentials are also used for other services like email) and click &#039;&#039;&#039;Login/Einloggen&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
3. You will be redirected back to the registration page &#039;&#039;&#039;https://login.bwidm.de&#039;&#039;&#039;.&lt;br /&gt;
When you log in to bwIDM for the first time, an overview will appear, with the account information that your home institution submits to the system.&lt;br /&gt;
Please verify that all data is valid and then click &#039;&#039;&#039;Continue/Weiter&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
4. After you have successfully logged into the bwIDM system, you will be greeted by a welcome screen that displays all the statewide services you have access to.&lt;br /&gt;
There you will find a field labeled &#039;&#039;&#039;bwForCluster JUSTUS 2&#039;&#039;&#039;.&lt;br /&gt;
Click &#039;&#039;&#039;Register/Registrieren&#039;&#039;&#039; to start the registration process.&lt;br /&gt;
[[File:BwIDM-reg.png|center|frame|Register for JUSTUS 2]]&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
* If you do not see the service, then you are probably missing the necessary entitlement. Go to [[Registration/bwForCluster/Entitlement|step A]] to check this.&lt;br /&gt;
* By clicking on &#039;&#039;&#039;Register&#039;&#039;&#039; you automatically subscribe to the &#039;&#039;&#039;[https://imap.uni-ulm.de/lists/info/justus2-users justus2-users]&#039;&#039;&#039; mailing list. The list provides news and information related to the bwForCluster JUSTUS 2 for computational chemistry and quantum sciences in Ulm.&lt;br /&gt;
* When you &#039;&#039;&#039;De-Register&#039;&#039;&#039; your account from the cluster, you automatically unsubscribe from the list.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
5. JUSTUS 2 uses a &#039;&#039;&#039;2-factor authentication&#039;&#039;&#039; (2FA) mechanism to increase security.&lt;br /&gt;
If you have never registered a 2FA token on bwIDM, the following error message will appear:&lt;br /&gt;
[[File:Bwidm-3-red.png|center|600px|thumb|Second factor missing.]]&lt;br /&gt;
&lt;br /&gt;
Use this &#039;&#039;&#039;[https://login.bwidm.de/user/twofa.xhtml link]&#039;&#039;&#039; or select &#039;&#039;&#039;Index -&amp;gt; My Tokens&#039;&#039;&#039; in the main menu.&lt;br /&gt;
To register a new token, please follow these &#039;&#039;&#039;[[Registration/2FA|instructions]]&#039;&#039;&#039;.&lt;br /&gt;
Please complete this step before continuing.&lt;br /&gt;
&lt;br /&gt;
6. Read the Terms of Use (&#039;&#039;&#039;Nutzungsbedingungen und -richtlinien&#039;&#039;&#039;), place a check mark next to &#039;&#039;&#039;I have read and accepted the terms of use&#039;&#039;&#039; and click &#039;&#039;&#039;Register/Registrieren&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
7. Set a service password for JUSTUS 2 and click &#039;&#039;&#039;Save/Speichern&#039;&#039;&#039;.&lt;br /&gt;
Be sure to use a secure password that is different from any other passwords you currently use or have used on other systems.&lt;br /&gt;
[[File:BwIDM-passwd.png|center|800px|Set service password]]&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
Setting a service password is mandatory for access to any bwForCluster.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p style=&amp;quot;text-align:right;&amp;quot;&amp;gt;[[Registration/bwForCluster| Go back to bwForCluster Registration Home]]&amp;lt;/p&amp;gt;&lt;/div&gt;</summary>
		<author><name>C Mosch</name></author>
	</entry>
	<entry>
		<id>https://wiki.bwhpc.de/wiki/index.php?title=Registration/bwForCluster/JUSTUS2&amp;diff=11905</id>
		<title>Registration/bwForCluster/JUSTUS2</title>
		<link rel="alternate" type="text/html" href="https://wiki.bwhpc.de/wiki/index.php?title=Registration/bwForCluster/JUSTUS2&amp;diff=11905"/>
		<updated>2023-04-05T18:17:35Z</updated>

		<summary type="html">&lt;p&gt;C Mosch: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=  Registration at the bwForCluster JUSTUS 2 = &lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
You can return to the registration website at any time, in order to review your registration details, change/reset your service password or de-register from the service by yourself.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
After having completed steps A+B please visit the &#039;&#039;&#039;[https://login.bwidm.de bwForCluster JUSTUS 2 registration page]&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
Do the following steps to complete registration:&lt;br /&gt;
&lt;br /&gt;
1. Select your home organization from the list on the main page and click &#039;&#039;&#039;Proceed&#039;&#039;&#039; or &#039;&#039;&#039;Fortfahren&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-login.png|center|600px|thumb|Select your home organization]]&lt;br /&gt;
&lt;br /&gt;
2. You will be directed to the &#039;&#039;Identity Provider&#039;&#039; of your home organization.&lt;br /&gt;
Enter the username and password of your &#039;&#039;&#039;home organization&#039;&#039;&#039; (usually these credentials are also used for other services like email) and click &#039;&#039;&#039;Login/Einloggen&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
3. You will be redirected back to the registration page &#039;&#039;&#039;https://login.bwidm.de&#039;&#039;&#039;.&lt;br /&gt;
When you log in to bwIDM for the first time, an overview will appear, with the account information that your home institution submits to the system.&lt;br /&gt;
Please verify that all data is valid and then click &#039;&#039;&#039;Continue/Weiter&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
4. After you have successfully logged into the bwIDM system, you will be greeted by a welcome screen that displays all the statewide services you have access to.&lt;br /&gt;
There you will find a field labeled &#039;&#039;&#039;bwForCluster JUSTUS 2&#039;&#039;&#039;.&lt;br /&gt;
Click &#039;&#039;&#039;Register/Registrieren&#039;&#039;&#039; to start the registration process.&lt;br /&gt;
[[File:BwIDM-reg.png|center|frame|Register for JUSTUS 2]]&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
* If you do not see the service, then you are probably missing the necessary entitlement. Go to [[Registration/bwForCluster/Entitlement|step A]] to check this.&lt;br /&gt;
* By clicking on &#039;&#039;&#039;Register&#039;&#039;&#039; you automatically subscribe to the &#039;&#039;&#039;[https://imap.uni-ulm.de/lists/info/justus2-users justus2-users]&#039;&#039;&#039; mailing list. It provides news and information related to the bwForCluster JUSTUS 2 for computational chemistry and quantum sciences in Ulm.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
5. JUSTUS 2 uses a &#039;&#039;&#039;2-factor authentication&#039;&#039;&#039; (2FA) mechanism to increase security.&lt;br /&gt;
If you have never registered a 2FA token on bwIDM, the following error message will appear:&lt;br /&gt;
[[File:Bwidm-3-red.png|center|600px|thumb|Second factor missing.]]&lt;br /&gt;
&lt;br /&gt;
Use this &#039;&#039;&#039;[https://login.bwidm.de/user/twofa.xhtml link]&#039;&#039;&#039; or select &#039;&#039;&#039;Index -&amp;gt; My Tokens&#039;&#039;&#039; in the main menu.&lt;br /&gt;
To register a new token, please follow these &#039;&#039;&#039;[[Registration/2FA|instructions]]&#039;&#039;&#039;.&lt;br /&gt;
Please complete this step before continuing.&lt;br /&gt;
&lt;br /&gt;
6. Read the Terms of Use (&#039;&#039;&#039;Nutzungsbedingungen und -richtlinien&#039;&#039;&#039;), place a check mark next to &#039;&#039;&#039;I have read and accepted the terms of use&#039;&#039;&#039; and click &#039;&#039;&#039;Register/Registrieren&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
7. Set a service password for JUSTUS 2 and click &#039;&#039;&#039;Save/Speichern&#039;&#039;&#039;.&lt;br /&gt;
Be sure to use a secure password that is different from any other passwords you currently use or have used on other systems.&lt;br /&gt;
[[File:BwIDM-passwd.png|center|800px|Set service password]]&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
Setting a service password is mandatory for access to any bwForCluster.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
&lt;br /&gt;
&amp;lt;p style=&amp;quot;text-align:right;&amp;quot;&amp;gt;[[Registration/bwForCluster| Go back to bwForCluster Registration Home]]&amp;lt;/p&amp;gt;&lt;/div&gt;</summary>
		<author><name>C Mosch</name></author>
	</entry>
	<entry>
		<id>https://wiki.bwhpc.de/wiki/index.php?title=JUSTUS2&amp;diff=10571</id>
		<title>JUSTUS2</title>
		<link rel="alternate" type="text/html" href="https://wiki.bwhpc.de/wiki/index.php?title=JUSTUS2&amp;diff=10571"/>
		<updated>2022-07-19T14:12:35Z</updated>

		<summary type="html">&lt;p&gt;C Mosch: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[File:JUSTUS2_pre.jpg|right|frameless|thumb|alt=JUSTUS2 |upright=0.4| JUSTUS 2 ]]&lt;br /&gt;
Note: This page replaces replace [[:Category:BwForCluster_JUSTUS_2]] as an overview page.&lt;br /&gt;
&lt;br /&gt;
The &#039;&#039;&#039;bwForCluster JUSTUS2&#039;&#039;&#039; is a high-performance computer dedicated to  Computational Chemistry and Quantum Sciences and  located at Ulm University.&lt;br /&gt;
&amp;lt;!--{| style=&amp;quot;  background:#FEF4AB; width:100%;&amp;quot; &lt;br /&gt;
| style=&amp;quot;padding:8px; background:#FFE856; font-size:120%; font-weight:bold;  text-align:left&amp;quot; | News&lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
|}&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;  background:#eeeefe; width:100%;&amp;quot; &lt;br /&gt;
| style=&amp;quot;padding:8px; background:#dedefe; font-size:120%; font-weight:bold;  text-align:left&amp;quot; | Training &amp;amp; Support&lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
* [[JUSTUS2/Getting Started|Getting Started]]&lt;br /&gt;
* E-Learning Course [https://training.bwhpc.de/goto.php?target=crs_629_rcodeM6n48kAUsT&amp;amp;client_id=BWHPC  Introduction to JUSTUS2 ] (URL will be a direct link to the course)&lt;br /&gt;
* [https://bw-support.scc.kit.edu/ Submit a Ticket] to support unit &#039;bwForCluster Justus&#039;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;  background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
| style=&amp;quot;padding:8px; background:#cef2e0; font-size:120%; font-weight:bold;  text-align:left&amp;quot; | User Documentation&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* [[JUSTUS2/Login|Login]]&lt;br /&gt;
* [[JUSTUS2/Hardware|Hardware ]]&lt;br /&gt;
* [[JUSTUS2/Hardware#Storage_Architecture|File Systems]] &lt;br /&gt;
&lt;br /&gt;
* [[JUSTUS2/Software|Software]] - pre-installed (scientific) software&lt;br /&gt;
* [[JUSTUS2/Slurm|Batch System (Slurm)]] - running compute jobs&lt;br /&gt;
* [[JUSTUS2/Visualization|Visualisation]] - using graphical programs&lt;br /&gt;
* [[Development]] - compiling software, parallel programming, etc&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;  background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
| style=&amp;quot;padding:8px; background:#cef2e0; font-size:120%; font-weight:bold;  text-align:left&amp;quot; | Cluster Funding&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* [[JUSTUS2/Acknowledgement|Acknowledge]] the cluster in your publications&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>C Mosch</name></author>
	</entry>
	<entry>
		<id>https://wiki.bwhpc.de/wiki/index.php?title=Registration/2FA&amp;diff=10336</id>
		<title>Registration/2FA</title>
		<link rel="alternate" type="text/html" href="https://wiki.bwhpc.de/wiki/index.php?title=Registration/2FA&amp;diff=10336"/>
		<updated>2022-05-10T09:20:19Z</updated>

		<summary type="html">&lt;p&gt;C Mosch: /* Lost Token */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Generate a Second Factor (2FA) =&lt;br /&gt;
&lt;br /&gt;
To improve security a &#039;&#039;&#039;2-factor authentication mechanism (2FA)&#039;&#039;&#039; is being enforced for logins to bwUniCluster/bwForClusters. In addition to the service password a second value, the &#039;&#039;&#039;second factor&#039;&#039;&#039;, has to be entered on every login.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== How 2FA works ==&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
It is very important that the device that generates the One-Time Passwords and the device which is used to log into the bwUniCluster/bwForClusters are not the same.&lt;br /&gt;
Otherwise an attacker who gains access to your system can steal both the service password and the secret key of the Software Token application, which allows them to generate One-Time Passwords and log into the HPC system without your knowledge.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
[[File:2fa token code.jpg|right|200px|thumb|Hardware Token for TOTP]]&lt;br /&gt;
On the bwUniCluster/bwForClusters we use six-digit, auto-generated, time-dependent &#039;&#039;&#039;one-time passwords&#039;&#039;&#039; (TOTP). These passwords are generated by a piece of software which is part of a special hardware device (a &#039;&#039;&#039;hardware token&#039;&#039;&#039;) or of a normal application running on a common device (a &#039;&#039;&#039;software token&#039;&#039;&#039;).&lt;br /&gt;
&lt;br /&gt;
The Token has to be synchronized with a central server before it can be used for authentication and then generates an endless stream of six-digit values (TOTPs) which can only be used once and are only valid during a very short interval of time. This makes it much harder for potential attackers to access the HPC system, even if they know the regular service password.&lt;br /&gt;
&lt;br /&gt;
Typically a new TOTP value is generated every 30 seconds. When the current TOTP value has once been used successfully for a login, it is depleted and one has to wait up to 30 seconds for the next TOTP value. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:Otpapp.png|right|150px|thumb|Source: https://getaegis.app]]&lt;br /&gt;
&lt;br /&gt;
The most common solution is to use a mobile device (e.g. your smartphone or tablet) as a Software Token by installing one of the following apps:&lt;br /&gt;
* Google Authenticator for [https://play.google.com/store/apps/details?id=com.google.android.apps.authenticator2 Android] or [https://apps.apple.com/de/app/google-authenticator/id388497605 iOS]&lt;br /&gt;
* Microsoft Authenticator for [https://play.google.com/store/apps/details?id=com.azure.authenticator Android] or [https://apps.apple.com/de/app/microsoft-authenticator/id983156458 iOS] ([https://www.microsoft.com/de-de/security/mobile-authenticator-app Web Page])&lt;br /&gt;
* LastPass Authenticator for [https://play.google.com/store/apps/details?id=com.lastpass.authenticator Android], [https://apps.apple.com/us/app/lastpass-authenticator/id1079110004 iOS] or [https://lastpass.com/auth/ Windows]&lt;br /&gt;
* Aegis Authenticator for [https://play.google.com/store/apps/details?id=com.beemdevelopment.aegis Android (Google Play)] or [https://f-droid.org/en/packages/com.beemdevelopment.aegis/ Android (F-Droid)] ([https://getaegis.app/ Web Page])&lt;br /&gt;
* andOTP Authenticator for [https://play.google.com/store/apps/details?id=org.shadowice.flocke.andotp Android (Google Play)] or [https://f-droid.org/packages/org.shadowice.flocke.andotp/ Android (F-Droid)] ([https://github.com/andOTP/andOTP GitHub])&lt;br /&gt;
* OTP Auth for [https://apps.apple.com/app/otp-auth/id659877384 iOS]&lt;br /&gt;
* (Authy for [https://play.google.com/store/apps/details?id=com.authy.authy Android], [https://apps.apple.com/us/app/authy/id494168017 iOS], [https://authy.com/download/ Mac, Windows or Linux]) requires account&lt;br /&gt;
* (On Linux you can use [https://keepassxc.org/ KeepassXC] or [https://github.com/paolostivanin/OTPClient otpclient])&lt;br /&gt;
&lt;br /&gt;
These are only suggestions. You can use any application compatible with the [https://tools.ietf.org/html/rfc6238 TOTP] standard.&lt;br /&gt;
&lt;br /&gt;
If you don&#039;t want to use a smartphone, we recommend using a hardware token, such as Yubikey or another TOTP-compatible device. [https://www.yubico.com/resources/glossary/yubico-otp/ Yubico OTP] is also supported if you want to use your Yubikey without depending on having a six-digit code displayed. But you can also use the Yubikey as a generator for six-digit [https://www.yubico.com/resources/glossary/oath-totp/ TOTP].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Token Management =&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
* Create at least two separate tokens: &#039;&#039;&#039;FIRST&#039;&#039;&#039; set up a software/hardware TOTP token. &#039;&#039;&#039;THEN&#039;&#039;&#039; create and print a &amp;quot;backup TAN list&amp;quot;. Never create the &amp;quot;backup TAN list&amp;quot; first.&lt;br /&gt;
* If you lose access to all your tokens, you will not be able to create new tokens and support will have to reset your tokens manually.&lt;br /&gt;
* The &amp;quot;backup TAN list&amp;quot; should always be created and printed in a &#039;&#039;&#039;second step&#039;&#039;&#039;. The printout should be kept in a separate place for emergencies.&lt;br /&gt;
* Please clean up your second factors as soon as you have created new tokens. Tokens that can no longer be used (e.g. because not initialized, smartphone/Yubikey lost, etc.) or an old backup TAN list where you have already used all TANs or there is no printout should be deactivated and deleted.&lt;br /&gt;
* Returning users who have already activated one or more tokens must first verify their token before they can create new tokens, see section [[Registration/2FA#Returning_Users|Returning Users]].&lt;br /&gt;
* &#039;&#039;&#039;Please disable all privacy tools, ad blockers and further add-ons when registering new tokens.&#039;&#039;&#039; These tools prevent the registration website from generating new security tokens. When the problems remains (you can not generate the QR code or can not confirm it by clicking CHECK), please try once more with an entirely new unmodified web browser profile.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;bwUniCluster/bwForCluster Tokens&#039;&#039;&#039; are generally managed via the &#039;&#039;&#039;Index -&amp;gt; My Tokens&#039;&#039;&#039; menu entry on the registration pages for the clusters. Here you can register, activate, deactivate and delete tokens.&lt;br /&gt;
&lt;br /&gt;
To activate the second factor, &#039;&#039;&#039;please perform the following steps:&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
1. &#039;&#039;&#039;Select the registration server of the cluster&#039;&#039;&#039; for which you want to create a second factor and login to it:&amp;lt;/br&amp;gt; &amp;amp;rarr; [https://login.bwidm.de/user/twofa.xhtml Registration server for &#039;&#039;&#039;bwUniCluster 2.0&#039;&#039;&#039; and &#039;&#039;&#039;bwForCluster JUSTUS 2&#039;&#039;&#039;] (2FA tokens are valid for both clusters; KIT members can reuse their existing hardware and software tokens)&amp;lt;/br&amp;gt; &amp;amp;rarr; [https://bwservices.uni-heidelberg.de//user/twofa.xhtml Registration server for &#039;&#039;&#039;bwForCluster MLS&amp;amp;WISO&#039;&#039;&#039;]&lt;br /&gt;
[[File:BwIDM-twofa.png|center|600px|thumb|My Tokens]]&lt;br /&gt;
&lt;br /&gt;
2. &#039;&#039;&#039;Register a new &amp;quot;[[Registration/2FA#Registering_a_new_Software_Token_using_a_Mobile_APP|Smartphone Token]]&amp;quot;&#039;&#039;&#039; or if you own a [https://www.yubico.com/ Yubikey]&#039;&#039;&#039; register a new &amp;quot;[[Registration/2FA#Registering_a_new_Yubikey_OTP_Token|Yubikey Token]]&amp;quot;&#039;&#039;&#039; or &#039;&#039;&#039;&amp;quot;[[Registration/2FA#Registering_a_new_Yubikey_OATH_TOTP_Token|Yubikey OATH TOTP Token]]&amp;quot;&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
3. &#039;&#039;&#039;Register a new &amp;quot;[[Registration/2FA#Backup_TAN_List|TAN List]]&amp;quot; (backup TAN list)&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
4. Repeat step 2. for additional tokens.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Registering a new Software Token using a Mobile APP ==&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
Please disable all privacy tools, ad blockers and further add-ons when registering new tokens.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
1. Select the [[Registration/2FA#Token_Management|registration server]] of the cluster for which you want to create a second factor and login to it.&lt;br /&gt;
&lt;br /&gt;
2. Registering a new Token starts with a click &#039;&#039;&#039;NEW SMARTPHONE TOKEN&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-token.png|center|600px|thumb|Create a new Token]]&lt;br /&gt;
&lt;br /&gt;
3. A new window opens. Click &#039;&#039;&#039;Start&#039;&#039;&#039; to generate a new &#039;&#039;&#039;QR code&#039;&#039;&#039;.&lt;br /&gt;
This may take a while.&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
The QR code contains a key which has to remain secret.&lt;br /&gt;
Only use the QR code to link your software token app with bwIDM/bwServices in the next step.&lt;br /&gt;
Do not save the QR code, print it out or share it with someone else.&lt;br /&gt;
|}&lt;br /&gt;
[[File:BwIDM-qr.png|center|600px|thumb|QR Code for Mobile App]]&lt;br /&gt;
&lt;br /&gt;
4. Start the software token app on your separate device and scan the QR code.&lt;br /&gt;
The exact process is a little bit different in every app, but is usually started by pressing on a button with a plus (+) sign or an icon of a QR code.&lt;br /&gt;
&lt;br /&gt;
5. Once the QR code has been loaded into your Software Token app there should be a new entry called &#039;&#039;&#039;bwIDM&#039;&#039;&#039; (bwUniCluster and JUSTUS 2) or &#039;&#039;&#039;bwServices&#039;&#039;&#039; (MLS&amp;amp;WISO).&lt;br /&gt;
Generate an One-Time-Password by pressing on this entry or selecting the appropriate button/menu item.&lt;br /&gt;
You will receive a six-digit code.&lt;br /&gt;
Enter this code into the field labeled &amp;quot;Current code:&amp;quot; in your bwIDM browser window to prove that the connection has worked and then click &#039;&#039;&#039;CHECK&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
6. If everything worked as expected, you will be returned to the &#039;&#039;&#039;My Tokens&#039;&#039;&#039; screen and there will be a new entry for your software token.&lt;br /&gt;
[[File:BwIDM-app.png|center|400px|thumb|Success]]&lt;br /&gt;
&lt;br /&gt;
7. Repeat the process to register additional tokens.&lt;br /&gt;
Please register at least the &amp;quot;Backup TAN list&amp;quot; in addition to the hardware/software token you plan to use regularly.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Registering a new Yubikey OTP Token ==&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
Please disable all privacy tools, ad blockers and further add-ons when registering new tokens.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
[https://developers.yubico.com/OTP/OTPs_Explained.html Yubikey OTP] is even easier and you don&#039;t need a device that displays the six-digit code or extra software.&lt;br /&gt;
New Yubikeys are already configured to provide Yubikey OTP in slot 1.&lt;br /&gt;
If you need to configure your Yubikey, read this [[Registration/2FA/Yubikey|documentation]].&lt;br /&gt;
&lt;br /&gt;
1. Select the [[Registration/2FA#Token_Management|registration server]] of the cluster for which you want to create a second factor and login to it.&lt;br /&gt;
&lt;br /&gt;
2. If you want to use [https://www.yubico.com/resources/glossary/yubico-otp/ Yubico OTP], you can click &#039;&#039;&#039;NEW YUBIKEY TOKEN&#039;&#039;&#039; instead.&lt;br /&gt;
[[File:BwIDM-token.png|center|600px|thumb|Generate Yubikey OTP]]&lt;br /&gt;
&lt;br /&gt;
3. Yubikey OTP is configured to slot 1 on new Yubikeys, so you only need to click in the text box and then touch the metal part of your Yubikey.&lt;br /&gt;
Please refer to this [[Registration/2FA/Yubikey|documentation]] on how to configure your Yubikey.&lt;br /&gt;
[[File:BwIDM-yubikey.png|center|400px|thumb|Yubikey OTP]]&lt;br /&gt;
&lt;br /&gt;
4. If everything worked as expected, you will be returned to the &#039;&#039;&#039;My Tokens&#039;&#039;&#039; screen and there will be a new entry for your Yubikey.&lt;br /&gt;
[[File:BwIDM-yubikey2.png|center|400px|thumb|Success]]&lt;br /&gt;
&lt;br /&gt;
5. Repeat the process to register additional tokens.&lt;br /&gt;
Please register at least the &amp;quot;Backup TAN list&amp;quot; in addition to the hardware/software token you plan to use regularly.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Registering a new Yubikey OATH TOTP Token ==&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
Please disable all privacy tools, ad blockers and further add-ons when registering new tokens.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
[https://developers.yubico.com/OATH/ Yubikey OATH TOTP] generates the TANs on your Yubikey and therefore you can use different computers and Android phones to generate these codes.&lt;br /&gt;
Please download and install [https://developers.yubico.com/OATH/YubiKey_OATH_software.html Yubico Authenticator] for Desktop (or Android) first.&lt;br /&gt;
Insert your Yubikey in your computer.&lt;br /&gt;
&amp;quot;Yubikey OTP&amp;quot; (not &amp;quot;Yubikey OATH TOTP&amp;quot;) is even easier and you don&#039;t need a device that displays the six-digit code or extra software (go to step [[Registration/2FA#Yubikey_OTP|Yubikey OTP]]).&lt;br /&gt;
&lt;br /&gt;
1. Select the [[Registration/2FA#Token_Management|registration server]] of the cluster for which you want to create a second factor and login to it.&lt;br /&gt;
&lt;br /&gt;
2. Registering a new Token starts with a click &#039;&#039;&#039;NEW SMARTPHONE TOKEN&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-token.png|center|600px|thumb|Create a new Token]]&lt;br /&gt;
&lt;br /&gt;
3. A new window opens. Click &#039;&#039;&#039;Start&#039;&#039;&#039; to generate a new &#039;&#039;&#039;QR code&#039;&#039;&#039;.&lt;br /&gt;
This may take a while.&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
The QR code contains a key which has to remain secret.&lt;br /&gt;
Only use the QR code to link your software token app with bwIDM/bwServices in the next step.&lt;br /&gt;
Do not save the QR code, print it out or share it with someone else.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
4. Start the Yubico Authenticator on your OS, click the three vertical dots in the upper right corner and select &#039;&#039;&#039;Scan QR code&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-yubi1.png|center|600px|thumb|QR Code and Yubico Authenticator on Linux]]&lt;br /&gt;
&lt;br /&gt;
5. Yubico Authenticator automatically translates the QR code to a new entry called &#039;&#039;&#039;bwIDM&#039;&#039;&#039; or &#039;&#039;&#039;bwServices&#039;&#039;&#039; (MLS&amp;amp;WISO).&lt;br /&gt;
Click &#039;&#039;&#039;Add account&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-yubi2.png|center|600px|thumb|Create new TOTP on Yubico Authenticator]]&lt;br /&gt;
&lt;br /&gt;
6. You will receive a six-digit code.&lt;br /&gt;
Enter this code into the field labeled &amp;quot;Current code:&amp;quot; in your bwIDM browser window to prove that the connection has worked and then click &#039;&#039;&#039;CHECK&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-yubi3.png|center|600px|thumb|Verify TOTP]]&lt;br /&gt;
&lt;br /&gt;
7. If everything worked as expected, you will be returned to the &#039;&#039;&#039;My Tokens&#039;&#039;&#039; screen and there will be a new entry for your software token.&lt;br /&gt;
[[File:BwIDM-app.png|center|400px|thumb|Success]]&lt;br /&gt;
&lt;br /&gt;
8. Repeat the process to register additional tokens.&lt;br /&gt;
Please register at least the &amp;quot;Backup TAN list&amp;quot; in addition to the hardware/software token you plan to use regularly.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Backup TAN List ==&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
Passwords from the &amp;quot;Backup TAN list&amp;quot; should only be used if no other token is left.&lt;br /&gt;
Please do not use the Backup TANs for regular cluster login, because you have only a limited number of TANs.&lt;br /&gt;
Each TAN can only be used once.&lt;br /&gt;
Please disable all privacy tools, ad blockers and further add-ons when registering a new Backup TAN list.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
1. Select the [[Registration/2FA#Token_Management|registration server]] of the cluster for which you want to create a second factor and login to it.&lt;br /&gt;
&lt;br /&gt;
2. Please create at least one &amp;quot;Backup TAN list&amp;quot; by clicking &#039;&#039;&#039;CREATE NEW TAN LIST&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-token.png|center|600px|thumb|Generate Backup TAN list]]&lt;br /&gt;
&lt;br /&gt;
3. Click &#039;&#039;&#039;START&#039;&#039;&#039;. You will be redirected to the &#039;&#039;&#039;My Tokens&#039;&#039;&#039; screen and there will be a new entry for your backup TANs.&lt;br /&gt;
[[File:BwIDM-tan.png|center|400px|thumb|Success]]&lt;br /&gt;
&lt;br /&gt;
4. Click &#039;&#039;&#039;SHOW TANS&#039;&#039;&#039;, print the codes and keep then in a separate place for emergencies.&lt;br /&gt;
[[File:JUSTUS-2-2FA-backup-TAN-list.png|center|800px|thumb|Print Backup TAN List]]&lt;br /&gt;
&lt;br /&gt;
5. Repeat the process to register additional tokens.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Deactivating a Token ==&lt;br /&gt;
&lt;br /&gt;
Click &#039;&#039;&#039;Disable&#039;&#039;&#039; next to the Token entry on the &#039;&#039;&#039;My Tokens&#039;&#039;&#039; screen.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Deleting a Token ==&lt;br /&gt;
&lt;br /&gt;
After a Token has been disabled a new button labeled &#039;&#039;&#039;Delete&#039;&#039;&#039; will appear. Click on it to delete the token.&lt;br /&gt;
&lt;br /&gt;
= Returning Users =&lt;br /&gt;
&lt;br /&gt;
Returning users who have already activated one or more tokens must first verify their token before they can create new tokens or deactivate/delete old ones.&lt;br /&gt;
If you no longer have valid tokens, you will not be able to create or manage tokens. &lt;br /&gt;
In this case, read the section [[Registration/2FA#Lost_Token|Lost Token]].&lt;br /&gt;
[[File:BwIDM-totp.png|center|400px|thumb|Returning users must first verify their token.]]&lt;br /&gt;
&lt;br /&gt;
= Lost Token =&lt;br /&gt;
&lt;br /&gt;
If you change your phone, please migrate your tokens first or register your new mobile app under &amp;quot;My Tokens&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;If you no longer have valid tokens (mobile app, hardware token, Yubikey or backup TAN, i.e. lost or broken smartphone), you can not access the section &amp;quot;My Tokens&amp;quot; anymore.&lt;br /&gt;
In this case you will need to contact the [https://bw-support.scc.kit.edu/ ticket system].&#039;&#039;&#039;&lt;br /&gt;
Open a ticket, include your user name, the name of the bwHPC cluster and ask for a reset of your 2FA tokens.&lt;br /&gt;
Please note that this process may take some time and also means additional work for the operators.&lt;/div&gt;</summary>
		<author><name>C Mosch</name></author>
	</entry>
	<entry>
		<id>https://wiki.bwhpc.de/wiki/index.php?title=Registration/2FA&amp;diff=10335</id>
		<title>Registration/2FA</title>
		<link rel="alternate" type="text/html" href="https://wiki.bwhpc.de/wiki/index.php?title=Registration/2FA&amp;diff=10335"/>
		<updated>2022-05-10T09:17:38Z</updated>

		<summary type="html">&lt;p&gt;C Mosch: /* Lost Token */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Generate a Second Factor (2FA) =&lt;br /&gt;
&lt;br /&gt;
To improve security a &#039;&#039;&#039;2-factor authentication mechanism (2FA)&#039;&#039;&#039; is being enforced for logins to bwUniCluster/bwForClusters. In addition to the service password a second value, the &#039;&#039;&#039;second factor&#039;&#039;&#039;, has to be entered on every login.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== How 2FA works ==&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
It is very important that the device that generates the One-Time Passwords and the device which is used to log into the bwUniCluster/bwForClusters are not the same.&lt;br /&gt;
Otherwise an attacker who gains access to your system can steal both the service password and the secret key of the Software Token application, which allows them to generate One-Time Passwords and log into the HPC system without your knowledge.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
[[File:2fa token code.jpg|right|200px|thumb|Hardware Token for TOTP]]&lt;br /&gt;
On the bwUniCluster/bwForClusters we use six-digit, auto-generated, time-dependent &#039;&#039;&#039;one-time passwords&#039;&#039;&#039; (TOTP). These passwords are generated by a piece of software which is part of a special hardware device (a &#039;&#039;&#039;hardware token&#039;&#039;&#039;) or of a normal application running on a common device (a &#039;&#039;&#039;software token&#039;&#039;&#039;).&lt;br /&gt;
&lt;br /&gt;
The Token has to be synchronized with a central server before it can be used for authentication and then generates an endless stream of six-digit values (TOTPs) which can only be used once and are only valid during a very short interval of time. This makes it much harder for potential attackers to access the HPC system, even if they know the regular service password.&lt;br /&gt;
&lt;br /&gt;
Typically a new TOTP value is generated every 30 seconds. When the current TOTP value has once been used successfully for a login, it is depleted and one has to wait up to 30 seconds for the next TOTP value. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:Otpapp.png|right|150px|thumb|Source: https://getaegis.app]]&lt;br /&gt;
&lt;br /&gt;
The most common solution is to use a mobile device (e.g. your smartphone or tablet) as a Software Token by installing one of the following apps:&lt;br /&gt;
* Google Authenticator for [https://play.google.com/store/apps/details?id=com.google.android.apps.authenticator2 Android] or [https://apps.apple.com/de/app/google-authenticator/id388497605 iOS]&lt;br /&gt;
* Microsoft Authenticator for [https://play.google.com/store/apps/details?id=com.azure.authenticator Android] or [https://apps.apple.com/de/app/microsoft-authenticator/id983156458 iOS] ([https://www.microsoft.com/de-de/security/mobile-authenticator-app Web Page])&lt;br /&gt;
* LastPass Authenticator for [https://play.google.com/store/apps/details?id=com.lastpass.authenticator Android], [https://apps.apple.com/us/app/lastpass-authenticator/id1079110004 iOS] or [https://lastpass.com/auth/ Windows]&lt;br /&gt;
* Aegis Authenticator for [https://play.google.com/store/apps/details?id=com.beemdevelopment.aegis Android (Google Play)] or [https://f-droid.org/en/packages/com.beemdevelopment.aegis/ Android (F-Droid)] ([https://getaegis.app/ Web Page])&lt;br /&gt;
* andOTP Authenticator for [https://play.google.com/store/apps/details?id=org.shadowice.flocke.andotp Android (Google Play)] or [https://f-droid.org/packages/org.shadowice.flocke.andotp/ Android (F-Droid)] ([https://github.com/andOTP/andOTP GitHub])&lt;br /&gt;
* OTP Auth for [https://apps.apple.com/app/otp-auth/id659877384 iOS]&lt;br /&gt;
* (Authy for [https://play.google.com/store/apps/details?id=com.authy.authy Android], [https://apps.apple.com/us/app/authy/id494168017 iOS], [https://authy.com/download/ Mac, Windows or Linux]) requires account&lt;br /&gt;
* (On Linux you can use [https://keepassxc.org/ KeepassXC] or [https://github.com/paolostivanin/OTPClient otpclient])&lt;br /&gt;
&lt;br /&gt;
These are only suggestions. You can use any application compatible with the [https://tools.ietf.org/html/rfc6238 TOTP] standard.&lt;br /&gt;
&lt;br /&gt;
If you don&#039;t want to use a smartphone, we recommend using a hardware token, such as Yubikey or another TOTP-compatible device. [https://www.yubico.com/resources/glossary/yubico-otp/ Yubico OTP] is also supported if you want to use your Yubikey without depending on having a six-digit code displayed. But you can also use the Yubikey as a generator for six-digit [https://www.yubico.com/resources/glossary/oath-totp/ TOTP].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Token Management =&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
* Create at least two separate tokens: &#039;&#039;&#039;FIRST&#039;&#039;&#039; set up a software/hardware TOTP token. &#039;&#039;&#039;THEN&#039;&#039;&#039; create and print a &amp;quot;backup TAN list&amp;quot;. Never create the &amp;quot;backup TAN list&amp;quot; first.&lt;br /&gt;
* If you lose access to all your tokens, you will not be able to create new tokens and support will have to reset your tokens manually.&lt;br /&gt;
* The &amp;quot;backup TAN list&amp;quot; should always be created and printed in a &#039;&#039;&#039;second step&#039;&#039;&#039;. The printout should be kept in a separate place for emergencies.&lt;br /&gt;
* Please clean up your second factors as soon as you have created new tokens. Tokens that can no longer be used (e.g. because not initialized, smartphone/Yubikey lost, etc.) or an old backup TAN list where you have already used all TANs or there is no printout should be deactivated and deleted.&lt;br /&gt;
* Returning users who have already activated one or more tokens must first verify their token before they can create new tokens, see section [[Registration/2FA#Returning_Users|Returning Users]].&lt;br /&gt;
* &#039;&#039;&#039;Please disable all privacy tools, ad blockers and further add-ons when registering new tokens.&#039;&#039;&#039; These tools prevent the registration website from generating new security tokens. When the problems remains (you can not generate the QR code or can not confirm it by clicking CHECK), please try once more with an entirely new unmodified web browser profile.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;bwUniCluster/bwForCluster Tokens&#039;&#039;&#039; are generally managed via the &#039;&#039;&#039;Index -&amp;gt; My Tokens&#039;&#039;&#039; menu entry on the registration pages for the clusters. Here you can register, activate, deactivate and delete tokens.&lt;br /&gt;
&lt;br /&gt;
To activate the second factor, &#039;&#039;&#039;please perform the following steps:&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
1. &#039;&#039;&#039;Select the registration server of the cluster&#039;&#039;&#039; for which you want to create a second factor and login to it:&amp;lt;/br&amp;gt; &amp;amp;rarr; [https://login.bwidm.de/user/twofa.xhtml Registration server for &#039;&#039;&#039;bwUniCluster 2.0&#039;&#039;&#039; and &#039;&#039;&#039;bwForCluster JUSTUS 2&#039;&#039;&#039;] (2FA tokens are valid for both clusters; KIT members can reuse their existing hardware and software tokens)&amp;lt;/br&amp;gt; &amp;amp;rarr; [https://bwservices.uni-heidelberg.de//user/twofa.xhtml Registration server for &#039;&#039;&#039;bwForCluster MLS&amp;amp;WISO&#039;&#039;&#039;]&lt;br /&gt;
[[File:BwIDM-twofa.png|center|600px|thumb|My Tokens]]&lt;br /&gt;
&lt;br /&gt;
2. &#039;&#039;&#039;Register a new &amp;quot;[[Registration/2FA#Registering_a_new_Software_Token_using_a_Mobile_APP|Smartphone Token]]&amp;quot;&#039;&#039;&#039; or if you own a [https://www.yubico.com/ Yubikey]&#039;&#039;&#039; register a new &amp;quot;[[Registration/2FA#Registering_a_new_Yubikey_OTP_Token|Yubikey Token]]&amp;quot;&#039;&#039;&#039; or &#039;&#039;&#039;&amp;quot;[[Registration/2FA#Registering_a_new_Yubikey_OATH_TOTP_Token|Yubikey OATH TOTP Token]]&amp;quot;&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
3. &#039;&#039;&#039;Register a new &amp;quot;[[Registration/2FA#Backup_TAN_List|TAN List]]&amp;quot; (backup TAN list)&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
4. Repeat step 2. for additional tokens.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Registering a new Software Token using a Mobile APP ==&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
Please disable all privacy tools, ad blockers and further add-ons when registering new tokens.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
1. Select the [[Registration/2FA#Token_Management|registration server]] of the cluster for which you want to create a second factor and login to it.&lt;br /&gt;
&lt;br /&gt;
2. Registering a new Token starts with a click &#039;&#039;&#039;NEW SMARTPHONE TOKEN&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-token.png|center|600px|thumb|Create a new Token]]&lt;br /&gt;
&lt;br /&gt;
3. A new window opens. Click &#039;&#039;&#039;Start&#039;&#039;&#039; to generate a new &#039;&#039;&#039;QR code&#039;&#039;&#039;.&lt;br /&gt;
This may take a while.&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
The QR code contains a key which has to remain secret.&lt;br /&gt;
Only use the QR code to link your software token app with bwIDM/bwServices in the next step.&lt;br /&gt;
Do not save the QR code, print it out or share it with someone else.&lt;br /&gt;
|}&lt;br /&gt;
[[File:BwIDM-qr.png|center|600px|thumb|QR Code for Mobile App]]&lt;br /&gt;
&lt;br /&gt;
4. Start the software token app on your separate device and scan the QR code.&lt;br /&gt;
The exact process is a little bit different in every app, but is usually started by pressing on a button with a plus (+) sign or an icon of a QR code.&lt;br /&gt;
&lt;br /&gt;
5. Once the QR code has been loaded into your Software Token app there should be a new entry called &#039;&#039;&#039;bwIDM&#039;&#039;&#039; (bwUniCluster and JUSTUS 2) or &#039;&#039;&#039;bwServices&#039;&#039;&#039; (MLS&amp;amp;WISO).&lt;br /&gt;
Generate an One-Time-Password by pressing on this entry or selecting the appropriate button/menu item.&lt;br /&gt;
You will receive a six-digit code.&lt;br /&gt;
Enter this code into the field labeled &amp;quot;Current code:&amp;quot; in your bwIDM browser window to prove that the connection has worked and then click &#039;&#039;&#039;CHECK&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
6. If everything worked as expected, you will be returned to the &#039;&#039;&#039;My Tokens&#039;&#039;&#039; screen and there will be a new entry for your software token.&lt;br /&gt;
[[File:BwIDM-app.png|center|400px|thumb|Success]]&lt;br /&gt;
&lt;br /&gt;
7. Repeat the process to register additional tokens.&lt;br /&gt;
Please register at least the &amp;quot;Backup TAN list&amp;quot; in addition to the hardware/software token you plan to use regularly.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Registering a new Yubikey OTP Token ==&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
Please disable all privacy tools, ad blockers and further add-ons when registering new tokens.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
[https://developers.yubico.com/OTP/OTPs_Explained.html Yubikey OTP] is even easier and you don&#039;t need a device that displays the six-digit code or extra software.&lt;br /&gt;
New Yubikeys are already configured to provide Yubikey OTP in slot 1.&lt;br /&gt;
If you need to configure your Yubikey, read this [[Registration/2FA/Yubikey|documentation]].&lt;br /&gt;
&lt;br /&gt;
1. Select the [[Registration/2FA#Token_Management|registration server]] of the cluster for which you want to create a second factor and login to it.&lt;br /&gt;
&lt;br /&gt;
2. If you want to use [https://www.yubico.com/resources/glossary/yubico-otp/ Yubico OTP], you can click &#039;&#039;&#039;NEW YUBIKEY TOKEN&#039;&#039;&#039; instead.&lt;br /&gt;
[[File:BwIDM-token.png|center|600px|thumb|Generate Yubikey OTP]]&lt;br /&gt;
&lt;br /&gt;
3. Yubikey OTP is configured to slot 1 on new Yubikeys, so you only need to click in the text box and then touch the metal part of your Yubikey.&lt;br /&gt;
Please refer to this [[Registration/2FA/Yubikey|documentation]] on how to configure your Yubikey.&lt;br /&gt;
[[File:BwIDM-yubikey.png|center|400px|thumb|Yubikey OTP]]&lt;br /&gt;
&lt;br /&gt;
4. If everything worked as expected, you will be returned to the &#039;&#039;&#039;My Tokens&#039;&#039;&#039; screen and there will be a new entry for your Yubikey.&lt;br /&gt;
[[File:BwIDM-yubikey2.png|center|400px|thumb|Success]]&lt;br /&gt;
&lt;br /&gt;
5. Repeat the process to register additional tokens.&lt;br /&gt;
Please register at least the &amp;quot;Backup TAN list&amp;quot; in addition to the hardware/software token you plan to use regularly.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Registering a new Yubikey OATH TOTP Token ==&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
Please disable all privacy tools, ad blockers and further add-ons when registering new tokens.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
[https://developers.yubico.com/OATH/ Yubikey OATH TOTP] generates the TANs on your Yubikey and therefore you can use different computers and Android phones to generate these codes.&lt;br /&gt;
Please download and install [https://developers.yubico.com/OATH/YubiKey_OATH_software.html Yubico Authenticator] for Desktop (or Android) first.&lt;br /&gt;
Insert your Yubikey in your computer.&lt;br /&gt;
&amp;quot;Yubikey OTP&amp;quot; (not &amp;quot;Yubikey OATH TOTP&amp;quot;) is even easier and you don&#039;t need a device that displays the six-digit code or extra software (go to step [[Registration/2FA#Yubikey_OTP|Yubikey OTP]]).&lt;br /&gt;
&lt;br /&gt;
1. Select the [[Registration/2FA#Token_Management|registration server]] of the cluster for which you want to create a second factor and login to it.&lt;br /&gt;
&lt;br /&gt;
2. Registering a new Token starts with a click &#039;&#039;&#039;NEW SMARTPHONE TOKEN&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-token.png|center|600px|thumb|Create a new Token]]&lt;br /&gt;
&lt;br /&gt;
3. A new window opens. Click &#039;&#039;&#039;Start&#039;&#039;&#039; to generate a new &#039;&#039;&#039;QR code&#039;&#039;&#039;.&lt;br /&gt;
This may take a while.&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
The QR code contains a key which has to remain secret.&lt;br /&gt;
Only use the QR code to link your software token app with bwIDM/bwServices in the next step.&lt;br /&gt;
Do not save the QR code, print it out or share it with someone else.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
4. Start the Yubico Authenticator on your OS, click the three vertical dots in the upper right corner and select &#039;&#039;&#039;Scan QR code&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-yubi1.png|center|600px|thumb|QR Code and Yubico Authenticator on Linux]]&lt;br /&gt;
&lt;br /&gt;
5. Yubico Authenticator automatically translates the QR code to a new entry called &#039;&#039;&#039;bwIDM&#039;&#039;&#039; or &#039;&#039;&#039;bwServices&#039;&#039;&#039; (MLS&amp;amp;WISO).&lt;br /&gt;
Click &#039;&#039;&#039;Add account&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-yubi2.png|center|600px|thumb|Create new TOTP on Yubico Authenticator]]&lt;br /&gt;
&lt;br /&gt;
6. You will receive a six-digit code.&lt;br /&gt;
Enter this code into the field labeled &amp;quot;Current code:&amp;quot; in your bwIDM browser window to prove that the connection has worked and then click &#039;&#039;&#039;CHECK&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-yubi3.png|center|600px|thumb|Verify TOTP]]&lt;br /&gt;
&lt;br /&gt;
7. If everything worked as expected, you will be returned to the &#039;&#039;&#039;My Tokens&#039;&#039;&#039; screen and there will be a new entry for your software token.&lt;br /&gt;
[[File:BwIDM-app.png|center|400px|thumb|Success]]&lt;br /&gt;
&lt;br /&gt;
8. Repeat the process to register additional tokens.&lt;br /&gt;
Please register at least the &amp;quot;Backup TAN list&amp;quot; in addition to the hardware/software token you plan to use regularly.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Backup TAN List ==&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
Passwords from the &amp;quot;Backup TAN list&amp;quot; should only be used if no other token is left.&lt;br /&gt;
Please do not use the Backup TANs for regular cluster login, because you have only a limited number of TANs.&lt;br /&gt;
Each TAN can only be used once.&lt;br /&gt;
Please disable all privacy tools, ad blockers and further add-ons when registering a new Backup TAN list.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
1. Select the [[Registration/2FA#Token_Management|registration server]] of the cluster for which you want to create a second factor and login to it.&lt;br /&gt;
&lt;br /&gt;
2. Please create at least one &amp;quot;Backup TAN list&amp;quot; by clicking &#039;&#039;&#039;CREATE NEW TAN LIST&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-token.png|center|600px|thumb|Generate Backup TAN list]]&lt;br /&gt;
&lt;br /&gt;
3. Click &#039;&#039;&#039;START&#039;&#039;&#039;. You will be redirected to the &#039;&#039;&#039;My Tokens&#039;&#039;&#039; screen and there will be a new entry for your backup TANs.&lt;br /&gt;
[[File:BwIDM-tan.png|center|400px|thumb|Success]]&lt;br /&gt;
&lt;br /&gt;
4. Click &#039;&#039;&#039;SHOW TANS&#039;&#039;&#039;, print the codes and keep then in a separate place for emergencies.&lt;br /&gt;
[[File:JUSTUS-2-2FA-backup-TAN-list.png|center|800px|thumb|Print Backup TAN List]]&lt;br /&gt;
&lt;br /&gt;
5. Repeat the process to register additional tokens.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Deactivating a Token ==&lt;br /&gt;
&lt;br /&gt;
Click &#039;&#039;&#039;Disable&#039;&#039;&#039; next to the Token entry on the &#039;&#039;&#039;My Tokens&#039;&#039;&#039; screen.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Deleting a Token ==&lt;br /&gt;
&lt;br /&gt;
After a Token has been disabled a new button labeled &#039;&#039;&#039;Delete&#039;&#039;&#039; will appear. Click on it to delete the token.&lt;br /&gt;
&lt;br /&gt;
= Returning Users =&lt;br /&gt;
&lt;br /&gt;
Returning users who have already activated one or more tokens must first verify their token before they can create new tokens or deactivate/delete old ones.&lt;br /&gt;
If you no longer have valid tokens, you will not be able to create or manage tokens. &lt;br /&gt;
In this case, read the section [[Registration/2FA#Lost_Token|Lost Token]].&lt;br /&gt;
[[File:BwIDM-totp.png|center|400px|thumb|Returning users must first verify their token.]]&lt;br /&gt;
&lt;br /&gt;
= Lost Token =&lt;br /&gt;
&lt;br /&gt;
If you have lost a token, please create a new one.&lt;br /&gt;
If you change your phone, please migrate your tokens first or register your new mobile app under &amp;quot;My Tokens&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;If you no longer have valid tokens (mobile app, hardware token, Yubikey or backup TAN), you will need to contact the [https://bw-support.scc.kit.edu/ ticket system].&#039;&#039;&#039;&lt;br /&gt;
Open a ticket, include your user name, the name of the bwHPC cluster and ask for a reset of your 2FA tokens.&lt;br /&gt;
Please note that this process may take some time and also means additional work for the operators.&lt;/div&gt;</summary>
		<author><name>C Mosch</name></author>
	</entry>
	<entry>
		<id>https://wiki.bwhpc.de/wiki/index.php?title=JUSTUS2&amp;diff=10179</id>
		<title>JUSTUS2</title>
		<link rel="alternate" type="text/html" href="https://wiki.bwhpc.de/wiki/index.php?title=JUSTUS2&amp;diff=10179"/>
		<updated>2022-03-10T17:04:26Z</updated>

		<summary type="html">&lt;p&gt;C Mosch: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[File:JUSTUS2_pre.jpg|right|frameless|thumb|alt=JUSTUS2 |upright=0.4| JUSTUS 2 ]]&lt;br /&gt;
This page is supposed to replace [[:Category:BwForCluster_JUSTUS_2]] as an overview page. Please refer back to the category for now.&lt;br /&gt;
&lt;br /&gt;
The &#039;&#039;&#039;bwForCluster JUSTUS2&#039;&#039;&#039; is a high-performance computer dedicated to  Computational Chemistry and Quantum Sciences and  located at Ulm University.&lt;br /&gt;
&amp;lt;!--{| style=&amp;quot;  background:#FEF4AB; width:100%;&amp;quot; &lt;br /&gt;
| style=&amp;quot;padding:8px; background:#FFE856; font-size:120%; font-weight:bold;  text-align:left&amp;quot; | News&lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
|}&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;  background:#eeeefe; width:100%;&amp;quot; &lt;br /&gt;
| style=&amp;quot;padding:8px; background:#dedefe; font-size:120%; font-weight:bold;  text-align:left&amp;quot; | Training &amp;amp; Support&lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
* [[JUSTUS2/Getting Started|Getting Started]]&lt;br /&gt;
* E-Learning Course [https://training.bwhpc.de/ Introduction to JUSTUS2 ] (URL will be a direct link to the course)&lt;br /&gt;
* [https://bw-support.scc.kit.edu/ Submit a Ticket] to support unit &#039;bwForCluster Justus&#039;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;  background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
| style=&amp;quot;padding:8px; background:#cef2e0; font-size:120%; font-weight:bold;  text-align:left&amp;quot; | User Documentation&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* [[JUSTUS2/Login|Login]]&lt;br /&gt;
* [[JUSTUS2/Hardware|Hardware and Architecture]]&lt;br /&gt;
* [[JUSTUS2/Filesystems|File Systems and Workspaces]] &lt;br /&gt;
&lt;br /&gt;
* [[JUSTUS2/Software|Software]]&lt;br /&gt;
* [[JUSTUS2/Slurm|Batch System]] &lt;br /&gt;
* [[JUSTUS2/Visualization|Visualisation]] &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;  background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
| style=&amp;quot;padding:8px; background:#cef2e0; font-size:120%; font-weight:bold;  text-align:left&amp;quot; | Cluster Funding&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* [[JUSTUS2/Acknowledgement|Acknowledge]] the cluster in your publications&lt;br /&gt;
|}&lt;/div&gt;</summary>
		<author><name>C Mosch</name></author>
	</entry>
	<entry>
		<id>https://wiki.bwhpc.de/wiki/index.php?title=JUSTUS2/Software&amp;diff=10178</id>
		<title>JUSTUS2/Software</title>
		<link rel="alternate" type="text/html" href="https://wiki.bwhpc.de/wiki/index.php?title=JUSTUS2/Software&amp;diff=10178"/>
		<updated>2022-03-10T17:04:16Z</updated>

		<summary type="html">&lt;p&gt;C Mosch: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Environment Modules ==&lt;br /&gt;
Most software is provided as Modules.&lt;br /&gt;
&lt;br /&gt;
Required reading to use: [[Environment Modules]]&lt;br /&gt;
&lt;br /&gt;
== Software Search ==&lt;br /&gt;
Visit [https://www.bwhpc.de/software.php https://www.bwhpc.de/software.php], select &amp;lt;code&amp;gt;Cluster → bwForCluster JUSTUS2&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Documentation ==&lt;br /&gt;
Documentation by the cluster operators: &lt;br /&gt;
{| style=&amp;quot;width:100%;&amp;quot;&lt;br /&gt;
|- style=&amp;quot;background:#eeeeee;&amp;quot; |&lt;br /&gt;
|  &amp;lt;code&amp;gt;module help&amp;lt;/code&amp;gt; ||  See section: [[Environment_Modules#module_help]]&lt;br /&gt;
|-  style=&amp;quot;background:#dddddd; &amp;quot; | &lt;br /&gt;
| examples in &amp;lt;code&amp;gt;$SOFTNAME_EXA_DIR&amp;lt;/code&amp;gt; || See section: [[Environment_Modules#Software_job_examples]]&lt;br /&gt;
|- style=&amp;quot;background:#eeeeee; &amp;quot; | &lt;br /&gt;
| this wiki || See below&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Documentation in the Wiki ==&lt;br /&gt;
Modules with additional documentation here in the wiki:&lt;br /&gt;
&lt;br /&gt;
* [[JUSTUS2/Software/ADF|ADF]]&lt;br /&gt;
&lt;br /&gt;
* [[JUSTUS2/Software/Dalton|Dalton]]&lt;br /&gt;
&lt;br /&gt;
* [[JUSTUS2/Software/Gaussian|Gaussian]]&lt;br /&gt;
&lt;br /&gt;
* [[JUSTUS2/Software/Gaussview|Gaussview]]&lt;br /&gt;
&lt;br /&gt;
* [[JUSTUS2/Software/Molden|Molden]]&lt;br /&gt;
&lt;br /&gt;
* [[JUSTUS2/Software/Schrodinger|Schrodinger]]&lt;br /&gt;
&lt;br /&gt;
* [[JUSTUS2/Software/VASP|VASP]]&lt;/div&gt;</summary>
		<author><name>C Mosch</name></author>
	</entry>
	<entry>
		<id>https://wiki.bwhpc.de/wiki/index.php?title=JUSTUS2&amp;diff=10177</id>
		<title>JUSTUS2</title>
		<link rel="alternate" type="text/html" href="https://wiki.bwhpc.de/wiki/index.php?title=JUSTUS2&amp;diff=10177"/>
		<updated>2022-03-10T16:58:08Z</updated>

		<summary type="html">&lt;p&gt;C Mosch: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;[[File:JUSTUS2_pre.jpg|right|frameless|thumb|alt=JUSTUS2 |upright=0.4| JUSTUS 2 ]]&lt;br /&gt;
This page is supposed to replace [[:Category:BwForCluster_JUSTUS_2]] as an overview page. Please refer back to the category for now.&lt;br /&gt;
&lt;br /&gt;
The &#039;&#039;&#039;bwForCluster JUSTUS2&#039;&#039;&#039; is a high-performance computer dedicated to  Computational Chemistry and Quantum Sciences and  located at Ulm University.&lt;br /&gt;
&amp;lt;!--{| style=&amp;quot;  background:#FEF4AB; width:100%;&amp;quot; &lt;br /&gt;
| style=&amp;quot;padding:8px; background:#FFE856; font-size:120%; font-weight:bold;  text-align:left&amp;quot; | News&lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
|}&lt;br /&gt;
--&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;  background:#eeeefe; width:100%;&amp;quot; &lt;br /&gt;
| style=&amp;quot;padding:8px; background:#dedefe; font-size:120%; font-weight:bold;  text-align:left&amp;quot; | Training &amp;amp; Support&lt;br /&gt;
|-&lt;br /&gt;
| &lt;br /&gt;
* [[JUSTUS2/Getting Started|Getting Started]]&lt;br /&gt;
* E-Learning Course [https://training.bwhpc.de/ Introduction to JUSTUS2 ] (URL will be a direct link to the course)&lt;br /&gt;
* [https://bw-support.scc.kit.edu/ Submit a Ticket] to support unit &#039;bwForCluster Justus&#039;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;  background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
| style=&amp;quot;padding:8px; background:#cef2e0; font-size:120%; font-weight:bold;  text-align:left&amp;quot; | User Documentation&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* [[JUSTUS2/Login|Login]]&lt;br /&gt;
* [[JUSTUS2/Hardware|Hardware and Architecture]]&lt;br /&gt;
* [[JUSTUS2/Filesystems|File Systems and Workspaces]] &lt;br /&gt;
&lt;br /&gt;
* [[JUSTUS2/Software|Software]]&lt;br /&gt;
* [[JUSTUS2/Slurm|Batch System]] &lt;br /&gt;
* [[JUSTUS2/Visualization|Visualisation]] &lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;  background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
| style=&amp;quot;padding:8px; background:#cef2e0; font-size:120%; font-weight:bold;  text-align:left&amp;quot; | Cluster Funding&lt;br /&gt;
|-&lt;br /&gt;
|&lt;br /&gt;
* [[JUSTUS2/Acknowledgement|Acknowledge]] the cluster in your publications&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
[[Category:JUSTUS2/Software]]&lt;/div&gt;</summary>
		<author><name>C Mosch</name></author>
	</entry>
	<entry>
		<id>https://wiki.bwhpc.de/wiki/index.php?title=JUSTUS2/Software&amp;diff=10176</id>
		<title>JUSTUS2/Software</title>
		<link rel="alternate" type="text/html" href="https://wiki.bwhpc.de/wiki/index.php?title=JUSTUS2/Software&amp;diff=10176"/>
		<updated>2022-03-10T16:57:35Z</updated>

		<summary type="html">&lt;p&gt;C Mosch: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Environment Modules ==&lt;br /&gt;
Most software is provided as Modules.&lt;br /&gt;
&lt;br /&gt;
Required reading to use: [[Environment Modules]]&lt;br /&gt;
&lt;br /&gt;
== Software Search ==&lt;br /&gt;
Visit [https://www.bwhpc.de/software.php https://www.bwhpc.de/software.php], select &amp;lt;code&amp;gt;Cluster → bwForCluster JUSTUS2&amp;lt;/code&amp;gt;&lt;br /&gt;
&lt;br /&gt;
== Documentation ==&lt;br /&gt;
Documentation by the cluster operators: &lt;br /&gt;
{| style=&amp;quot;width:100%;&amp;quot;&lt;br /&gt;
|- style=&amp;quot;background:#eeeeee;&amp;quot; |&lt;br /&gt;
|  &amp;lt;code&amp;gt;module help&amp;lt;/code&amp;gt; ||  See section: [[Environment_Modules#module_help]]&lt;br /&gt;
|-  style=&amp;quot;background:#dddddd; &amp;quot; | &lt;br /&gt;
| examples in &amp;lt;code&amp;gt;$SOFTNAME_EXA_DIR&amp;lt;/code&amp;gt; || See section: [[Environment_Modules#Software_job_examples]]&lt;br /&gt;
|- style=&amp;quot;background:#eeeeee; &amp;quot; | &lt;br /&gt;
| this wiki || See below&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Documentation in the Wiki ==&lt;br /&gt;
Modules with additional documentation here in the wiki:&lt;br /&gt;
&lt;br /&gt;
* [[JUSTUS2/Software/ADF|ADF]]&lt;br /&gt;
&lt;br /&gt;
* [[JUSTUS2/Software/Dalton|Dalton]]&lt;br /&gt;
&lt;br /&gt;
* [[JUSTUS2/Software/Gaussian|Gaussian]]&lt;br /&gt;
&lt;br /&gt;
* [[JUSTUS2/Software/Gaussview|Gaussview]]&lt;br /&gt;
&lt;br /&gt;
* [[JUSTUS2/Software/Molden|Molden]]&lt;br /&gt;
&lt;br /&gt;
* [[JUSTUS2/Software/Schrodinger|Schrodinger]]&lt;br /&gt;
&lt;br /&gt;
* [[JUSTUS2/Software/VASP|VASP]]&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
[[Category:JUSTUS2/Software]]&lt;/div&gt;</summary>
		<author><name>C Mosch</name></author>
	</entry>
	<entry>
		<id>https://wiki.bwhpc.de/wiki/index.php?title=JUSTUS2/Software&amp;diff=10162</id>
		<title>JUSTUS2/Software</title>
		<link rel="alternate" type="text/html" href="https://wiki.bwhpc.de/wiki/index.php?title=JUSTUS2/Software&amp;diff=10162"/>
		<updated>2022-03-10T15:14:41Z</updated>

		<summary type="html">&lt;p&gt;C Mosch: /* Documentation in the Wiki */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;== Documentation ==&lt;br /&gt;
Documentation by the cluster operators is mainly provided in three forms:&lt;br /&gt;
* the &amp;lt;code&amp;gt;module help&amp;lt;/code&amp;gt; of software modules&lt;br /&gt;
* examples in $SOFTNAME_EXA_DIR (replace SOFTNAME with name of the software)&lt;br /&gt;
* this wiki&lt;br /&gt;
&lt;br /&gt;
Required reading for the first two forms of documentation:&lt;br /&gt;
* [[Environment Modules]]&lt;br /&gt;
&lt;br /&gt;
=== Documentation in the Wiki ===&lt;br /&gt;
Modules with additional documentation here in the wiki:&lt;br /&gt;
&lt;br /&gt;
* [[JUSTUS2/Software/ADF|ADF]]&lt;br /&gt;
&lt;br /&gt;
* [[JUSTUS2/Software/Dalton|Dalton]]&lt;br /&gt;
&lt;br /&gt;
* [[JUSTUS2/Software/Gaussian|Gaussian]]&lt;br /&gt;
&lt;br /&gt;
* [[JUSTUS2/Software/Gaussview|Gaussview]]&lt;br /&gt;
&lt;br /&gt;
* [[JUSTUS2/Software/Molden|Molden]]&lt;br /&gt;
&lt;br /&gt;
* [[JUSTUS2/Software/Schrodinger|Schrodinger]]&lt;br /&gt;
&lt;br /&gt;
* [[JUSTUS2/Software/VASP|VASP]]&lt;/div&gt;</summary>
		<author><name>C Mosch</name></author>
	</entry>
	<entry>
		<id>https://wiki.bwhpc.de/wiki/index.php?title=VASP&amp;diff=10161</id>
		<title>VASP</title>
		<link rel="alternate" type="text/html" href="https://wiki.bwhpc.de/wiki/index.php?title=VASP&amp;diff=10161"/>
		<updated>2022-03-10T14:56:59Z</updated>

		<summary type="html">&lt;p&gt;C Mosch: C Mosch moved page VASP to JUSTUS2/Software/VASP&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;#REDIRECT [[JUSTUS2/Software/VASP]]&lt;/div&gt;</summary>
		<author><name>C Mosch</name></author>
	</entry>
	<entry>
		<id>https://wiki.bwhpc.de/wiki/index.php?title=JUSTUS2/Software/VASP&amp;diff=10160</id>
		<title>JUSTUS2/Software/VASP</title>
		<link rel="alternate" type="text/html" href="https://wiki.bwhpc.de/wiki/index.php?title=JUSTUS2/Software/VASP&amp;diff=10160"/>
		<updated>2022-03-10T14:56:59Z</updated>

		<summary type="html">&lt;p&gt;C Mosch: C Mosch moved page VASP to JUSTUS2/Software/VASP&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;{{Softwarepage|chem/vasp}}&lt;br /&gt;
&lt;br /&gt;
{| width=600px class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Description !! Content&lt;br /&gt;
|-&lt;br /&gt;
| module load&lt;br /&gt;
| chem/vasp&lt;br /&gt;
|-&lt;br /&gt;
| License&lt;br /&gt;
| Commercial VASP license. [[#License and Citing|See text]].&lt;br /&gt;
|-&lt;br /&gt;
| Citing&lt;br /&gt;
| [[#License and Citing|See VASP license and documentation]]&lt;br /&gt;
|-&lt;br /&gt;
| Links&lt;br /&gt;
| [https://www.vasp.at/ Homepage] &amp;amp;#124; [https://www.vasp.at/index.php/documentation Documentation]&lt;br /&gt;
|-&lt;br /&gt;
| Graphical Interface&lt;br /&gt;
| No (only via 3rd party tools like VMD)&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
= Description = &lt;br /&gt;
The Vienna Ab initio Simulation Package (&#039;&#039;&#039;VASP&#039;&#039;&#039;) is an atomic scale materials modelling&lt;br /&gt;
program for e.g. electronic structure calculations and quantum-mechanical molecular dynamics.&lt;br /&gt;
Although the focus is on simulation of periodic structures like solids and surfaces, molecular&lt;br /&gt;
structures can be simulated as well by the so-called &#039;&#039;supercell approach&#039;&#039;. VASP is a plane&lt;br /&gt;
wave code using PAW (projector augmented wave) pseudopotentials. Exchange and correlation&lt;br /&gt;
effects are described based on DFT (density functional theory) as well as Hartree-Fock&lt;br /&gt;
and post Hartree-Fock methods. &lt;br /&gt;
&lt;br /&gt;
Some features of VASP:&lt;br /&gt;
* Functionals: LDA, GGAs, metaGGAs, Hartree-Fock, Hartree-Fock/DFT hybrids&lt;br /&gt;
* Dynamics: Born-Oppenheimer molecular dynamics&lt;br /&gt;
* Relaxation: Conjugate gradient, quasi-Newton or damped molecular dynamics&lt;br /&gt;
* Transition state search: Nudged elastic band methods, climbing dimer method&lt;br /&gt;
* Linear response to electric fields: Static dielectric properties, Born effective charge tensors, piezoelectric tensors&lt;br /&gt;
* Green&#039;s function methods: GW quasiparticles&lt;br /&gt;
* Magnetism: Collinear and non-collinear, spin-orbit coupling&lt;br /&gt;
* Linear response to ionic displacements: Phonons, elastic constants, internal strain tensors&lt;br /&gt;
&lt;br /&gt;
For more information on VASP please&lt;br /&gt;
visit [https://www.vasp.at/index.php/about-vasp/59-about-vasp What is VASP?].&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
= License and Citing =&lt;br /&gt;
VASP is available only for groups with a valid group license. Furthermore every&lt;br /&gt;
scientist has to be registered with his group VASP license&lt;br /&gt;
at [http://vasp.at the VASP group in Vienna] before we can grant access to the&lt;br /&gt;
VASP binaries or pseudopotentials.&lt;br /&gt;
&lt;br /&gt;
In future publications of work performed using VASP, the&lt;br /&gt;
use of the software shall be properly acknowledged, e.g. in the form:&lt;br /&gt;
&lt;br /&gt;
The calculations have been performed using the ab-initio total-energy and&lt;br /&gt;
molecular-dynamics program VASP (Vienna ab-initio simulation program)&lt;br /&gt;
developed at the Institut für Materialphysik of the Universität Wien [1,2].&amp;lt;br&amp;gt;&lt;br /&gt;
[1] G. Kresse and J. Furthmüller, Phys. Rev. B &#039;&#039;&#039;54&#039;&#039;&#039;, 11169 (1996).&amp;lt;br&amp;gt;&lt;br /&gt;
If the PAW-version is used, an additional reference shell be made to:&amp;lt;br&amp;gt;&lt;br /&gt;
[2] G. Kresse and D. Joubert, Phys. Rev. &#039;&#039;&#039;59&#039;&#039;&#039;, 1758 (1999).&lt;br /&gt;
&lt;br /&gt;
If special features or method implemented in VASP are used,&lt;br /&gt;
reference should be made to the relevant publications&lt;br /&gt;
as listed on the [http://vasp.at VASP home-page] (see also&lt;br /&gt;
the [http://cms.mpi.univie.ac.at/vasp/vasp/Bibliography.html Bibliography]&lt;br /&gt;
of the [http://cms.mpi.univie.ac.at/vasp/vasp/vasp.html VASP manual]).&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Usage =&lt;br /&gt;
&lt;br /&gt;
== Parallel computing and disk usage ==&lt;br /&gt;
Depending on the resources requested from the queueing system,&lt;br /&gt;
the &#039;&#039;vasp&#039;&#039; script automatically detects whether to run the&lt;br /&gt;
serial or the MPI-parallel version.&lt;br /&gt;
&lt;br /&gt;
If running on multiple nodes, the job must run within&lt;br /&gt;
a common job directory visible on all nodes. So in case of&lt;br /&gt;
multi-node jobs, using &#039;&#039;/tmp/$USER&#039;&#039; is no option.&lt;br /&gt;
&lt;br /&gt;
To lower the disk I/O demands of the VASP jobs one should&lt;br /&gt;
add the options&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
  LWAVE  = .FALSE.; LCHARG = .FALSE.; LVTOT  = .FALSE.&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
to the &#039;&#039;INCAR&#039;&#039; file. For further hints on how to optimize&lt;br /&gt;
your VASP see the [http://cms.mpi.univie.ac.at/vasp/vasp/vasp.html VASP online manual]&lt;br /&gt;
and [http://cms.mpi.univie.ac.at/wiki/index.php/The_VASP_Manual VASP wiki] as well&lt;br /&gt;
as the module help of VASP:&lt;br /&gt;
&amp;lt;pre&amp;gt;&lt;br /&gt;
$ module help chem/vasp&lt;br /&gt;
&amp;lt;/pre&amp;gt;&lt;br /&gt;
&amp;lt;br&amp;gt;&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
[[Category:Chemistry software]][[Category:bwUniCluster]]&lt;/div&gt;</summary>
		<author><name>C Mosch</name></author>
	</entry>
	<entry>
		<id>https://wiki.bwhpc.de/wiki/index.php?title=Registration/bwUniCluster&amp;diff=10092</id>
		<title>Registration/bwUniCluster</title>
		<link rel="alternate" type="text/html" href="https://wiki.bwhpc.de/wiki/index.php?title=Registration/bwUniCluster&amp;diff=10092"/>
		<updated>2022-02-24T14:41:20Z</updated>

		<summary type="html">&lt;p&gt;C Mosch: /* Three Steps for Registration */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Registration bwUniCluster =&lt;br /&gt;
&lt;br /&gt;
The [[bwUniCluster 2.0]] is the universal cluster for tier 3 high performance computing (HPC) in Baden-Württemberg.&lt;br /&gt;
It is co-financed by the Ministry of Science, Research and the Arts Baden-Württemberg and the shareholders:&lt;br /&gt;
* Universität Freiburg&lt;br /&gt;
* Universität Heidelberg&lt;br /&gt;
* Universität Hohenheim&lt;br /&gt;
* Karlsruhe Institute of Technology (KIT)&lt;br /&gt;
* Universität Konstanz&lt;br /&gt;
* Universität Mannheim&lt;br /&gt;
* Universität Stuttgart&lt;br /&gt;
* Universität Tübingen&lt;br /&gt;
* Universität Ulm&lt;br /&gt;
* [[Registration/HAW|HAW BW e.V.]] (an association of several universities of applied sciences in Baden-Württemberg)&lt;br /&gt;
&lt;br /&gt;
All members of the shareholder universities can apply for an account.&lt;br /&gt;
&lt;br /&gt;
The use of the bwUniCluster is free of charge.&lt;br /&gt;
&lt;br /&gt;
== Three Steps for Registration ==&lt;br /&gt;
&lt;br /&gt;
The registration process for the bwUniCluster is divided into three steps:&lt;br /&gt;
&lt;br /&gt;
* Step A: You need to get the &#039;&#039;&#039;bwUniCluster Entitlement&#039;&#039;&#039; from your university/college.&amp;lt;br /&amp;gt;&amp;amp;rarr; &#039;&#039;&#039;[[Registration/bwUniCluster/Entitlement|Step A: bwUniCluster Entitlement]]&lt;br /&gt;
* Step B: You need to &#039;&#039;&#039;register for the service bwUniCluster&#039;&#039;&#039;.&amp;lt;br /&amp;gt;&amp;amp;rarr; &#039;&#039;&#039;[[Registration/bwUniCluster/Service|Step B: bwUniCluster Registration]]&lt;br /&gt;
* Step C: You need to fill out the &#039;&#039;&#039;bwUniCluster questionnaire within 14 days&#039;&#039;&#039;.&amp;lt;br /&amp;gt;&amp;amp;rarr; &#039;&#039;&#039;[[Registration/bwUniCluster/Questionnaire|Step C: bwUniCluster Questionnaire]]&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
Please fill out the bwUniCluster questionnaire within 14 days after registration. Otherwise your login to the cluster will be deactivated.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
After registering, please refer further to &#039;&#039;&#039;[[Registration/bwForCluster#Information_for_already_registered_users|Information for already registered users]]&#039;&#039;&#039; at the bottom of the page and to the cluster-specific pages below &#039;&#039;&#039;bwHPC Systems&#039;&#039;&#039; in the menu on the left.&lt;br /&gt;
&lt;br /&gt;
[[File:bwUniCluster-Registration.png|center|bwUniCluster Registration Process]]&lt;br /&gt;
&lt;br /&gt;
== Information for already registered users ==&lt;br /&gt;
&lt;br /&gt;
* If you want to &#039;&#039;&#039;login&#039;&#039;&#039; to the bwUniCluster, please refer to the general &amp;lt;br /&amp;gt; &amp;amp;rarr; &#039;&#039;&#039;[[Registration/Login|Login Guide]]&#039;&#039;&#039;&lt;br /&gt;
* If you want to &#039;&#039;&#039;create a second factor&#039;&#039;&#039;, please refer to &amp;lt;br /&amp;gt; &amp;amp;rarr; &#039;&#039;&#039;[[Registration/2FA|Generate a Second Factor (2FA)]]&#039;&#039;&#039;&lt;br /&gt;
* If you need to &#039;&#039;&#039;change or forgot your password&#039;&#039;&#039; for the bwUniCluster, please refer to the general &amp;lt;br /&amp;gt; &amp;amp;rarr; &#039;&#039;&#039;[[Registration/Password|Password Guide]]&#039;&#039;&#039;&lt;br /&gt;
* If you want to &#039;&#039;&#039;use SSH keys&#039;&#039;&#039; on the bwUniCluster, please refer to &amp;lt;br /&amp;gt; &amp;amp;rarr; &#039;&#039;&#039;[[Registration/SSH|Registering SSH Keys with your Cluster]]&#039;&#039;&#039;&lt;br /&gt;
* If you want do &#039;&#039;&#039;de-register your user account&#039;&#039;&#039; from the bwUniCluster, please refer to the general &amp;lt;br /&amp;gt;&amp;amp;rarr; &#039;&#039;&#039;[[Registration/Deregistration|De-registration Guide]]&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Contact / Support ==&lt;br /&gt;
&lt;br /&gt;
If you have questions or problems concerning the bwUniCluster registration, please [[bwUniCluster 2.0 Support|contact your local hotline]].&lt;/div&gt;</summary>
		<author><name>C Mosch</name></author>
	</entry>
	<entry>
		<id>https://wiki.bwhpc.de/wiki/index.php?title=Registration/bwUniCluster&amp;diff=10091</id>
		<title>Registration/bwUniCluster</title>
		<link rel="alternate" type="text/html" href="https://wiki.bwhpc.de/wiki/index.php?title=Registration/bwUniCluster&amp;diff=10091"/>
		<updated>2022-02-24T14:40:51Z</updated>

		<summary type="html">&lt;p&gt;C Mosch: /* Three Steps for Registration */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Registration bwUniCluster =&lt;br /&gt;
&lt;br /&gt;
The [[bwUniCluster 2.0]] is the universal cluster for tier 3 high performance computing (HPC) in Baden-Württemberg.&lt;br /&gt;
It is co-financed by the Ministry of Science, Research and the Arts Baden-Württemberg and the shareholders:&lt;br /&gt;
* Universität Freiburg&lt;br /&gt;
* Universität Heidelberg&lt;br /&gt;
* Universität Hohenheim&lt;br /&gt;
* Karlsruhe Institute of Technology (KIT)&lt;br /&gt;
* Universität Konstanz&lt;br /&gt;
* Universität Mannheim&lt;br /&gt;
* Universität Stuttgart&lt;br /&gt;
* Universität Tübingen&lt;br /&gt;
* Universität Ulm&lt;br /&gt;
* [[Registration/HAW|HAW BW e.V.]] (an association of several universities of applied sciences in Baden-Württemberg)&lt;br /&gt;
&lt;br /&gt;
All members of the shareholder universities can apply for an account.&lt;br /&gt;
&lt;br /&gt;
The use of the bwUniCluster is free of charge.&lt;br /&gt;
&lt;br /&gt;
== Three Steps for Registration ==&lt;br /&gt;
&lt;br /&gt;
The registration process for the bwUniCluster is divided into three steps:&lt;br /&gt;
&lt;br /&gt;
* Step A: You need to get the &#039;&#039;&#039;bwUniCluster Entitlement&#039;&#039;&#039; from your university/college.&amp;lt;br /&amp;gt;&amp;amp;rarr; &#039;&#039;&#039;[[Registration/bwUniCluster/Entitlement|Step A: bwUniCluster Entitlement]]&lt;br /&gt;
* Step B: You need to &#039;&#039;&#039;register for the service bwUniCluster&#039;&#039;&#039;.&amp;lt;br /&amp;gt;&amp;amp;rarr; &#039;&#039;&#039;[[Registration/bwUniCluster/Service|Step B: bwUniCluster Registration]]&lt;br /&gt;
* Step C: You need to fill out the &#039;&#039;&#039;bwUniCluster questionnaire within 14 days&#039;&#039;&#039;.&amp;lt;br /&amp;gt;&amp;amp;rarr; &#039;&#039;&#039;[[Registration/bwUniCluster/Questionnaire|Step C: bwUniCluster Questionnaire]]&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
Please fill out the bwUniCluster questionnaire within 14 days after registration. Otherwise your login to the cluster will be deactivated.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
After registering, please refer further to &#039;&#039;&#039;[[Registration/bwForCluster#Information_for_already_registered_users|Information for already registered users]]&#039;&#039;&#039; at the bottom and the page or to the cluster-specific pages below &#039;&#039;&#039;bwHPC Systems&#039;&#039;&#039; in the menu on the left.&lt;br /&gt;
&lt;br /&gt;
[[File:bwUniCluster-Registration.png|center|bwUniCluster Registration Process]]&lt;br /&gt;
&lt;br /&gt;
== Information for already registered users ==&lt;br /&gt;
&lt;br /&gt;
* If you want to &#039;&#039;&#039;login&#039;&#039;&#039; to the bwUniCluster, please refer to the general &amp;lt;br /&amp;gt; &amp;amp;rarr; &#039;&#039;&#039;[[Registration/Login|Login Guide]]&#039;&#039;&#039;&lt;br /&gt;
* If you want to &#039;&#039;&#039;create a second factor&#039;&#039;&#039;, please refer to &amp;lt;br /&amp;gt; &amp;amp;rarr; &#039;&#039;&#039;[[Registration/2FA|Generate a Second Factor (2FA)]]&#039;&#039;&#039;&lt;br /&gt;
* If you need to &#039;&#039;&#039;change or forgot your password&#039;&#039;&#039; for the bwUniCluster, please refer to the general &amp;lt;br /&amp;gt; &amp;amp;rarr; &#039;&#039;&#039;[[Registration/Password|Password Guide]]&#039;&#039;&#039;&lt;br /&gt;
* If you want to &#039;&#039;&#039;use SSH keys&#039;&#039;&#039; on the bwUniCluster, please refer to &amp;lt;br /&amp;gt; &amp;amp;rarr; &#039;&#039;&#039;[[Registration/SSH|Registering SSH Keys with your Cluster]]&#039;&#039;&#039;&lt;br /&gt;
* If you want do &#039;&#039;&#039;de-register your user account&#039;&#039;&#039; from the bwUniCluster, please refer to the general &amp;lt;br /&amp;gt;&amp;amp;rarr; &#039;&#039;&#039;[[Registration/Deregistration|De-registration Guide]]&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
== Contact / Support ==&lt;br /&gt;
&lt;br /&gt;
If you have questions or problems concerning the bwUniCluster registration, please [[bwUniCluster 2.0 Support|contact your local hotline]].&lt;/div&gt;</summary>
		<author><name>C Mosch</name></author>
	</entry>
	<entry>
		<id>https://wiki.bwhpc.de/wiki/index.php?title=Registration/bwForCluster&amp;diff=10090</id>
		<title>Registration/bwForCluster</title>
		<link rel="alternate" type="text/html" href="https://wiki.bwhpc.de/wiki/index.php?title=Registration/bwForCluster&amp;diff=10090"/>
		<updated>2022-02-24T14:40:09Z</updated>

		<summary type="html">&lt;p&gt;C Mosch: /* Three Steps for Registration */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Registration bwForCluster =&lt;br /&gt;
&lt;br /&gt;
A bwForCluster is a cluster for a specific [https://www.bwhpc.de/cluster.php research area].&lt;br /&gt;
You can apply for a bwForCluster and the &amp;quot;cluster assignment team&amp;quot; will assign you to the appropriate cluster for your research area, taking into account your specific hardware/software needs.&lt;br /&gt;
bwForClusters are funded by the German Research Foundation (DFG) and the Ministry of Science, Research and the Arts of Baden-Württemberg on the basis of grant applications (cf. proposals application guidelines according to Art. 91b GG).&lt;br /&gt;
&lt;br /&gt;
All members of the universities in Baden-Württemberg can apply for an account.&lt;br /&gt;
&lt;br /&gt;
The use of the bwForClusters is free of charge.&lt;br /&gt;
&lt;br /&gt;
== Three Steps for Registration ==&lt;br /&gt;
&lt;br /&gt;
The registration process for a bwForCluster is divided into three steps, whereby step A+B can be performed in parallel.&lt;br /&gt;
When both are completed, you can perform step C.&lt;br /&gt;
To which cluster you get access depends on your research area and will be decided in step B.&lt;br /&gt;
&lt;br /&gt;
* Step A: You need to get the &#039;&#039;&#039;bwForCluster Entitlement&#039;&#039;&#039; from your university/college.&amp;lt;br /&amp;gt;&amp;amp;rarr; &#039;&#039;&#039;[[Registration/bwForCluster/Entitlement|bwForCluster User Access Step A]]&#039;&#039;&#039;&lt;br /&gt;
* Step B: You need to &#039;&#039;&#039;apply for a Rechenvorhaben/project&#039;&#039;&#039; on the &amp;quot;central application site&amp;quot; (ZAS).&amp;lt;br /&amp;gt;&amp;amp;rarr; &#039;&#039;&#039;[[Registration/bwForCluster/RV|bwForCluster User Access Step B]]&#039;&#039;&#039;&lt;br /&gt;
* Step C: You need to &#039;&#039;&#039;register for a bwForCluster&#039;&#039;&#039;.&amp;lt;br /&amp;gt;&amp;amp;rarr; &#039;&#039;&#039;[[Registration/bwForCluster/Service|bwForCluster User Access Step C]]&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
After registering, please refer further to &#039;&#039;&#039;[[Registration/bwForCluster#Information_for_already_registered_users|Information for already registered users]]&#039;&#039;&#039; at the bottom of the page and to the cluster-specific pages below &#039;&#039;&#039;bwHPC Systems&#039;&#039;&#039; in the menu on the left.&lt;br /&gt;
&lt;br /&gt;
[[File:bwForCluster-Registration.png|center|bwForCluster Registration Process]]&lt;br /&gt;
&lt;br /&gt;
== Information for already registered users ==&lt;br /&gt;
&lt;br /&gt;
* If you want to &#039;&#039;&#039;login&#039;&#039;&#039; to one of the bwForClusters, please refer to the general &amp;lt;br /&amp;gt; &amp;amp;rarr; &#039;&#039;&#039;[[Registration/Login|Login Guide]]&#039;&#039;&#039;&lt;br /&gt;
* If you want to &#039;&#039;&#039;create a second factor&#039;&#039;&#039;, please refer to &amp;lt;br /&amp;gt; &amp;amp;rarr; &#039;&#039;&#039;[[Registration/2FA|Generate a Second Factor (2FA)]]&#039;&#039;&#039; (only Justus 2 and MLS&amp;amp;WISO)&lt;br /&gt;
* If you need to &#039;&#039;&#039;change or forgot your password&#039;&#039;&#039; for a bwForCluster, please refer to the general &amp;lt;br /&amp;gt; &amp;amp;rarr; &#039;&#039;&#039;[[Registration/Password|Password Guide]]&#039;&#039;&#039;&lt;br /&gt;
* If you want to &#039;&#039;&#039;use SSH keys&#039;&#039;&#039; on a bwForCluster, please refer to &amp;lt;br /&amp;gt; &amp;amp;rarr; &#039;&#039;&#039;[[Registration/SSH|Registering SSH Keys with your Cluster]]&#039;&#039;&#039; (only MLS&amp;amp;WISO)&lt;br /&gt;
* If you want do &#039;&#039;&#039;de-register your user account&#039;&#039;&#039; from a bwForCluster, please refer to the general &amp;lt;br /&amp;gt;&amp;amp;rarr; &#039;&#039;&#039;[[Registration/Deregistration|De-registration Guide]]&#039;&#039;&#039;&lt;/div&gt;</summary>
		<author><name>C Mosch</name></author>
	</entry>
	<entry>
		<id>https://wiki.bwhpc.de/wiki/index.php?title=Registration/bwForCluster&amp;diff=10047</id>
		<title>Registration/bwForCluster</title>
		<link rel="alternate" type="text/html" href="https://wiki.bwhpc.de/wiki/index.php?title=Registration/bwForCluster&amp;diff=10047"/>
		<updated>2022-02-17T15:56:14Z</updated>

		<summary type="html">&lt;p&gt;C Mosch: /* Three Steps for Registration */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Registration bwForCluster =&lt;br /&gt;
&lt;br /&gt;
A bwForCluster is a cluster for a specific [https://www.bwhpc.de/cluster.php research area].&lt;br /&gt;
You can apply for a bwForCluster and the &amp;quot;cluster assignment team&amp;quot; will assign you to the appropriate cluster for your research area, taking into account your specific hardware/software needs.&lt;br /&gt;
bwForClusters are funded by the German Research Foundation (DFG) and the Ministry of Science, Research and the Arts of Baden-Württemberg on the basis of grant applications (cf. proposals application guidelines according to Art. 91b GG).&lt;br /&gt;
&lt;br /&gt;
All members of the universities in Baden-Württemberg can apply for an account.&lt;br /&gt;
&lt;br /&gt;
The use of the bwForClusters is free of charge.&lt;br /&gt;
&lt;br /&gt;
== Three Steps for Registration ==&lt;br /&gt;
&lt;br /&gt;
The registration process for a bwForCluster is divided into three steps, whereby step A+B can be performed in parallel.&lt;br /&gt;
When both are completed, you can perform step C.&lt;br /&gt;
To which cluster you get access depends on your research area and will be decided in step B.&lt;br /&gt;
&lt;br /&gt;
* Step A: You need to get the &#039;&#039;&#039;bwForCluster Entitlement&#039;&#039;&#039; from your university/college.&amp;lt;br /&amp;gt;&amp;amp;rarr; &#039;&#039;&#039;[[Registration/bwForCluster/Entitlement|bwForCluster User Access Step A]]&#039;&#039;&#039;&lt;br /&gt;
* Step B: You need to &#039;&#039;&#039;apply for a Rechenvorhaben/project&#039;&#039;&#039; on the &amp;quot;central application site&amp;quot; (ZAS).&amp;lt;br /&amp;gt;&amp;amp;rarr; &#039;&#039;&#039;[[Registration/bwForCluster/RV|bwForCluster User Access Step B]]&#039;&#039;&#039;&lt;br /&gt;
* Step C: You need to &#039;&#039;&#039;register for a bwForCluster&#039;&#039;&#039;.&amp;lt;br /&amp;gt;&amp;amp;rarr; &#039;&#039;&#039;[[Registration/bwForCluster/Service|bwForCluster User Access Step C]]&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
After registering, please refer further to &#039;&#039;&#039;[[Registration/bwForCluster#Information_for_already_registered_users|Information for already registered users]]&#039;&#039;&#039; at the bottom of the page or to the cluster-specific pages below &#039;&#039;&#039;bwHPC Systems&#039;&#039;&#039; in the menu on the left.&lt;br /&gt;
&lt;br /&gt;
[[File:bwForCluster-Registration.png|center|bwForCluster Registration Process]]&lt;br /&gt;
&lt;br /&gt;
== Information for already registered users ==&lt;br /&gt;
&lt;br /&gt;
* If you want to &#039;&#039;&#039;login&#039;&#039;&#039; to one of the bwForClusters, please refer to the general &amp;lt;br /&amp;gt; &amp;amp;rarr; &#039;&#039;&#039;[[Registration/Login|Login Guide]]&#039;&#039;&#039;&lt;br /&gt;
* If you want to &#039;&#039;&#039;create a second factor&#039;&#039;&#039;, please refer to &amp;lt;br /&amp;gt; &amp;amp;rarr; &#039;&#039;&#039;[[Registration/2FA|Generate a Second Factor (2FA)]]&#039;&#039;&#039; (only Justus 2 and MLS&amp;amp;WISO)&lt;br /&gt;
* If you need to &#039;&#039;&#039;change or forgot your password&#039;&#039;&#039; for a bwForCluster, please refer to the general &amp;lt;br /&amp;gt; &amp;amp;rarr; &#039;&#039;&#039;[[Registration/Password|Password Guide]]&#039;&#039;&#039;&lt;br /&gt;
* If you want to &#039;&#039;&#039;use SSH keys&#039;&#039;&#039; on a bwForCluster, please refer to &amp;lt;br /&amp;gt; &amp;amp;rarr; &#039;&#039;&#039;[[Registration/SSH|Registering SSH Keys with your Cluster]]&#039;&#039;&#039; (only MLS&amp;amp;WISO)&lt;br /&gt;
* If you want do &#039;&#039;&#039;de-register your user account&#039;&#039;&#039; from a bwForCluster, please refer to the general &amp;lt;br /&amp;gt;&amp;amp;rarr; &#039;&#039;&#039;[[Registration/Deregistration|De-registration Guide]]&#039;&#039;&#039;&lt;/div&gt;</summary>
		<author><name>C Mosch</name></author>
	</entry>
	<entry>
		<id>https://wiki.bwhpc.de/wiki/index.php?title=Registration/bwForCluster&amp;diff=10042</id>
		<title>Registration/bwForCluster</title>
		<link rel="alternate" type="text/html" href="https://wiki.bwhpc.de/wiki/index.php?title=Registration/bwForCluster&amp;diff=10042"/>
		<updated>2022-02-17T11:29:14Z</updated>

		<summary type="html">&lt;p&gt;C Mosch: /* Three Steps for Registration */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Registration bwForCluster =&lt;br /&gt;
&lt;br /&gt;
A bwForCluster is a cluster for a specific [https://www.bwhpc.de/cluster.php research area].&lt;br /&gt;
You can apply for a bwForCluster and the &amp;quot;cluster assignment team&amp;quot; will assign you to the appropriate cluster for your research area, taking into account your specific hardware/software needs.&lt;br /&gt;
bwForClusters are funded by the German Research Foundation (DFG) and the Ministry of Science, Research and the Arts of Baden-Württemberg on the basis of grant applications (cf. proposals application guidelines according to Art. 91b GG).&lt;br /&gt;
&lt;br /&gt;
All members of the universities in Baden-Württemberg can apply for an account.&lt;br /&gt;
&lt;br /&gt;
The use of the bwForClusters is free of charge.&lt;br /&gt;
&lt;br /&gt;
== Three Steps for Registration ==&lt;br /&gt;
&lt;br /&gt;
The registration process for a bwForCluster is divided into three steps, whereby step A+B can be performed in parallel.&lt;br /&gt;
When both are completed, you can perform step C.&lt;br /&gt;
To which cluster you get access depends on your research area and will be decided in step B.&lt;br /&gt;
&lt;br /&gt;
* Step A: You need to get the &#039;&#039;&#039;bwForCluster Entitlement&#039;&#039;&#039; from your university/college.&amp;lt;br /&amp;gt;&amp;amp;rarr; &#039;&#039;&#039;[[Registration/bwForCluster/Entitlement|bwForCluster User Access Step A]]&#039;&#039;&#039;&lt;br /&gt;
* Step B: You need to &#039;&#039;&#039;apply for a Rechenvorhaben/project&#039;&#039;&#039; on the &amp;quot;central application site&amp;quot; (ZAS).&amp;lt;br /&amp;gt;&amp;amp;rarr; &#039;&#039;&#039;[[Registration/bwForCluster/RV|bwForCluster User Access Step B]]&#039;&#039;&#039;&lt;br /&gt;
* Step C: You need to &#039;&#039;&#039;register for a bwForCluster&#039;&#039;&#039;.&amp;lt;br /&amp;gt;&amp;amp;rarr; &#039;&#039;&#039;[[Registration/bwForCluster/Service|bwForCluster User Access Step C]]&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
After registering, please refer further to [[Registration/bwForCluster#Information_for_already_registered_users|Information for already registered users]] at the bottom of the page or to the cluster-specific pages below &#039;&#039;&#039;bwHPC Systems&#039;&#039;&#039; in the menu on the left.&lt;br /&gt;
&lt;br /&gt;
[[File:bwForCluster-Registration.png|center|bwForCluster Registration Process]]&lt;br /&gt;
&lt;br /&gt;
== Information for already registered users ==&lt;br /&gt;
&lt;br /&gt;
* If you want to &#039;&#039;&#039;login&#039;&#039;&#039; to one of the bwForClusters, please refer to the general &amp;lt;br /&amp;gt; &amp;amp;rarr; &#039;&#039;&#039;[[Registration/Login|Login Guide]]&#039;&#039;&#039;&lt;br /&gt;
* If you want to &#039;&#039;&#039;create a second factor&#039;&#039;&#039;, please refer to &amp;lt;br /&amp;gt; &amp;amp;rarr; &#039;&#039;&#039;[[Registration/2FA|Generate a Second Factor (2FA)]]&#039;&#039;&#039; (only Justus 2 and MLS&amp;amp;WISO)&lt;br /&gt;
* If you need to &#039;&#039;&#039;change or forgot your password&#039;&#039;&#039; for a bwForCluster, please refer to the general &amp;lt;br /&amp;gt; &amp;amp;rarr; &#039;&#039;&#039;[[Registration/Password|Password Guide]]&#039;&#039;&#039;&lt;br /&gt;
* If you want to &#039;&#039;&#039;use SSH keys&#039;&#039;&#039; on a bwForCluster, please refer to &amp;lt;br /&amp;gt; &amp;amp;rarr; &#039;&#039;&#039;[[Registration/SSH|Registering SSH Keys with your Cluster]]&#039;&#039;&#039; (only MLS&amp;amp;WISO)&lt;br /&gt;
* If you want do &#039;&#039;&#039;de-register your user account&#039;&#039;&#039; from a bwForCluster, please refer to the general &amp;lt;br /&amp;gt;&amp;amp;rarr; &#039;&#039;&#039;[[Registration/Deregistration|De-registration Guide]]&#039;&#039;&#039;&lt;/div&gt;</summary>
		<author><name>C Mosch</name></author>
	</entry>
	<entry>
		<id>https://wiki.bwhpc.de/wiki/index.php?title=Registration/bwForCluster&amp;diff=10041</id>
		<title>Registration/bwForCluster</title>
		<link rel="alternate" type="text/html" href="https://wiki.bwhpc.de/wiki/index.php?title=Registration/bwForCluster&amp;diff=10041"/>
		<updated>2022-02-17T11:27:57Z</updated>

		<summary type="html">&lt;p&gt;C Mosch: /* Information for already registered users */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Registration bwForCluster =&lt;br /&gt;
&lt;br /&gt;
A bwForCluster is a cluster for a specific [https://www.bwhpc.de/cluster.php research area].&lt;br /&gt;
You can apply for a bwForCluster and the &amp;quot;cluster assignment team&amp;quot; will assign you to the appropriate cluster for your research area, taking into account your specific hardware/software needs.&lt;br /&gt;
bwForClusters are funded by the German Research Foundation (DFG) and the Ministry of Science, Research and the Arts of Baden-Württemberg on the basis of grant applications (cf. proposals application guidelines according to Art. 91b GG).&lt;br /&gt;
&lt;br /&gt;
All members of the universities in Baden-Württemberg can apply for an account.&lt;br /&gt;
&lt;br /&gt;
The use of the bwForClusters is free of charge.&lt;br /&gt;
&lt;br /&gt;
== Three Steps for Registration ==&lt;br /&gt;
&lt;br /&gt;
The registration process for a bwForCluster is divided into three steps, whereby step A+B can be performed in parallel.&lt;br /&gt;
When both are completed, you can perform step C.&lt;br /&gt;
To which cluster you get access depends on your research area and will be decided in step B.&lt;br /&gt;
&lt;br /&gt;
* Step A: You need to get the &#039;&#039;&#039;bwForCluster Entitlement&#039;&#039;&#039; from your university/college.&amp;lt;br /&amp;gt;&amp;amp;rarr; &#039;&#039;&#039;[[Registration/bwForCluster/Entitlement|bwForCluster User Access Step A]]&#039;&#039;&#039;&lt;br /&gt;
* Step B: You need to &#039;&#039;&#039;apply for a Rechenvorhaben/project&#039;&#039;&#039; on the &amp;quot;central application site&amp;quot; (ZAS).&amp;lt;br /&amp;gt;&amp;amp;rarr; &#039;&#039;&#039;[[Registration/bwForCluster/RV|bwForCluster User Access Step B]]&#039;&#039;&#039;&lt;br /&gt;
* Step C: You need to &#039;&#039;&#039;register for a bwForCluster&#039;&#039;&#039;.&amp;lt;br /&amp;gt;&amp;amp;rarr; &#039;&#039;&#039;[[Registration/bwForCluster/Service|bwForCluster User Access Step C]]&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
After registering, please refer further to [[Registration/bwForCluster#Information_for_already_registered_users|Information for already registered users]] at the bottom of the page or to the cluster-specific pages.&lt;br /&gt;
&lt;br /&gt;
[[File:bwForCluster-Registration.png|center|bwForCluster Registration Process]]&lt;br /&gt;
&lt;br /&gt;
== Information for already registered users ==&lt;br /&gt;
&lt;br /&gt;
* If you want to &#039;&#039;&#039;login&#039;&#039;&#039; to one of the bwForClusters, please refer to the general &amp;lt;br /&amp;gt; &amp;amp;rarr; &#039;&#039;&#039;[[Registration/Login|Login Guide]]&#039;&#039;&#039;&lt;br /&gt;
* If you want to &#039;&#039;&#039;create a second factor&#039;&#039;&#039;, please refer to &amp;lt;br /&amp;gt; &amp;amp;rarr; &#039;&#039;&#039;[[Registration/2FA|Generate a Second Factor (2FA)]]&#039;&#039;&#039; (only Justus 2 and MLS&amp;amp;WISO)&lt;br /&gt;
* If you need to &#039;&#039;&#039;change or forgot your password&#039;&#039;&#039; for a bwForCluster, please refer to the general &amp;lt;br /&amp;gt; &amp;amp;rarr; &#039;&#039;&#039;[[Registration/Password|Password Guide]]&#039;&#039;&#039;&lt;br /&gt;
* If you want to &#039;&#039;&#039;use SSH keys&#039;&#039;&#039; on a bwForCluster, please refer to &amp;lt;br /&amp;gt; &amp;amp;rarr; &#039;&#039;&#039;[[Registration/SSH|Registering SSH Keys with your Cluster]]&#039;&#039;&#039; (only MLS&amp;amp;WISO)&lt;br /&gt;
* If you want do &#039;&#039;&#039;de-register your user account&#039;&#039;&#039; from a bwForCluster, please refer to the general &amp;lt;br /&amp;gt;&amp;amp;rarr; &#039;&#039;&#039;[[Registration/Deregistration|De-registration Guide]]&#039;&#039;&#039;&lt;/div&gt;</summary>
		<author><name>C Mosch</name></author>
	</entry>
	<entry>
		<id>https://wiki.bwhpc.de/wiki/index.php?title=Registration/bwForCluster&amp;diff=10040</id>
		<title>Registration/bwForCluster</title>
		<link rel="alternate" type="text/html" href="https://wiki.bwhpc.de/wiki/index.php?title=Registration/bwForCluster&amp;diff=10040"/>
		<updated>2022-02-17T11:27:41Z</updated>

		<summary type="html">&lt;p&gt;C Mosch: /* Three Steps for Registration */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Registration bwForCluster =&lt;br /&gt;
&lt;br /&gt;
A bwForCluster is a cluster for a specific [https://www.bwhpc.de/cluster.php research area].&lt;br /&gt;
You can apply for a bwForCluster and the &amp;quot;cluster assignment team&amp;quot; will assign you to the appropriate cluster for your research area, taking into account your specific hardware/software needs.&lt;br /&gt;
bwForClusters are funded by the German Research Foundation (DFG) and the Ministry of Science, Research and the Arts of Baden-Württemberg on the basis of grant applications (cf. proposals application guidelines according to Art. 91b GG).&lt;br /&gt;
&lt;br /&gt;
All members of the universities in Baden-Württemberg can apply for an account.&lt;br /&gt;
&lt;br /&gt;
The use of the bwForClusters is free of charge.&lt;br /&gt;
&lt;br /&gt;
== Three Steps for Registration ==&lt;br /&gt;
&lt;br /&gt;
The registration process for a bwForCluster is divided into three steps, whereby step A+B can be performed in parallel.&lt;br /&gt;
When both are completed, you can perform step C.&lt;br /&gt;
To which cluster you get access depends on your research area and will be decided in step B.&lt;br /&gt;
&lt;br /&gt;
* Step A: You need to get the &#039;&#039;&#039;bwForCluster Entitlement&#039;&#039;&#039; from your university/college.&amp;lt;br /&amp;gt;&amp;amp;rarr; &#039;&#039;&#039;[[Registration/bwForCluster/Entitlement|bwForCluster User Access Step A]]&#039;&#039;&#039;&lt;br /&gt;
* Step B: You need to &#039;&#039;&#039;apply for a Rechenvorhaben/project&#039;&#039;&#039; on the &amp;quot;central application site&amp;quot; (ZAS).&amp;lt;br /&amp;gt;&amp;amp;rarr; &#039;&#039;&#039;[[Registration/bwForCluster/RV|bwForCluster User Access Step B]]&#039;&#039;&#039;&lt;br /&gt;
* Step C: You need to &#039;&#039;&#039;register for a bwForCluster&#039;&#039;&#039;.&amp;lt;br /&amp;gt;&amp;amp;rarr; &#039;&#039;&#039;[[Registration/bwForCluster/Service|bwForCluster User Access Step C]]&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
After registering, please refer further to [[Registration/bwForCluster#Information_for_already_registered_users|Information for already registered users]] at the bottom of the page or to the cluster-specific pages.&lt;br /&gt;
&lt;br /&gt;
[[File:bwForCluster-Registration.png|center|bwForCluster Registration Process]]&lt;br /&gt;
&lt;br /&gt;
== Information for already registered users ==&lt;br /&gt;
&lt;br /&gt;
* For cluster specific documentation see links below &#039;&#039;&#039;bwHPC Systems&#039;&#039;&#039; in the menu on the left.&lt;br /&gt;
* If you want to &#039;&#039;&#039;login&#039;&#039;&#039; to one of the bwForClusters, please refer to the general &amp;lt;br /&amp;gt; &amp;amp;rarr; &#039;&#039;&#039;[[Registration/Login|Login Guide]]&#039;&#039;&#039;&lt;br /&gt;
* If you want to &#039;&#039;&#039;create a second factor&#039;&#039;&#039;, please refer to &amp;lt;br /&amp;gt; &amp;amp;rarr; &#039;&#039;&#039;[[Registration/2FA|Generate a Second Factor (2FA)]]&#039;&#039;&#039; (only Justus 2 and MLS&amp;amp;WISO)&lt;br /&gt;
* If you need to &#039;&#039;&#039;change or forgot your password&#039;&#039;&#039; for a bwForCluster, please refer to the general &amp;lt;br /&amp;gt; &amp;amp;rarr; &#039;&#039;&#039;[[Registration/Password|Password Guide]]&#039;&#039;&#039;&lt;br /&gt;
* If you want to &#039;&#039;&#039;use SSH keys&#039;&#039;&#039; on a bwForCluster, please refer to &amp;lt;br /&amp;gt; &amp;amp;rarr; &#039;&#039;&#039;[[Registration/SSH|Registering SSH Keys with your Cluster]]&#039;&#039;&#039; (only MLS&amp;amp;WISO)&lt;br /&gt;
* If you want do &#039;&#039;&#039;de-register your user account&#039;&#039;&#039; from a bwForCluster, please refer to the general &amp;lt;br /&amp;gt;&amp;amp;rarr; &#039;&#039;&#039;[[Registration/Deregistration|De-registration Guide]]&#039;&#039;&#039;&lt;/div&gt;</summary>
		<author><name>C Mosch</name></author>
	</entry>
	<entry>
		<id>https://wiki.bwhpc.de/wiki/index.php?title=Registration/bwForCluster&amp;diff=10039</id>
		<title>Registration/bwForCluster</title>
		<link rel="alternate" type="text/html" href="https://wiki.bwhpc.de/wiki/index.php?title=Registration/bwForCluster&amp;diff=10039"/>
		<updated>2022-02-17T11:24:47Z</updated>

		<summary type="html">&lt;p&gt;C Mosch: /* Information for already registered users */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Registration bwForCluster =&lt;br /&gt;
&lt;br /&gt;
A bwForCluster is a cluster for a specific [https://www.bwhpc.de/cluster.php research area].&lt;br /&gt;
You can apply for a bwForCluster and the &amp;quot;cluster assignment team&amp;quot; will assign you to the appropriate cluster for your research area, taking into account your specific hardware/software needs.&lt;br /&gt;
bwForClusters are funded by the German Research Foundation (DFG) and the Ministry of Science, Research and the Arts of Baden-Württemberg on the basis of grant applications (cf. proposals application guidelines according to Art. 91b GG).&lt;br /&gt;
&lt;br /&gt;
All members of the universities in Baden-Württemberg can apply for an account.&lt;br /&gt;
&lt;br /&gt;
The use of the bwForClusters is free of charge.&lt;br /&gt;
&lt;br /&gt;
== Three Steps for Registration ==&lt;br /&gt;
&lt;br /&gt;
The registration process for a bwForCluster is divided into three steps, whereby step A+B can be performed in parallel.&lt;br /&gt;
When both are completed, you can perform step C.&lt;br /&gt;
To which cluster you get access depends on your research area and will be decided in step B.&lt;br /&gt;
&lt;br /&gt;
* Step A: You need to get the &#039;&#039;&#039;bwForCluster Entitlement&#039;&#039;&#039; from your university/college.&amp;lt;br /&amp;gt;&amp;amp;rarr; &#039;&#039;&#039;[[Registration/bwForCluster/Entitlement|bwForCluster User Access Step A]]&#039;&#039;&#039;&lt;br /&gt;
* Step B: You need to &#039;&#039;&#039;apply for a Rechenvorhaben/project&#039;&#039;&#039; on the &amp;quot;central application site&amp;quot; (ZAS).&amp;lt;br /&amp;gt;&amp;amp;rarr; &#039;&#039;&#039;[[Registration/bwForCluster/RV|bwForCluster User Access Step B]]&#039;&#039;&#039;&lt;br /&gt;
* Step C: You need to &#039;&#039;&#039;register for a bwForCluster&#039;&#039;&#039;.&amp;lt;br /&amp;gt;&amp;amp;rarr; &#039;&#039;&#039;[[Registration/bwForCluster/Service|bwForCluster User Access Step C]]&#039;&#039;&#039;&lt;br /&gt;
* See next chapter 1.2 for further steps (e.g. login).&lt;br /&gt;
&lt;br /&gt;
After registering, please refer further to [[Registration/bwForCluster#Information_for_already_registered_users|Information for already registered users]] at the bottom of the page or to the cluster-specific pages.&lt;br /&gt;
&lt;br /&gt;
[[File:bwForCluster-Registration.png|center|bwForCluster Registration Process]]&lt;br /&gt;
&lt;br /&gt;
== Information for already registered users ==&lt;br /&gt;
&lt;br /&gt;
* For cluster specific documentation see links below &#039;&#039;&#039;bwHPC Systems&#039;&#039;&#039; in the menu on the left.&lt;br /&gt;
* If you want to &#039;&#039;&#039;login&#039;&#039;&#039; to one of the bwForClusters, please refer to the general &amp;lt;br /&amp;gt; &amp;amp;rarr; &#039;&#039;&#039;[[Registration/Login|Login Guide]]&#039;&#039;&#039;&lt;br /&gt;
* If you want to &#039;&#039;&#039;create a second factor&#039;&#039;&#039;, please refer to &amp;lt;br /&amp;gt; &amp;amp;rarr; &#039;&#039;&#039;[[Registration/2FA|Generate a Second Factor (2FA)]]&#039;&#039;&#039; (only Justus 2 and MLS&amp;amp;WISO)&lt;br /&gt;
* If you need to &#039;&#039;&#039;change or forgot your password&#039;&#039;&#039; for a bwForCluster, please refer to the general &amp;lt;br /&amp;gt; &amp;amp;rarr; &#039;&#039;&#039;[[Registration/Password|Password Guide]]&#039;&#039;&#039;&lt;br /&gt;
* If you want to &#039;&#039;&#039;use SSH keys&#039;&#039;&#039; on a bwForCluster, please refer to &amp;lt;br /&amp;gt; &amp;amp;rarr; &#039;&#039;&#039;[[Registration/SSH|Registering SSH Keys with your Cluster]]&#039;&#039;&#039; (only MLS&amp;amp;WISO)&lt;br /&gt;
* If you want do &#039;&#039;&#039;de-register your user account&#039;&#039;&#039; from a bwForCluster, please refer to the general &amp;lt;br /&amp;gt;&amp;amp;rarr; &#039;&#039;&#039;[[Registration/Deregistration|De-registration Guide]]&#039;&#039;&#039;&lt;/div&gt;</summary>
		<author><name>C Mosch</name></author>
	</entry>
	<entry>
		<id>https://wiki.bwhpc.de/wiki/index.php?title=Registration/bwForCluster&amp;diff=10038</id>
		<title>Registration/bwForCluster</title>
		<link rel="alternate" type="text/html" href="https://wiki.bwhpc.de/wiki/index.php?title=Registration/bwForCluster&amp;diff=10038"/>
		<updated>2022-02-17T11:23:56Z</updated>

		<summary type="html">&lt;p&gt;C Mosch: /* Information for already registered users */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Registration bwForCluster =&lt;br /&gt;
&lt;br /&gt;
A bwForCluster is a cluster for a specific [https://www.bwhpc.de/cluster.php research area].&lt;br /&gt;
You can apply for a bwForCluster and the &amp;quot;cluster assignment team&amp;quot; will assign you to the appropriate cluster for your research area, taking into account your specific hardware/software needs.&lt;br /&gt;
bwForClusters are funded by the German Research Foundation (DFG) and the Ministry of Science, Research and the Arts of Baden-Württemberg on the basis of grant applications (cf. proposals application guidelines according to Art. 91b GG).&lt;br /&gt;
&lt;br /&gt;
All members of the universities in Baden-Württemberg can apply for an account.&lt;br /&gt;
&lt;br /&gt;
The use of the bwForClusters is free of charge.&lt;br /&gt;
&lt;br /&gt;
== Three Steps for Registration ==&lt;br /&gt;
&lt;br /&gt;
The registration process for a bwForCluster is divided into three steps, whereby step A+B can be performed in parallel.&lt;br /&gt;
When both are completed, you can perform step C.&lt;br /&gt;
To which cluster you get access depends on your research area and will be decided in step B.&lt;br /&gt;
&lt;br /&gt;
* Step A: You need to get the &#039;&#039;&#039;bwForCluster Entitlement&#039;&#039;&#039; from your university/college.&amp;lt;br /&amp;gt;&amp;amp;rarr; &#039;&#039;&#039;[[Registration/bwForCluster/Entitlement|bwForCluster User Access Step A]]&#039;&#039;&#039;&lt;br /&gt;
* Step B: You need to &#039;&#039;&#039;apply for a Rechenvorhaben/project&#039;&#039;&#039; on the &amp;quot;central application site&amp;quot; (ZAS).&amp;lt;br /&amp;gt;&amp;amp;rarr; &#039;&#039;&#039;[[Registration/bwForCluster/RV|bwForCluster User Access Step B]]&#039;&#039;&#039;&lt;br /&gt;
* Step C: You need to &#039;&#039;&#039;register for a bwForCluster&#039;&#039;&#039;.&amp;lt;br /&amp;gt;&amp;amp;rarr; &#039;&#039;&#039;[[Registration/bwForCluster/Service|bwForCluster User Access Step C]]&#039;&#039;&#039;&lt;br /&gt;
* See next chapter 1.2 for further steps (e.g. login).&lt;br /&gt;
&lt;br /&gt;
After registering, please refer further to [[Registration/bwForCluster#Information_for_already_registered_users|Information for already registered users]] at the bottom of the page or to the cluster-specific pages.&lt;br /&gt;
&lt;br /&gt;
[[File:bwForCluster-Registration.png|center|bwForCluster Registration Process]]&lt;br /&gt;
&lt;br /&gt;
== Information for already registered users ==&lt;br /&gt;
&lt;br /&gt;
* For cluster specific documentation see &#039;&#039;&#039;bwHPC Systems&#039;&#039;&#039; in the menu on the left side.&lt;br /&gt;
* If you want to &#039;&#039;&#039;login&#039;&#039;&#039; to one of the bwForClusters, please refer to the general &amp;lt;br /&amp;gt; &amp;amp;rarr; &#039;&#039;&#039;[[Registration/Login|Login Guide]]&#039;&#039;&#039;&lt;br /&gt;
* If you want to &#039;&#039;&#039;create a second factor&#039;&#039;&#039;, please refer to &amp;lt;br /&amp;gt; &amp;amp;rarr; &#039;&#039;&#039;[[Registration/2FA|Generate a Second Factor (2FA)]]&#039;&#039;&#039; (only Justus 2 and MLS&amp;amp;WISO)&lt;br /&gt;
* If you need to &#039;&#039;&#039;change or forgot your password&#039;&#039;&#039; for a bwForCluster, please refer to the general &amp;lt;br /&amp;gt; &amp;amp;rarr; &#039;&#039;&#039;[[Registration/Password|Password Guide]]&#039;&#039;&#039;&lt;br /&gt;
* If you want to &#039;&#039;&#039;use SSH keys&#039;&#039;&#039; on a bwForCluster, please refer to &amp;lt;br /&amp;gt; &amp;amp;rarr; &#039;&#039;&#039;[[Registration/SSH|Registering SSH Keys with your Cluster]]&#039;&#039;&#039; (only MLS&amp;amp;WISO)&lt;br /&gt;
* If you want do &#039;&#039;&#039;de-register your user account&#039;&#039;&#039; from a bwForCluster, please refer to the general &amp;lt;br /&amp;gt;&amp;amp;rarr; &#039;&#039;&#039;[[Registration/Deregistration|De-registration Guide]]&#039;&#039;&#039;&lt;/div&gt;</summary>
		<author><name>C Mosch</name></author>
	</entry>
	<entry>
		<id>https://wiki.bwhpc.de/wiki/index.php?title=Registration/bwForCluster&amp;diff=10035</id>
		<title>Registration/bwForCluster</title>
		<link rel="alternate" type="text/html" href="https://wiki.bwhpc.de/wiki/index.php?title=Registration/bwForCluster&amp;diff=10035"/>
		<updated>2022-02-17T11:20:43Z</updated>

		<summary type="html">&lt;p&gt;C Mosch: /* Three Steps for Registration */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Registration bwForCluster =&lt;br /&gt;
&lt;br /&gt;
A bwForCluster is a cluster for a specific [https://www.bwhpc.de/cluster.php research area].&lt;br /&gt;
You can apply for a bwForCluster and the &amp;quot;cluster assignment team&amp;quot; will assign you to the appropriate cluster for your research area, taking into account your specific hardware/software needs.&lt;br /&gt;
bwForClusters are funded by the German Research Foundation (DFG) and the Ministry of Science, Research and the Arts of Baden-Württemberg on the basis of grant applications (cf. proposals application guidelines according to Art. 91b GG).&lt;br /&gt;
&lt;br /&gt;
All members of the universities in Baden-Württemberg can apply for an account.&lt;br /&gt;
&lt;br /&gt;
The use of the bwForClusters is free of charge.&lt;br /&gt;
&lt;br /&gt;
== Three Steps for Registration ==&lt;br /&gt;
&lt;br /&gt;
The registration process for a bwForCluster is divided into three steps, whereby step A+B can be performed in parallel.&lt;br /&gt;
When both are completed, you can perform step C.&lt;br /&gt;
To which cluster you get access depends on your research area and will be decided in step B.&lt;br /&gt;
&lt;br /&gt;
* Step A: You need to get the &#039;&#039;&#039;bwForCluster Entitlement&#039;&#039;&#039; from your university/college.&amp;lt;br /&amp;gt;&amp;amp;rarr; &#039;&#039;&#039;[[Registration/bwForCluster/Entitlement|bwForCluster User Access Step A]]&#039;&#039;&#039;&lt;br /&gt;
* Step B: You need to &#039;&#039;&#039;apply for a Rechenvorhaben/project&#039;&#039;&#039; on the &amp;quot;central application site&amp;quot; (ZAS).&amp;lt;br /&amp;gt;&amp;amp;rarr; &#039;&#039;&#039;[[Registration/bwForCluster/RV|bwForCluster User Access Step B]]&#039;&#039;&#039;&lt;br /&gt;
* Step C: You need to &#039;&#039;&#039;register for a bwForCluster&#039;&#039;&#039;.&amp;lt;br /&amp;gt;&amp;amp;rarr; &#039;&#039;&#039;[[Registration/bwForCluster/Service|bwForCluster User Access Step C]]&#039;&#039;&#039;&lt;br /&gt;
* See next chapter 1.2 for further steps (e.g. login).&lt;br /&gt;
&lt;br /&gt;
[[File:bwForCluster-Registration.png|center|bwForCluster Registration Process]]&lt;br /&gt;
&lt;br /&gt;
== Information for already registered users ==&lt;br /&gt;
&lt;br /&gt;
* If you want to &#039;&#039;&#039;login&#039;&#039;&#039; to one of the bwForClusters, please refer to the general &amp;lt;br /&amp;gt; &amp;amp;rarr; &#039;&#039;&#039;[[Registration/Login|Login Guide]]&#039;&#039;&#039;&lt;br /&gt;
* If you want to &#039;&#039;&#039;create a second factor&#039;&#039;&#039;, please refer to &amp;lt;br /&amp;gt; &amp;amp;rarr; &#039;&#039;&#039;[[Registration/2FA|Generate a Second Factor (2FA)]]&#039;&#039;&#039; (only Justus 2 and MLS&amp;amp;WISO)&lt;br /&gt;
* If you need to &#039;&#039;&#039;change or forgot your password&#039;&#039;&#039; for a bwForCluster, please refer to the general &amp;lt;br /&amp;gt; &amp;amp;rarr; &#039;&#039;&#039;[[Registration/Password|Password Guide]]&#039;&#039;&#039;&lt;br /&gt;
* If you want to &#039;&#039;&#039;use SSH keys&#039;&#039;&#039; on a bwForCluster, please refer to &amp;lt;br /&amp;gt; &amp;amp;rarr; &#039;&#039;&#039;[[Registration/SSH|Registering SSH Keys with your Cluster]]&#039;&#039;&#039; (only MLS&amp;amp;WISO)&lt;br /&gt;
* If you want do &#039;&#039;&#039;de-register your user account&#039;&#039;&#039; from a bwForCluster, please refer to the general &amp;lt;br /&amp;gt;&amp;amp;rarr; &#039;&#039;&#039;[[Registration/Deregistration|De-registration Guide]]&#039;&#039;&#039;&lt;/div&gt;</summary>
		<author><name>C Mosch</name></author>
	</entry>
	<entry>
		<id>https://wiki.bwhpc.de/wiki/index.php?title=Registration/bwForCluster&amp;diff=10034</id>
		<title>Registration/bwForCluster</title>
		<link rel="alternate" type="text/html" href="https://wiki.bwhpc.de/wiki/index.php?title=Registration/bwForCluster&amp;diff=10034"/>
		<updated>2022-02-17T11:14:39Z</updated>

		<summary type="html">&lt;p&gt;C Mosch: /* Three Steps for Registration */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Registration bwForCluster =&lt;br /&gt;
&lt;br /&gt;
A bwForCluster is a cluster for a specific [https://www.bwhpc.de/cluster.php research area].&lt;br /&gt;
You can apply for a bwForCluster and the &amp;quot;cluster assignment team&amp;quot; will assign you to the appropriate cluster for your research area, taking into account your specific hardware/software needs.&lt;br /&gt;
bwForClusters are funded by the German Research Foundation (DFG) and the Ministry of Science, Research and the Arts of Baden-Württemberg on the basis of grant applications (cf. proposals application guidelines according to Art. 91b GG).&lt;br /&gt;
&lt;br /&gt;
All members of the universities in Baden-Württemberg can apply for an account.&lt;br /&gt;
&lt;br /&gt;
The use of the bwForClusters is free of charge.&lt;br /&gt;
&lt;br /&gt;
== Three Steps for Registration ==&lt;br /&gt;
&lt;br /&gt;
The registration process for a bwForCluster is divided into three steps, whereby step A+B can be performed in parallel.&lt;br /&gt;
When both are completed, you can perform step C.&lt;br /&gt;
To which cluster you get access depends on your research area and will be decided in step B.&lt;br /&gt;
&lt;br /&gt;
* Step A: You need to get the &#039;&#039;&#039;bwForCluster Entitlement&#039;&#039;&#039; from your university/college.&amp;lt;br /&amp;gt;&amp;amp;rarr; &#039;&#039;&#039;[[Registration/bwForCluster/Entitlement|bwForCluster User Access Step A]]&#039;&#039;&#039;&lt;br /&gt;
* Step B: You need to &#039;&#039;&#039;apply for a Rechenvorhaben/project&#039;&#039;&#039; on the &amp;quot;central application site&amp;quot; (ZAS).&amp;lt;br /&amp;gt;&amp;amp;rarr; &#039;&#039;&#039;[[Registration/bwForCluster/RV|bwForCluster User Access Step B]]&#039;&#039;&#039;&lt;br /&gt;
* Step C: You need to &#039;&#039;&#039;register for a bwForCluster&#039;&#039;&#039;.&amp;lt;br /&amp;gt;&amp;amp;rarr; &#039;&#039;&#039;[[Registration/bwForCluster/Service|bwForCluster User Access Step C]]&#039;&#039;&#039;&lt;br /&gt;
* See next chapter 1.2 below for further steps.&lt;br /&gt;
&lt;br /&gt;
[[File:bwForCluster-Registration.png|center|bwForCluster Registration Process]]&lt;br /&gt;
&lt;br /&gt;
== Information for already registered users ==&lt;br /&gt;
&lt;br /&gt;
* If you want to &#039;&#039;&#039;login&#039;&#039;&#039; to one of the bwForClusters, please refer to the general &amp;lt;br /&amp;gt; &amp;amp;rarr; &#039;&#039;&#039;[[Registration/Login|Login Guide]]&#039;&#039;&#039;&lt;br /&gt;
* If you want to &#039;&#039;&#039;create a second factor&#039;&#039;&#039;, please refer to &amp;lt;br /&amp;gt; &amp;amp;rarr; &#039;&#039;&#039;[[Registration/2FA|Generate a Second Factor (2FA)]]&#039;&#039;&#039; (only Justus 2 and MLS&amp;amp;WISO)&lt;br /&gt;
* If you need to &#039;&#039;&#039;change or forgot your password&#039;&#039;&#039; for a bwForCluster, please refer to the general &amp;lt;br /&amp;gt; &amp;amp;rarr; &#039;&#039;&#039;[[Registration/Password|Password Guide]]&#039;&#039;&#039;&lt;br /&gt;
* If you want to &#039;&#039;&#039;use SSH keys&#039;&#039;&#039; on a bwForCluster, please refer to &amp;lt;br /&amp;gt; &amp;amp;rarr; &#039;&#039;&#039;[[Registration/SSH|Registering SSH Keys with your Cluster]]&#039;&#039;&#039; (only MLS&amp;amp;WISO)&lt;br /&gt;
* If you want do &#039;&#039;&#039;de-register your user account&#039;&#039;&#039; from a bwForCluster, please refer to the general &amp;lt;br /&amp;gt;&amp;amp;rarr; &#039;&#039;&#039;[[Registration/Deregistration|De-registration Guide]]&#039;&#039;&#039;&lt;/div&gt;</summary>
		<author><name>C Mosch</name></author>
	</entry>
	<entry>
		<id>https://wiki.bwhpc.de/wiki/index.php?title=Registration/Browser&amp;diff=10025</id>
		<title>Registration/Browser</title>
		<link rel="alternate" type="text/html" href="https://wiki.bwhpc.de/wiki/index.php?title=Registration/Browser&amp;diff=10025"/>
		<updated>2022-02-16T15:35:30Z</updated>

		<summary type="html">&lt;p&gt;C Mosch: /* Firefox Troubleshoot Mode */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Disabling Add Ons in Browsers =&lt;br /&gt;
&lt;br /&gt;
Some user interfaces can be blocked by browser add-ons during the registration process or when changes are made afterwards, such as the &amp;quot;[[Registration/2FA|Second Factor (2FA)]]&amp;quot; and [[Registration/SSH|SSH]] settings.&lt;br /&gt;
Please disable all privacy tools, ad blockers and further add-ons when registering new tokens.&lt;br /&gt;
&lt;br /&gt;
For Chrome, we recommend using &amp;quot;Incognito Mode&amp;quot; when configuring 2FA and SSH.&lt;br /&gt;
For Firefox, please use the &amp;quot;Troubleshoot Mode&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Chrome Incognito Mode ==&lt;br /&gt;
&lt;br /&gt;
By default, Chrome&#039;s incognito mode disables add-ons, but you can manually enable them for this mode as well.&lt;br /&gt;
If this is the case, please disable them manually again first.&lt;br /&gt;
&lt;br /&gt;
You can start Chrome incognito mode by either, ...&lt;br /&gt;
&lt;br /&gt;
1. pressing &#039;&#039;&#039;CTRL+SHIFT+N&#039;&#039;&#039; in an already open Chrome window, ...&lt;br /&gt;
&lt;br /&gt;
2. typing &amp;lt;code&amp;gt;google-chrome --incognito&amp;lt;/code&amp;gt; in a linux console or &amp;lt;code&amp;gt;chrome.exe --incognito&amp;lt;/code&amp;gt; in a Windows console or ...&lt;br /&gt;
&lt;br /&gt;
3. &#039;&#039;&#039;selecting &amp;quot;New Incognito Window&amp;quot; from the burger menu&#039;&#039;&#039; in the upper right corner.&lt;br /&gt;
[[File:Chrome-inc.png|center|400px|thumb|Chrome Incognito Mode.]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Firefox Troubleshoot Mode ==&lt;br /&gt;
&lt;br /&gt;
For Firefox, we recommend using the &amp;quot;Troubleshoot Mode&amp;quot;.&lt;br /&gt;
In this mode, all add-ons are disabled.&lt;br /&gt;
&lt;br /&gt;
You can start Firefox &amp;quot;Troubleshoot Mode&amp;quot; or &amp;quot;Safe Mode&amp;quot; by either, ...&lt;br /&gt;
&lt;br /&gt;
1. (Firefox NOT running) typing &amp;lt;code&amp;gt;firefox --safe-mode&amp;lt;/code&amp;gt; in a linux console or &amp;lt;code&amp;gt;firefox.exe --safe-mode&amp;lt;/code&amp;gt; in a Windows console or ...&lt;br /&gt;
&lt;br /&gt;
2. (Firefox already running) &#039;&#039;&#039;selecting &amp;quot;Help&amp;quot; and then &amp;quot;Troubleshoot Mode&amp;quot; from the burger menu&#039;&#039;&#039; in the upper right corner.&lt;br /&gt;
[[File:Firefox-safe.png|center|400px|thumb|Firefox Troubleshoot Mode.]]&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
Be careful: This step will reload all currently loaded browser tabs without any Add-Ons.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Select &#039;&#039;&#039;Open&#039;&#039;&#039; to start &amp;quot;Troubleshoot Mode&amp;quot;.&lt;br /&gt;
[[File:Firefox-safe-open.png|center|400px|thumb|Start Troubleshoot Mode by clicking Open.]]&lt;/div&gt;</summary>
		<author><name>C Mosch</name></author>
	</entry>
	<entry>
		<id>https://wiki.bwhpc.de/wiki/index.php?title=Registration/Browser&amp;diff=10024</id>
		<title>Registration/Browser</title>
		<link rel="alternate" type="text/html" href="https://wiki.bwhpc.de/wiki/index.php?title=Registration/Browser&amp;diff=10024"/>
		<updated>2022-02-16T15:29:23Z</updated>

		<summary type="html">&lt;p&gt;C Mosch: /* Firefox Troubleshoot Mode */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Disabling Add Ons in Browsers =&lt;br /&gt;
&lt;br /&gt;
Some user interfaces can be blocked by browser add-ons during the registration process or when changes are made afterwards, such as the &amp;quot;[[Registration/2FA|Second Factor (2FA)]]&amp;quot; and [[Registration/SSH|SSH]] settings.&lt;br /&gt;
Please disable all privacy tools, ad blockers and further add-ons when registering new tokens.&lt;br /&gt;
&lt;br /&gt;
For Chrome, we recommend using &amp;quot;Incognito Mode&amp;quot; when configuring 2FA and SSH.&lt;br /&gt;
For Firefox, please use the &amp;quot;Troubleshoot Mode&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Chrome Incognito Mode ==&lt;br /&gt;
&lt;br /&gt;
By default, Chrome&#039;s incognito mode disables add-ons, but you can manually enable them for this mode as well.&lt;br /&gt;
If this is the case, please disable them manually again first.&lt;br /&gt;
&lt;br /&gt;
You can start Chrome incognito mode by either, ...&lt;br /&gt;
&lt;br /&gt;
1. pressing &#039;&#039;&#039;CTRL+SHIFT+N&#039;&#039;&#039; in an already open Chrome window, ...&lt;br /&gt;
&lt;br /&gt;
2. typing &amp;lt;code&amp;gt;google-chrome --incognito&amp;lt;/code&amp;gt; in a linux console or &amp;lt;code&amp;gt;chrome.exe --incognito&amp;lt;/code&amp;gt; in a Windows console or ...&lt;br /&gt;
&lt;br /&gt;
3. &#039;&#039;&#039;selecting &amp;quot;New Incognito Window&amp;quot; from the burger menu&#039;&#039;&#039; in the upper right corner.&lt;br /&gt;
[[File:Chrome-inc.png|center|400px|thumb|Chrome Incognito Mode.]]&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Firefox Troubleshoot Mode ==&lt;br /&gt;
&lt;br /&gt;
For Firefox, we recommend using the &amp;quot;Troubleshoot Mode&amp;quot;.&lt;br /&gt;
In this mode, all add-ons are disabled.&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
Be careful: Following steps will reload all your browser windows.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
You can start Firefox &amp;quot;Troubleshoot Mode&amp;quot; or &amp;quot;Safe Mode&amp;quot; by either, ...&lt;br /&gt;
&lt;br /&gt;
1. typing &amp;lt;code&amp;gt;firefox --safe-mode&amp;lt;/code&amp;gt; in a linux console or &amp;lt;code&amp;gt;firefox.exe --safe-mode&amp;lt;/code&amp;gt; in a Windows console or ...&lt;br /&gt;
&lt;br /&gt;
2. &#039;&#039;&#039;selecting &amp;quot;Help&amp;quot; and then &amp;quot;Troubleshoot Mode&amp;quot; from the burger menu&#039;&#039;&#039; in the upper right corner.&lt;br /&gt;
[[File:Firefox-safe.png|center|400px|thumb|Firefox Troubleshoot Mode.]]&lt;br /&gt;
Select &#039;&#039;&#039;Open&#039;&#039;&#039; to start &amp;quot;Troubleshoot Mode&amp;quot;.&lt;br /&gt;
[[File:Firefox-safe-open.png|center|400px|thumb|Start Troubleshoot Mode by clicking Open.]]&lt;/div&gt;</summary>
		<author><name>C Mosch</name></author>
	</entry>
	<entry>
		<id>https://wiki.bwhpc.de/wiki/index.php?title=Registration/2FA&amp;diff=10008</id>
		<title>Registration/2FA</title>
		<link rel="alternate" type="text/html" href="https://wiki.bwhpc.de/wiki/index.php?title=Registration/2FA&amp;diff=10008"/>
		<updated>2022-02-15T20:00:02Z</updated>

		<summary type="html">&lt;p&gt;C Mosch: /* Token Management */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Generate a Second Factor (2FA) =&lt;br /&gt;
&lt;br /&gt;
To improve security a &#039;&#039;&#039;2-factor authentication mechanism (2FA)&#039;&#039;&#039; is being enforced for logins to bwUniCluster/bwForClusters. In addition to the service password a second value, the &#039;&#039;&#039;second factor&#039;&#039;&#039;, has to be entered on every login.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== How 2FA works ==&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
It is very important that the device that generates the One-Time Passwords and the device which is used to log into the bwUniCluster/bwForClusters are not the same.&lt;br /&gt;
Otherwise an attacker who gains access to your system can steal both the service password and the secret key of the Software Token application, which allows them to generate One-Time Passwords and log into the HPC system without your knowledge.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
[[File:2fa token code.jpg|right|200px|thumb|Hardware Token for TOTP]]&lt;br /&gt;
On the bwUniCluster/bwForClusters we use six-digit, auto-generated, time-dependent &#039;&#039;&#039;one-time passwords&#039;&#039;&#039; (TOTP). These passwords are generated by a piece of software which is part of a special hardware device (a &#039;&#039;&#039;hardware token&#039;&#039;&#039;) or of a normal application running on a common device (a &#039;&#039;&#039;software token&#039;&#039;&#039;).&lt;br /&gt;
&lt;br /&gt;
The Token has to be synchronized with a central server before it can be used for authentication and then generates an endless stream of six-digit values (TOTPs) which can only be used once and are only valid during a very short interval of time. This makes it much harder for potential attackers to access the HPC system, even if they know the regular service password.&lt;br /&gt;
&lt;br /&gt;
Typically a new TOTP value is generated every 30 seconds. When the current TOTP value has once been used successfully for a login, it is depleted and one has to wait up to 30 seconds for the next TOTP value. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:Otpapp.png|right|150px|thumb|Source: https://getaegis.app]]&lt;br /&gt;
&lt;br /&gt;
The most common solution is to use a mobile device (e.g. your smartphone or tablet) as a Software Token by installing one of the following apps:&lt;br /&gt;
* Google Authenticator for [https://play.google.com/store/apps/details?id=com.google.android.apps.authenticator2 Android] or [https://apps.apple.com/de/app/google-authenticator/id388497605 iOS]&lt;br /&gt;
* Microsoft Authenticator for [https://play.google.com/store/apps/details?id=com.azure.authenticator Android] or [https://apps.apple.com/de/app/microsoft-authenticator/id983156458 iOS] ([https://www.microsoft.com/de-de/security/mobile-authenticator-app Web Page])&lt;br /&gt;
* LastPass Authenticator for [https://play.google.com/store/apps/details?id=com.lastpass.authenticator Android], [https://apps.apple.com/us/app/lastpass-authenticator/id1079110004 iOS] or [https://lastpass.com/auth/ Windows]&lt;br /&gt;
* Aegis Authenticator for [https://play.google.com/store/apps/details?id=com.beemdevelopment.aegis Android (Google Play)] or [https://f-droid.org/en/packages/com.beemdevelopment.aegis/ Android (F-Droid)] ([https://getaegis.app/ Web Page])&lt;br /&gt;
* andOTP Authenticator for [https://play.google.com/store/apps/details?id=org.shadowice.flocke.andotp Android (Google Play)] or [https://f-droid.org/packages/org.shadowice.flocke.andotp/ Android (F-Droid)] ([https://github.com/andOTP/andOTP GitHub])&lt;br /&gt;
* OTP Auth for [https://apps.apple.com/app/otp-auth/id659877384 iOS]&lt;br /&gt;
* (Authy for [https://play.google.com/store/apps/details?id=com.authy.authy Android], [https://apps.apple.com/us/app/authy/id494168017 iOS], [https://authy.com/download/ Mac, Windows or Linux]) requires account&lt;br /&gt;
* (On Linux you can use [https://keepassxc.org/ KeepassXC] or [https://github.com/paolostivanin/OTPClient otpclient])&lt;br /&gt;
&lt;br /&gt;
These are only suggestions. You can use any application compatible with the [https://tools.ietf.org/html/rfc6238 TOTP] standard.&lt;br /&gt;
&lt;br /&gt;
If you don&#039;t want to use a smartphone, we recommend using a hardware token, such as Yubikey or another TOTP-compatible device. [https://www.yubico.com/resources/glossary/yubico-otp/ Yubico OTP] is also supported if you want to use your Yubikey without depending on having a six-digit code displayed. But you can also use the Yubikey as a generator for six-digit [https://www.yubico.com/resources/glossary/oath-totp/ TOTP].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Token Management =&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
* Create at least two separate tokens: &#039;&#039;&#039;FIRST&#039;&#039;&#039; set up a software/hardware TOTP token. &#039;&#039;&#039;THEN&#039;&#039;&#039; create and print a &amp;quot;backup TAN list&amp;quot;. Never create the &amp;quot;backup TAN list&amp;quot; first.&lt;br /&gt;
* If you lose access to all your tokens, you will not be able to create new tokens and support will have to reset your tokens manually.&lt;br /&gt;
* The &amp;quot;backup TAN list&amp;quot; should always be created and printed in a &#039;&#039;&#039;second step&#039;&#039;&#039;. The printout should be kept in a separate place for emergencies.&lt;br /&gt;
* Please clean up your second factors as soon as you have created new tokens. Tokens that can no longer be used (e.g. because not initialized, smartphone/Yubikey lost, etc.) or an old backup TAN list where you have already used all TANs or there is no printout should be deactivated and deleted.&lt;br /&gt;
* Returning users who have already activated one or more tokens must first verify their token before they can create new tokens, see section [[Registration/2FA#Returning_Users|Returning Users]].&lt;br /&gt;
* &#039;&#039;&#039;Please disable all privacy tools, ad blockers and further add-ons when registering new tokens.&#039;&#039;&#039; These tools prevent the registration website from generating new security tokens. When the problems remains (you can not generate the QR code or can not confirm it by clicking CHECK), please try once more with an entirely new unmodified web browser profile.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;bwUniCluster/bwForCluster Tokens&#039;&#039;&#039; are generally managed via the &#039;&#039;&#039;Index -&amp;gt; My Tokens&#039;&#039;&#039; menu entry on the registration pages for the clusters. Here you can register, activate, deactivate and delete tokens.&lt;br /&gt;
&lt;br /&gt;
To activate the second factor, &#039;&#039;&#039;please perform the following steps:&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
1. &#039;&#039;&#039;Select the registration server of the cluster&#039;&#039;&#039; for which you want to create a second factor and login to it:&amp;lt;/br&amp;gt; &amp;amp;rarr; [https://login.bwidm.de/user/twofa.xhtml Registration server for &#039;&#039;&#039;bwUniCluster 2.0&#039;&#039;&#039; and &#039;&#039;&#039;bwForCluster JUSTUS 2&#039;&#039;&#039;] (2FA tokens are valid for both clusters; KIT members can reuse their existing hardware and software tokens)&amp;lt;/br&amp;gt; &amp;amp;rarr; [https://bwservices.uni-heidelberg.de//user/twofa.xhtml Registration server for &#039;&#039;&#039;bwForCluster MLS&amp;amp;WISO&#039;&#039;&#039;]&lt;br /&gt;
[[File:BwIDM-twofa.png|center|600px|thumb|My Tokens]]&lt;br /&gt;
&lt;br /&gt;
2. &#039;&#039;&#039;Register a new &amp;quot;[[Registration/2FA#Registering_a_new_Software_Token_using_a_Mobile_APP|Smartphone Token]]&amp;quot;&#039;&#039;&#039; or if you own a [https://www.yubico.com/ Yubikey]&#039;&#039;&#039; register a new &amp;quot;[[Registration/2FA#Registering_a_new_Yubikey_OTP_Token|Yubikey Token]]&amp;quot;&#039;&#039;&#039; or &#039;&#039;&#039;&amp;quot;[[Registration/2FA#Registering_a_new_Yubikey_OATH_TOTP_Token|Yubikey OATH TOTP Token]]&amp;quot;&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
3. &#039;&#039;&#039;Register a new &amp;quot;[[Registration/2FA#Backup_TAN_List|TAN List]]&amp;quot; (backup TAN list)&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
4. Repeat step 2. for additional tokens.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Registering a new Software Token using a Mobile APP ==&lt;br /&gt;
&lt;br /&gt;
1. Registering a new Token starts with a click &#039;&#039;&#039;NEW SMARTPHONE TOKEN&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-token.png|center|600px|thumb|Create a new Token]]&lt;br /&gt;
&lt;br /&gt;
2. A new window opens. Click &#039;&#039;&#039;Start&#039;&#039;&#039; to generate a new &#039;&#039;&#039;QR code&#039;&#039;&#039;.&lt;br /&gt;
This may take a while.&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
The QR code contains a key which has to remain secret.&lt;br /&gt;
Only use the QR code to link your software token app with bwIDM/bwServices in the next step.&lt;br /&gt;
Do not save the QR code, print it out or share it with someone else.&lt;br /&gt;
|}&lt;br /&gt;
[[File:BwIDM-qr.png|center|600px|thumb|QR Code for Mobile App]]&lt;br /&gt;
&lt;br /&gt;
3. Start the software token app on your separate device and scan the QR code.&lt;br /&gt;
The exact process is a little bit different in every app, but is usually started by pressing on a button with a plus (+) sign or an icon of a QR code.&lt;br /&gt;
&lt;br /&gt;
4. Once the QR code has been loaded into your Software Token app there should be a new entry called &#039;&#039;&#039;bwIDM&#039;&#039;&#039; (bwUniCluster and JUSTUS 2) or &#039;&#039;&#039;bwServices&#039;&#039;&#039; (MLS&amp;amp;WISO).&lt;br /&gt;
Generate an One-Time-Password by pressing on this entry or selecting the appropriate button/menu item.&lt;br /&gt;
You will receive a six-digit code.&lt;br /&gt;
Enter this code into the field labeled &amp;quot;Current code:&amp;quot; in your bwIDM browser window to prove that the connection has worked and then click &#039;&#039;&#039;CHECK&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
5. If everything worked as expected, you will be returned to the &#039;&#039;&#039;My Tokens&#039;&#039;&#039; screen and there will be a new entry for your software token.&lt;br /&gt;
[[File:BwIDM-app.png|center|400px|thumb|Success]]&lt;br /&gt;
&lt;br /&gt;
6. Repeat the process to register additional tokens.&lt;br /&gt;
Please register at least the &amp;quot;Backup TAN list&amp;quot; in addition to the hardware/software token you plan to use regularly.&lt;br /&gt;
&lt;br /&gt;
== Registering a new Yubikey OTP Token ==&lt;br /&gt;
&lt;br /&gt;
[https://developers.yubico.com/OTP/OTPs_Explained.html Yubikey OTP] is even easier and you don&#039;t need a device that displays the six-digit code or extra software.&lt;br /&gt;
New Yubikeys are already configured to provide Yubikey OTP in slot 1.&lt;br /&gt;
If you need to configure your Yubikey, read this [[Registration/2FA/Yubikey|documentation]].&lt;br /&gt;
&lt;br /&gt;
1. If you want to use [https://www.yubico.com/resources/glossary/yubico-otp/ Yubico OTP], you can click &#039;&#039;&#039;NEW YUBIKEY TOKEN&#039;&#039;&#039; instead.&lt;br /&gt;
[[File:BwIDM-token.png|center|600px|thumb|Generate Yubikey OTP]]&lt;br /&gt;
&lt;br /&gt;
2. Yubikey OTP is configured to slot 1 on new Yubikeys, so you only need to click in the text box and then touch the metal part of your Yubikey.&lt;br /&gt;
Please refer to this [[Registration/2FA/Yubikey|documentation]] on how to configure your Yubikey.&lt;br /&gt;
[[File:BwIDM-yubikey.png|center|400px|thumb|Yubikey OTP]]&lt;br /&gt;
&lt;br /&gt;
3. If everything worked as expected, you will be returned to the &#039;&#039;&#039;My Tokens&#039;&#039;&#039; screen and there will be a new entry for your Yubikey.&lt;br /&gt;
[[File:BwIDM-yubikey2.png|center|400px|thumb|Success]]&lt;br /&gt;
&lt;br /&gt;
4. Repeat the process to register additional tokens.&lt;br /&gt;
Please register at least the &amp;quot;Backup TAN list&amp;quot; in addition to the hardware/software token you plan to use regularly.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Registering a new Yubikey OATH TOTP Token ==&lt;br /&gt;
&lt;br /&gt;
[https://developers.yubico.com/OATH/ Yubikey OATH TOTP] generates the TANs on your Yubikey and therefore you can use different computers and Android phones to generate these codes.&lt;br /&gt;
Please download and install [https://developers.yubico.com/OATH/YubiKey_OATH_software.html Yubico Authenticator] for Desktop (or Android) first.&lt;br /&gt;
Insert your Yubikey in your computer.&lt;br /&gt;
&amp;quot;Yubikey OTP&amp;quot; (not &amp;quot;Yubikey OATH TOTP&amp;quot;) is even easier and you don&#039;t need a device that displays the six-digit code or extra software (go to step [[Registration/2FA#Yubikey_OTP|Yubikey OTP]]).&lt;br /&gt;
&lt;br /&gt;
1. Registering a new Token starts with a click &#039;&#039;&#039;NEW SMARTPHONE TOKEN&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-token.png|center|600px|thumb|Create a new Token]]&lt;br /&gt;
&lt;br /&gt;
2. A new window opens. Click &#039;&#039;&#039;Start&#039;&#039;&#039; to generate a new &#039;&#039;&#039;QR code&#039;&#039;&#039;.&lt;br /&gt;
This may take a while.&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
The QR code contains a key which has to remain secret.&lt;br /&gt;
Only use the QR code to link your software token app with bwIDM/bwServices in the next step.&lt;br /&gt;
Do not save the QR code, print it out or share it with someone else.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
3. Start the Yubico Authenticator on your OS, click the three vertical dots in the upper right corner and select &#039;&#039;&#039;Scan QR code&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-yubi1.png|center|600px|thumb|QR Code and Yubico Authenticator on Linux]]&lt;br /&gt;
&lt;br /&gt;
4. Yubico Authenticator automatically translates the QR code to a new entry called &#039;&#039;&#039;bwIDM&#039;&#039;&#039; or &#039;&#039;&#039;bwServices&#039;&#039;&#039; (MLS&amp;amp;WISO).&lt;br /&gt;
Click &#039;&#039;&#039;Add account&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-yubi2.png|center|600px|thumb|Create new TOTP on Yubico Authenticator]]&lt;br /&gt;
&lt;br /&gt;
5. You will receive a six-digit code.&lt;br /&gt;
Enter this code into the field labeled &amp;quot;Current code:&amp;quot; in your bwIDM browser window to prove that the connection has worked and then click &#039;&#039;&#039;CHECK&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-yubi3.png|center|600px|thumb|Verify TOTP]]&lt;br /&gt;
&lt;br /&gt;
6. If everything worked as expected, you will be returned to the &#039;&#039;&#039;My Tokens&#039;&#039;&#039; screen and there will be a new entry for your software token.&lt;br /&gt;
[[File:BwIDM-app.png|center|400px|thumb|Success]]&lt;br /&gt;
&lt;br /&gt;
7. Repeat the process to register additional tokens.&lt;br /&gt;
Please register at least the &amp;quot;Backup TAN list&amp;quot; in addition to the hardware/software token you plan to use regularly.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Backup TAN List ==&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
Passwords from the &amp;quot;Backup TAN list&amp;quot; should only be used if no other token is left.&lt;br /&gt;
Please do not use the Backup TANs for regular cluster login, because you have only a limited number of TANs.&lt;br /&gt;
Each TAN can only be used once.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
1. Please create at least one &amp;quot;Backup TAN list&amp;quot; by clicking &#039;&#039;&#039;CREATE NEW TAN LIST&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-token.png|center|600px|thumb|Generate Backup TAN list]]&lt;br /&gt;
&lt;br /&gt;
2. Click &#039;&#039;&#039;START&#039;&#039;&#039;. You will be redirected to the &#039;&#039;&#039;My Tokens&#039;&#039;&#039; screen and there will be a new entry for your backup TANs.&lt;br /&gt;
[[File:BwIDM-tan.png|center|400px|thumb|Success]]&lt;br /&gt;
&lt;br /&gt;
3. Click &#039;&#039;&#039;SHOW TANS&#039;&#039;&#039;, print the codes and keep then in a separate place for emergencies.&lt;br /&gt;
[[File:JUSTUS-2-2FA-backup-TAN-list.png|center|800px|thumb|Print Backup TAN List]]&lt;br /&gt;
&lt;br /&gt;
4. Repeat the process to register additional tokens.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Deactivating a Token ==&lt;br /&gt;
&lt;br /&gt;
Click &#039;&#039;&#039;Disable&#039;&#039;&#039; next to the Token entry on the &#039;&#039;&#039;My Tokens&#039;&#039;&#039; screen.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Deleting a Token ==&lt;br /&gt;
&lt;br /&gt;
After a Token has been disabled a new button labeled &#039;&#039;&#039;Delete&#039;&#039;&#039; will appear. Click on it to delete the token.&lt;br /&gt;
&lt;br /&gt;
= Returning Users =&lt;br /&gt;
&lt;br /&gt;
Returning users who have already activated one or more tokens must first verify their token before they can create new tokens or deactivate/delete old ones.&lt;br /&gt;
If you no longer have valid tokens, you will not be able to create or manage tokens. &lt;br /&gt;
In this case, read the section [[Registration/2FA#Lost_Token|Lost Token]].&lt;br /&gt;
[[File:BwIDM-totp.png|center|400px|thumb|Returning users must first verify their token.]]&lt;br /&gt;
&lt;br /&gt;
= Lost Token =&lt;br /&gt;
&lt;br /&gt;
If you have lost a token, please create a new one.&lt;br /&gt;
If you change your phone, please migrate your tokens first or register your new mobile app under &amp;quot;My Tokens&amp;quot;.&lt;br /&gt;
&#039;&#039;&#039;If you no longer have valid tokens (mobile app, hardware token, Yubikey or backup TAN), you will need to contact the [https://bw-support.scc.kit.edu/ ticket system].&#039;&#039;&#039;&lt;br /&gt;
Please note that this process may take some time and also means additional work for the operators.&lt;/div&gt;</summary>
		<author><name>C Mosch</name></author>
	</entry>
	<entry>
		<id>https://wiki.bwhpc.de/wiki/index.php?title=Registration/2FA&amp;diff=10007</id>
		<title>Registration/2FA</title>
		<link rel="alternate" type="text/html" href="https://wiki.bwhpc.de/wiki/index.php?title=Registration/2FA&amp;diff=10007"/>
		<updated>2022-02-15T19:23:46Z</updated>

		<summary type="html">&lt;p&gt;C Mosch: /* Token Management */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Generate a Second Factor (2FA) =&lt;br /&gt;
&lt;br /&gt;
To improve security a &#039;&#039;&#039;2-factor authentication mechanism (2FA)&#039;&#039;&#039; is being enforced for logins to bwUniCluster/bwForClusters. In addition to the service password a second value, the &#039;&#039;&#039;second factor&#039;&#039;&#039;, has to be entered on every login.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== How 2FA works ==&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
It is very important that the device that generates the One-Time Passwords and the device which is used to log into the bwUniCluster/bwForClusters are not the same.&lt;br /&gt;
Otherwise an attacker who gains access to your system can steal both the service password and the secret key of the Software Token application, which allows them to generate One-Time Passwords and log into the HPC system without your knowledge.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
[[File:2fa token code.jpg|right|200px|thumb|Hardware Token for TOTP]]&lt;br /&gt;
On the bwUniCluster/bwForClusters we use six-digit, auto-generated, time-dependent &#039;&#039;&#039;one-time passwords&#039;&#039;&#039; (TOTP). These passwords are generated by a piece of software which is part of a special hardware device (a &#039;&#039;&#039;hardware token&#039;&#039;&#039;) or of a normal application running on a common device (a &#039;&#039;&#039;software token&#039;&#039;&#039;).&lt;br /&gt;
&lt;br /&gt;
The Token has to be synchronized with a central server before it can be used for authentication and then generates an endless stream of six-digit values (TOTPs) which can only be used once and are only valid during a very short interval of time. This makes it much harder for potential attackers to access the HPC system, even if they know the regular service password.&lt;br /&gt;
&lt;br /&gt;
Typically a new TOTP value is generated every 30 seconds. When the current TOTP value has once been used successfully for a login, it is depleted and one has to wait up to 30 seconds for the next TOTP value. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:Otpapp.png|right|150px|thumb|Source: https://getaegis.app]]&lt;br /&gt;
&lt;br /&gt;
The most common solution is to use a mobile device (e.g. your smartphone or tablet) as a Software Token by installing one of the following apps:&lt;br /&gt;
* Google Authenticator for [https://play.google.com/store/apps/details?id=com.google.android.apps.authenticator2 Android] or [https://apps.apple.com/de/app/google-authenticator/id388497605 iOS]&lt;br /&gt;
* Microsoft Authenticator for [https://play.google.com/store/apps/details?id=com.azure.authenticator Android] or [https://apps.apple.com/de/app/microsoft-authenticator/id983156458 iOS] ([https://www.microsoft.com/de-de/security/mobile-authenticator-app Web Page])&lt;br /&gt;
* LastPass Authenticator for [https://play.google.com/store/apps/details?id=com.lastpass.authenticator Android], [https://apps.apple.com/us/app/lastpass-authenticator/id1079110004 iOS] or [https://lastpass.com/auth/ Windows]&lt;br /&gt;
* Aegis Authenticator for [https://play.google.com/store/apps/details?id=com.beemdevelopment.aegis Android (Google Play)] or [https://f-droid.org/en/packages/com.beemdevelopment.aegis/ Android (F-Droid)] ([https://getaegis.app/ Web Page])&lt;br /&gt;
* andOTP Authenticator for [https://play.google.com/store/apps/details?id=org.shadowice.flocke.andotp Android (Google Play)] or [https://f-droid.org/packages/org.shadowice.flocke.andotp/ Android (F-Droid)] ([https://github.com/andOTP/andOTP GitHub])&lt;br /&gt;
* OTP Auth for [https://apps.apple.com/app/otp-auth/id659877384 iOS]&lt;br /&gt;
* (Authy for [https://play.google.com/store/apps/details?id=com.authy.authy Android], [https://apps.apple.com/us/app/authy/id494168017 iOS], [https://authy.com/download/ Mac, Windows or Linux]) requires account&lt;br /&gt;
* (On Linux you can use [https://keepassxc.org/ KeepassXC] or [https://github.com/paolostivanin/OTPClient otpclient])&lt;br /&gt;
&lt;br /&gt;
These are only suggestions. You can use any application compatible with the [https://tools.ietf.org/html/rfc6238 TOTP] standard.&lt;br /&gt;
&lt;br /&gt;
If you don&#039;t want to use a smartphone, we recommend using a hardware token, such as Yubikey or another TOTP-compatible device. [https://www.yubico.com/resources/glossary/yubico-otp/ Yubico OTP] is also supported if you want to use your Yubikey without depending on having a six-digit code displayed. But you can also use the Yubikey as a generator for six-digit [https://www.yubico.com/resources/glossary/oath-totp/ TOTP].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Token Management =&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
* Create at least two separate tokens: &#039;&#039;&#039;FIRST&#039;&#039;&#039; set up a software/hardware TOTP token. &#039;&#039;&#039;THEN&#039;&#039;&#039; create and print a &amp;quot;backup TAN list&amp;quot;. Never create the &amp;quot;backup TAN list&amp;quot; first.&lt;br /&gt;
* If you lose access to all your tokens, you will not be able to create new tokens and support will have to reset your tokens manually.&lt;br /&gt;
* The &amp;quot;backup TAN list&amp;quot; should always be created and printed in a &#039;&#039;&#039;second step&#039;&#039;&#039;. The printout should be kept in a separate place for emergencies.&lt;br /&gt;
* Please clean up your second factors as soon as you have created new tokens. Tokens that can no longer be used (e.g. because not initialized, smartphone/Yubikey lost, etc.) or an old backup TAN list where you have already used all TANs or there is no printout should be deactivated and deleted.&lt;br /&gt;
* Returning users who have already activated one or more tokens must first verify their token before they can create new tokens, see section [[Registration/2FA#Returning_Users|Returning Users]].&lt;br /&gt;
* &#039;&#039;&#039;Please disable all privacy tools, ad blockers and further add-ons when registering new tokens. These tools prevent the registration website from generating new security tokens. When the problems remains (you can not generate the QR code or can not confirm it by clicking CHECK), please try once more with an entirely new unmodified web browser profile.&#039;&#039;&#039;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;bwUniCluster/bwForCluster Tokens&#039;&#039;&#039; are generally managed via the &#039;&#039;&#039;Index -&amp;gt; My Tokens&#039;&#039;&#039; menu entry on the registration pages for the clusters. Here you can register, activate, deactivate and delete tokens.&lt;br /&gt;
&lt;br /&gt;
To activate the second factor, &#039;&#039;&#039;please perform the following steps:&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
1. &#039;&#039;&#039;Select the registration server of the cluster&#039;&#039;&#039; for which you want to create a second factor and login to it:&amp;lt;/br&amp;gt; &amp;amp;rarr; [https://login.bwidm.de/user/twofa.xhtml Registration server for &#039;&#039;&#039;bwUniCluster 2.0&#039;&#039;&#039; and &#039;&#039;&#039;bwForCluster JUSTUS 2&#039;&#039;&#039;] (2FA tokens are valid for both clusters; KIT members can reuse their existing hardware and software tokens)&amp;lt;/br&amp;gt; &amp;amp;rarr; [https://bwservices.uni-heidelberg.de//user/twofa.xhtml Registration server for &#039;&#039;&#039;bwForCluster MLS&amp;amp;WISO&#039;&#039;&#039;]&lt;br /&gt;
[[File:BwIDM-twofa.png|center|600px|thumb|My Tokens]]&lt;br /&gt;
&lt;br /&gt;
2. &#039;&#039;&#039;Register a new &amp;quot;[[Registration/2FA#Registering_a_new_Software_Token_using_a_Mobile_APP|Smartphone Token]]&amp;quot;&#039;&#039;&#039; or if you own a [https://www.yubico.com/ Yubikey]&#039;&#039;&#039; register a new &amp;quot;[[Registration/2FA#Registering_a_new_Yubikey_OTP_Token|Yubikey Token]]&amp;quot;&#039;&#039;&#039; or &#039;&#039;&#039;&amp;quot;[[Registration/2FA#Registering_a_new_Yubikey_OATH_TOTP_Token|Yubikey OATH TOTP Token]]&amp;quot;&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
3. &#039;&#039;&#039;Register a new &amp;quot;[[Registration/2FA#Backup_TAN_List|TAN List]]&amp;quot; (backup TAN list)&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
4. Repeat step 2. for additional tokens.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Registering a new Software Token using a Mobile APP ==&lt;br /&gt;
&lt;br /&gt;
1. Registering a new Token starts with a click &#039;&#039;&#039;NEW SMARTPHONE TOKEN&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-token.png|center|600px|thumb|Create a new Token]]&lt;br /&gt;
&lt;br /&gt;
2. A new window opens. Click &#039;&#039;&#039;Start&#039;&#039;&#039; to generate a new &#039;&#039;&#039;QR code&#039;&#039;&#039;.&lt;br /&gt;
This may take a while.&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
The QR code contains a key which has to remain secret.&lt;br /&gt;
Only use the QR code to link your software token app with bwIDM/bwServices in the next step.&lt;br /&gt;
Do not save the QR code, print it out or share it with someone else.&lt;br /&gt;
|}&lt;br /&gt;
[[File:BwIDM-qr.png|center|600px|thumb|QR Code for Mobile App]]&lt;br /&gt;
&lt;br /&gt;
3. Start the software token app on your separate device and scan the QR code.&lt;br /&gt;
The exact process is a little bit different in every app, but is usually started by pressing on a button with a plus (+) sign or an icon of a QR code.&lt;br /&gt;
&lt;br /&gt;
4. Once the QR code has been loaded into your Software Token app there should be a new entry called &#039;&#039;&#039;bwIDM&#039;&#039;&#039; (bwUniCluster and JUSTUS 2) or &#039;&#039;&#039;bwServices&#039;&#039;&#039; (MLS&amp;amp;WISO).&lt;br /&gt;
Generate an One-Time-Password by pressing on this entry or selecting the appropriate button/menu item.&lt;br /&gt;
You will receive a six-digit code.&lt;br /&gt;
Enter this code into the field labeled &amp;quot;Current code:&amp;quot; in your bwIDM browser window to prove that the connection has worked and then click &#039;&#039;&#039;CHECK&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
5. If everything worked as expected, you will be returned to the &#039;&#039;&#039;My Tokens&#039;&#039;&#039; screen and there will be a new entry for your software token.&lt;br /&gt;
[[File:BwIDM-app.png|center|400px|thumb|Success]]&lt;br /&gt;
&lt;br /&gt;
6. Repeat the process to register additional tokens.&lt;br /&gt;
Please register at least the &amp;quot;Backup TAN list&amp;quot; in addition to the hardware/software token you plan to use regularly.&lt;br /&gt;
&lt;br /&gt;
== Registering a new Yubikey OTP Token ==&lt;br /&gt;
&lt;br /&gt;
[https://developers.yubico.com/OTP/OTPs_Explained.html Yubikey OTP] is even easier and you don&#039;t need a device that displays the six-digit code or extra software.&lt;br /&gt;
New Yubikeys are already configured to provide Yubikey OTP in slot 1.&lt;br /&gt;
If you need to configure your Yubikey, read this [[Registration/2FA/Yubikey|documentation]].&lt;br /&gt;
&lt;br /&gt;
1. If you want to use [https://www.yubico.com/resources/glossary/yubico-otp/ Yubico OTP], you can click &#039;&#039;&#039;NEW YUBIKEY TOKEN&#039;&#039;&#039; instead.&lt;br /&gt;
[[File:BwIDM-token.png|center|600px|thumb|Generate Yubikey OTP]]&lt;br /&gt;
&lt;br /&gt;
2. Yubikey OTP is configured to slot 1 on new Yubikeys, so you only need to click in the text box and then touch the metal part of your Yubikey.&lt;br /&gt;
Please refer to this [[Registration/2FA/Yubikey|documentation]] on how to configure your Yubikey.&lt;br /&gt;
[[File:BwIDM-yubikey.png|center|400px|thumb|Yubikey OTP]]&lt;br /&gt;
&lt;br /&gt;
3. If everything worked as expected, you will be returned to the &#039;&#039;&#039;My Tokens&#039;&#039;&#039; screen and there will be a new entry for your Yubikey.&lt;br /&gt;
[[File:BwIDM-yubikey2.png|center|400px|thumb|Success]]&lt;br /&gt;
&lt;br /&gt;
4. Repeat the process to register additional tokens.&lt;br /&gt;
Please register at least the &amp;quot;Backup TAN list&amp;quot; in addition to the hardware/software token you plan to use regularly.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Registering a new Yubikey OATH TOTP Token ==&lt;br /&gt;
&lt;br /&gt;
[https://developers.yubico.com/OATH/ Yubikey OATH TOTP] generates the TANs on your Yubikey and therefore you can use different computers and Android phones to generate these codes.&lt;br /&gt;
Please download and install [https://developers.yubico.com/OATH/YubiKey_OATH_software.html Yubico Authenticator] for Desktop (or Android) first.&lt;br /&gt;
Insert your Yubikey in your computer.&lt;br /&gt;
&amp;quot;Yubikey OTP&amp;quot; (not &amp;quot;Yubikey OATH TOTP&amp;quot;) is even easier and you don&#039;t need a device that displays the six-digit code or extra software (go to step [[Registration/2FA#Yubikey_OTP|Yubikey OTP]]).&lt;br /&gt;
&lt;br /&gt;
1. Registering a new Token starts with a click &#039;&#039;&#039;NEW SMARTPHONE TOKEN&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-token.png|center|600px|thumb|Create a new Token]]&lt;br /&gt;
&lt;br /&gt;
2. A new window opens. Click &#039;&#039;&#039;Start&#039;&#039;&#039; to generate a new &#039;&#039;&#039;QR code&#039;&#039;&#039;.&lt;br /&gt;
This may take a while.&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
The QR code contains a key which has to remain secret.&lt;br /&gt;
Only use the QR code to link your software token app with bwIDM/bwServices in the next step.&lt;br /&gt;
Do not save the QR code, print it out or share it with someone else.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
3. Start the Yubico Authenticator on your OS, click the three vertical dots in the upper right corner and select &#039;&#039;&#039;Scan QR code&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-yubi1.png|center|600px|thumb|QR Code and Yubico Authenticator on Linux]]&lt;br /&gt;
&lt;br /&gt;
4. Yubico Authenticator automatically translates the QR code to a new entry called &#039;&#039;&#039;bwIDM&#039;&#039;&#039; or &#039;&#039;&#039;bwServices&#039;&#039;&#039; (MLS&amp;amp;WISO).&lt;br /&gt;
Click &#039;&#039;&#039;Add account&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-yubi2.png|center|600px|thumb|Create new TOTP on Yubico Authenticator]]&lt;br /&gt;
&lt;br /&gt;
5. You will receive a six-digit code.&lt;br /&gt;
Enter this code into the field labeled &amp;quot;Current code:&amp;quot; in your bwIDM browser window to prove that the connection has worked and then click &#039;&#039;&#039;CHECK&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-yubi3.png|center|600px|thumb|Verify TOTP]]&lt;br /&gt;
&lt;br /&gt;
6. If everything worked as expected, you will be returned to the &#039;&#039;&#039;My Tokens&#039;&#039;&#039; screen and there will be a new entry for your software token.&lt;br /&gt;
[[File:BwIDM-app.png|center|400px|thumb|Success]]&lt;br /&gt;
&lt;br /&gt;
7. Repeat the process to register additional tokens.&lt;br /&gt;
Please register at least the &amp;quot;Backup TAN list&amp;quot; in addition to the hardware/software token you plan to use regularly.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Backup TAN List ==&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
Passwords from the &amp;quot;Backup TAN list&amp;quot; should only be used if no other token is left.&lt;br /&gt;
Please do not use the Backup TANs for regular cluster login, because you have only a limited number of TANs.&lt;br /&gt;
Each TAN can only be used once.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
1. Please create at least one &amp;quot;Backup TAN list&amp;quot; by clicking &#039;&#039;&#039;CREATE NEW TAN LIST&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-token.png|center|600px|thumb|Generate Backup TAN list]]&lt;br /&gt;
&lt;br /&gt;
2. Click &#039;&#039;&#039;START&#039;&#039;&#039;. You will be redirected to the &#039;&#039;&#039;My Tokens&#039;&#039;&#039; screen and there will be a new entry for your backup TANs.&lt;br /&gt;
[[File:BwIDM-tan.png|center|400px|thumb|Success]]&lt;br /&gt;
&lt;br /&gt;
3. Click &#039;&#039;&#039;SHOW TANS&#039;&#039;&#039;, print the codes and keep then in a separate place for emergencies.&lt;br /&gt;
[[File:JUSTUS-2-2FA-backup-TAN-list.png|center|800px|thumb|Print Backup TAN List]]&lt;br /&gt;
&lt;br /&gt;
4. Repeat the process to register additional tokens.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Deactivating a Token ==&lt;br /&gt;
&lt;br /&gt;
Click &#039;&#039;&#039;Disable&#039;&#039;&#039; next to the Token entry on the &#039;&#039;&#039;My Tokens&#039;&#039;&#039; screen.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Deleting a Token ==&lt;br /&gt;
&lt;br /&gt;
After a Token has been disabled a new button labeled &#039;&#039;&#039;Delete&#039;&#039;&#039; will appear. Click on it to delete the token.&lt;br /&gt;
&lt;br /&gt;
= Returning Users =&lt;br /&gt;
&lt;br /&gt;
Returning users who have already activated one or more tokens must first verify their token before they can create new tokens or deactivate/delete old ones.&lt;br /&gt;
If you no longer have valid tokens, you will not be able to create or manage tokens. &lt;br /&gt;
In this case, read the section [[Registration/2FA#Lost_Token|Lost Token]].&lt;br /&gt;
[[File:BwIDM-totp.png|center|400px|thumb|Returning users must first verify their token.]]&lt;br /&gt;
&lt;br /&gt;
= Lost Token =&lt;br /&gt;
&lt;br /&gt;
If you have lost a token, please create a new one.&lt;br /&gt;
If you change your phone, please migrate your tokens first or register your new mobile app under &amp;quot;My Tokens&amp;quot;.&lt;br /&gt;
&#039;&#039;&#039;If you no longer have valid tokens (mobile app, hardware token, Yubikey or backup TAN), you will need to contact the [https://bw-support.scc.kit.edu/ ticket system].&#039;&#039;&#039;&lt;br /&gt;
Please note that this process may take some time and also means additional work for the operators.&lt;/div&gt;</summary>
		<author><name>C Mosch</name></author>
	</entry>
	<entry>
		<id>https://wiki.bwhpc.de/wiki/index.php?title=Registration/2FA&amp;diff=10006</id>
		<title>Registration/2FA</title>
		<link rel="alternate" type="text/html" href="https://wiki.bwhpc.de/wiki/index.php?title=Registration/2FA&amp;diff=10006"/>
		<updated>2022-02-15T19:18:04Z</updated>

		<summary type="html">&lt;p&gt;C Mosch: /* Token Management */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Generate a Second Factor (2FA) =&lt;br /&gt;
&lt;br /&gt;
To improve security a &#039;&#039;&#039;2-factor authentication mechanism (2FA)&#039;&#039;&#039; is being enforced for logins to bwUniCluster/bwForClusters. In addition to the service password a second value, the &#039;&#039;&#039;second factor&#039;&#039;&#039;, has to be entered on every login.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== How 2FA works ==&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
It is very important that the device that generates the One-Time Passwords and the device which is used to log into the bwUniCluster/bwForClusters are not the same.&lt;br /&gt;
Otherwise an attacker who gains access to your system can steal both the service password and the secret key of the Software Token application, which allows them to generate One-Time Passwords and log into the HPC system without your knowledge.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
[[File:2fa token code.jpg|right|200px|thumb|Hardware Token for TOTP]]&lt;br /&gt;
On the bwUniCluster/bwForClusters we use six-digit, auto-generated, time-dependent &#039;&#039;&#039;one-time passwords&#039;&#039;&#039; (TOTP). These passwords are generated by a piece of software which is part of a special hardware device (a &#039;&#039;&#039;hardware token&#039;&#039;&#039;) or of a normal application running on a common device (a &#039;&#039;&#039;software token&#039;&#039;&#039;).&lt;br /&gt;
&lt;br /&gt;
The Token has to be synchronized with a central server before it can be used for authentication and then generates an endless stream of six-digit values (TOTPs) which can only be used once and are only valid during a very short interval of time. This makes it much harder for potential attackers to access the HPC system, even if they know the regular service password.&lt;br /&gt;
&lt;br /&gt;
Typically a new TOTP value is generated every 30 seconds. When the current TOTP value has once been used successfully for a login, it is depleted and one has to wait up to 30 seconds for the next TOTP value. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:Otpapp.png|right|150px|thumb|Source: https://getaegis.app]]&lt;br /&gt;
&lt;br /&gt;
The most common solution is to use a mobile device (e.g. your smartphone or tablet) as a Software Token by installing one of the following apps:&lt;br /&gt;
* Google Authenticator for [https://play.google.com/store/apps/details?id=com.google.android.apps.authenticator2 Android] or [https://apps.apple.com/de/app/google-authenticator/id388497605 iOS]&lt;br /&gt;
* Microsoft Authenticator for [https://play.google.com/store/apps/details?id=com.azure.authenticator Android] or [https://apps.apple.com/de/app/microsoft-authenticator/id983156458 iOS] ([https://www.microsoft.com/de-de/security/mobile-authenticator-app Web Page])&lt;br /&gt;
* LastPass Authenticator for [https://play.google.com/store/apps/details?id=com.lastpass.authenticator Android], [https://apps.apple.com/us/app/lastpass-authenticator/id1079110004 iOS] or [https://lastpass.com/auth/ Windows]&lt;br /&gt;
* Aegis Authenticator for [https://play.google.com/store/apps/details?id=com.beemdevelopment.aegis Android (Google Play)] or [https://f-droid.org/en/packages/com.beemdevelopment.aegis/ Android (F-Droid)] ([https://getaegis.app/ Web Page])&lt;br /&gt;
* andOTP Authenticator for [https://play.google.com/store/apps/details?id=org.shadowice.flocke.andotp Android (Google Play)] or [https://f-droid.org/packages/org.shadowice.flocke.andotp/ Android (F-Droid)] ([https://github.com/andOTP/andOTP GitHub])&lt;br /&gt;
* OTP Auth for [https://apps.apple.com/app/otp-auth/id659877384 iOS]&lt;br /&gt;
* (Authy for [https://play.google.com/store/apps/details?id=com.authy.authy Android], [https://apps.apple.com/us/app/authy/id494168017 iOS], [https://authy.com/download/ Mac, Windows or Linux]) requires account&lt;br /&gt;
* (On Linux you can use [https://keepassxc.org/ KeepassXC] or [https://github.com/paolostivanin/OTPClient otpclient])&lt;br /&gt;
&lt;br /&gt;
These are only suggestions. You can use any application compatible with the [https://tools.ietf.org/html/rfc6238 TOTP] standard.&lt;br /&gt;
&lt;br /&gt;
If you don&#039;t want to use a smartphone, we recommend using a hardware token, such as Yubikey or another TOTP-compatible device. [https://www.yubico.com/resources/glossary/yubico-otp/ Yubico OTP] is also supported if you want to use your Yubikey without depending on having a six-digit code displayed. But you can also use the Yubikey as a generator for six-digit [https://www.yubico.com/resources/glossary/oath-totp/ TOTP].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Token Management =&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
* Create at least two separate tokens: &#039;&#039;&#039;FIRST&#039;&#039;&#039; set up a software/hardware TOTP token. &#039;&#039;&#039;THEN&#039;&#039;&#039; create and print a &amp;quot;backup TAN list&amp;quot;. Never create the &amp;quot;backup TAN list&amp;quot; first.&lt;br /&gt;
* If you lose access to all your tokens, you will not be able to create new tokens and support will have to reset your tokens manually.&lt;br /&gt;
* The &amp;quot;backup TAN list&amp;quot; should always be created and printed in a &#039;&#039;&#039;second step&#039;&#039;&#039;. The printout should be kept in a separate place for emergencies.&lt;br /&gt;
* Please clean up your second factors as soon as you have created new tokens. Tokens that can no longer be used (e.g. because not initialized, smartphone/Yubikey lost, etc.) or an old backup TAN list where you have already used all TANs or there is no printout should be deactivated and deleted.&lt;br /&gt;
* Returning users who have already activated one or more tokens must first verify their token before they can create new tokens, see section [[Registration/2FA#Returning_Users|Returning Users]].&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;bwUniCluster/bwForCluster Tokens&#039;&#039;&#039; are generally managed via the &#039;&#039;&#039;Index -&amp;gt; My Tokens&#039;&#039;&#039; menu entry on the registration pages for the clusters. Here you can register, activate, deactivate and delete tokens.&lt;br /&gt;
&lt;br /&gt;
To activate the second factor, &#039;&#039;&#039;please perform the following steps:&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
1. &#039;&#039;&#039;Select the registration server of the cluster&#039;&#039;&#039; for which you want to create a second factor and login to it:&amp;lt;/br&amp;gt; &amp;amp;rarr; [https://login.bwidm.de/user/twofa.xhtml Registration server for &#039;&#039;&#039;bwUniCluster 2.0&#039;&#039;&#039; and &#039;&#039;&#039;bwForCluster JUSTUS 2&#039;&#039;&#039;] (2FA tokens are valid for both clusters; KIT members can reuse their existing hardware and software tokens)&amp;lt;/br&amp;gt; &amp;amp;rarr; [https://bwservices.uni-heidelberg.de//user/twofa.xhtml Registration server for &#039;&#039;&#039;bwForCluster MLS&amp;amp;WISO&#039;&#039;&#039;]&lt;br /&gt;
[[File:BwIDM-twofa.png|center|600px|thumb|My Tokens]]&lt;br /&gt;
&lt;br /&gt;
2. &#039;&#039;&#039;Register a new &amp;quot;[[Registration/2FA#Registering_a_new_Software_Token_using_a_Mobile_APP|Smartphone Token]]&amp;quot;&#039;&#039;&#039; or if you own a [https://www.yubico.com/ Yubikey]&#039;&#039;&#039; register a new &amp;quot;[[Registration/2FA#Registering_a_new_Yubikey_OTP_Token|Yubikey Token]]&amp;quot;&#039;&#039;&#039; or &#039;&#039;&#039;&amp;quot;[[Registration/2FA#Registering_a_new_Yubikey_OATH_TOTP_Token|Yubikey OATH TOTP Token]]&amp;quot;&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
3. &#039;&#039;&#039;Register a new &amp;quot;[[Registration/2FA#Backup_TAN_List|TAN List]]&amp;quot; (backup TAN list)&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
4. Repeat step 2. for additional tokens.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Registering a new Software Token using a Mobile APP ==&lt;br /&gt;
&lt;br /&gt;
1. Registering a new Token starts with a click &#039;&#039;&#039;NEW SMARTPHONE TOKEN&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-token.png|center|600px|thumb|Create a new Token]]&lt;br /&gt;
&lt;br /&gt;
2. A new window opens. Click &#039;&#039;&#039;Start&#039;&#039;&#039; to generate a new &#039;&#039;&#039;QR code&#039;&#039;&#039;.&lt;br /&gt;
This may take a while.&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
The QR code contains a key which has to remain secret.&lt;br /&gt;
Only use the QR code to link your software token app with bwIDM/bwServices in the next step.&lt;br /&gt;
Do not save the QR code, print it out or share it with someone else.&lt;br /&gt;
|}&lt;br /&gt;
[[File:BwIDM-qr.png|center|600px|thumb|QR Code for Mobile App]]&lt;br /&gt;
&lt;br /&gt;
3. Start the software token app on your separate device and scan the QR code.&lt;br /&gt;
The exact process is a little bit different in every app, but is usually started by pressing on a button with a plus (+) sign or an icon of a QR code.&lt;br /&gt;
&lt;br /&gt;
4. Once the QR code has been loaded into your Software Token app there should be a new entry called &#039;&#039;&#039;bwIDM&#039;&#039;&#039; (bwUniCluster and JUSTUS 2) or &#039;&#039;&#039;bwServices&#039;&#039;&#039; (MLS&amp;amp;WISO).&lt;br /&gt;
Generate an One-Time-Password by pressing on this entry or selecting the appropriate button/menu item.&lt;br /&gt;
You will receive a six-digit code.&lt;br /&gt;
Enter this code into the field labeled &amp;quot;Current code:&amp;quot; in your bwIDM browser window to prove that the connection has worked and then click &#039;&#039;&#039;CHECK&#039;&#039;&#039;.&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
In case of problems when generating the QR code or when confirming it by clicking CHECK: Please disable all privacy tools, ad blockers and further add-ons when registering new tokens. These tools prevent the registration website from generating new security tokens. When the problems remains, please try again with an entirely new unmodified web browser profile.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
5. If everything worked as expected, you will be returned to the &#039;&#039;&#039;My Tokens&#039;&#039;&#039; screen and there will be a new entry for your software token.&lt;br /&gt;
[[File:BwIDM-app.png|center|400px|thumb|Success]]&lt;br /&gt;
&lt;br /&gt;
6. Repeat the process to register additional tokens.&lt;br /&gt;
Please register at least the &amp;quot;Backup TAN list&amp;quot; in addition to the hardware/software token you plan to use regularly.&lt;br /&gt;
&lt;br /&gt;
== Registering a new Yubikey OTP Token ==&lt;br /&gt;
&lt;br /&gt;
[https://developers.yubico.com/OTP/OTPs_Explained.html Yubikey OTP] is even easier and you don&#039;t need a device that displays the six-digit code or extra software.&lt;br /&gt;
New Yubikeys are already configured to provide Yubikey OTP in slot 1.&lt;br /&gt;
If you need to configure your Yubikey, read this [[Registration/2FA/Yubikey|documentation]].&lt;br /&gt;
&lt;br /&gt;
1. If you want to use [https://www.yubico.com/resources/glossary/yubico-otp/ Yubico OTP], you can click &#039;&#039;&#039;NEW YUBIKEY TOKEN&#039;&#039;&#039; instead.&lt;br /&gt;
[[File:BwIDM-token.png|center|600px|thumb|Generate Yubikey OTP]]&lt;br /&gt;
&lt;br /&gt;
2. Yubikey OTP is configured to slot 1 on new Yubikeys, so you only need to click in the text box and then touch the metal part of your Yubikey.&lt;br /&gt;
Please refer to this [[Registration/2FA/Yubikey|documentation]] on how to configure your Yubikey.&lt;br /&gt;
[[File:BwIDM-yubikey.png|center|400px|thumb|Yubikey OTP]]&lt;br /&gt;
&lt;br /&gt;
3. If everything worked as expected, you will be returned to the &#039;&#039;&#039;My Tokens&#039;&#039;&#039; screen and there will be a new entry for your Yubikey.&lt;br /&gt;
[[File:BwIDM-yubikey2.png|center|400px|thumb|Success]]&lt;br /&gt;
&lt;br /&gt;
4. Repeat the process to register additional tokens.&lt;br /&gt;
Please register at least the &amp;quot;Backup TAN list&amp;quot; in addition to the hardware/software token you plan to use regularly.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Registering a new Yubikey OATH TOTP Token ==&lt;br /&gt;
&lt;br /&gt;
[https://developers.yubico.com/OATH/ Yubikey OATH TOTP] generates the TANs on your Yubikey and therefore you can use different computers and Android phones to generate these codes.&lt;br /&gt;
Please download and install [https://developers.yubico.com/OATH/YubiKey_OATH_software.html Yubico Authenticator] for Desktop (or Android) first.&lt;br /&gt;
Insert your Yubikey in your computer.&lt;br /&gt;
&amp;quot;Yubikey OTP&amp;quot; (not &amp;quot;Yubikey OATH TOTP&amp;quot;) is even easier and you don&#039;t need a device that displays the six-digit code or extra software (go to step [[Registration/2FA#Yubikey_OTP|Yubikey OTP]]).&lt;br /&gt;
&lt;br /&gt;
1. Registering a new Token starts with a click &#039;&#039;&#039;NEW SMARTPHONE TOKEN&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-token.png|center|600px|thumb|Create a new Token]]&lt;br /&gt;
&lt;br /&gt;
2. A new window opens. Click &#039;&#039;&#039;Start&#039;&#039;&#039; to generate a new &#039;&#039;&#039;QR code&#039;&#039;&#039;.&lt;br /&gt;
This may take a while.&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
The QR code contains a key which has to remain secret.&lt;br /&gt;
Only use the QR code to link your software token app with bwIDM/bwServices in the next step.&lt;br /&gt;
Do not save the QR code, print it out or share it with someone else.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
3. Start the Yubico Authenticator on your OS, click the three vertical dots in the upper right corner and select &#039;&#039;&#039;Scan QR code&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-yubi1.png|center|600px|thumb|QR Code and Yubico Authenticator on Linux]]&lt;br /&gt;
&lt;br /&gt;
4. Yubico Authenticator automatically translates the QR code to a new entry called &#039;&#039;&#039;bwIDM&#039;&#039;&#039; or &#039;&#039;&#039;bwServices&#039;&#039;&#039; (MLS&amp;amp;WISO).&lt;br /&gt;
Click &#039;&#039;&#039;Add account&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-yubi2.png|center|600px|thumb|Create new TOTP on Yubico Authenticator]]&lt;br /&gt;
&lt;br /&gt;
5. You will receive a six-digit code.&lt;br /&gt;
Enter this code into the field labeled &amp;quot;Current code:&amp;quot; in your bwIDM browser window to prove that the connection has worked and then click &#039;&#039;&#039;CHECK&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-yubi3.png|center|600px|thumb|Verify TOTP]]&lt;br /&gt;
&lt;br /&gt;
6. If everything worked as expected, you will be returned to the &#039;&#039;&#039;My Tokens&#039;&#039;&#039; screen and there will be a new entry for your software token.&lt;br /&gt;
[[File:BwIDM-app.png|center|400px|thumb|Success]]&lt;br /&gt;
&lt;br /&gt;
7. Repeat the process to register additional tokens.&lt;br /&gt;
Please register at least the &amp;quot;Backup TAN list&amp;quot; in addition to the hardware/software token you plan to use regularly.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Backup TAN List ==&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
Passwords from the &amp;quot;Backup TAN list&amp;quot; should only be used if no other token is left.&lt;br /&gt;
Please do not use the Backup TANs for regular cluster login, because you have only a limited number of TANs.&lt;br /&gt;
Each TAN can only be used once.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
1. Please create at least one &amp;quot;Backup TAN list&amp;quot; by clicking &#039;&#039;&#039;CREATE NEW TAN LIST&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-token.png|center|600px|thumb|Generate Backup TAN list]]&lt;br /&gt;
&lt;br /&gt;
2. Click &#039;&#039;&#039;START&#039;&#039;&#039;. You will be redirected to the &#039;&#039;&#039;My Tokens&#039;&#039;&#039; screen and there will be a new entry for your backup TANs.&lt;br /&gt;
[[File:BwIDM-tan.png|center|400px|thumb|Success]]&lt;br /&gt;
&lt;br /&gt;
3. Click &#039;&#039;&#039;SHOW TANS&#039;&#039;&#039;, print the codes and keep then in a separate place for emergencies.&lt;br /&gt;
[[File:JUSTUS-2-2FA-backup-TAN-list.png|center|800px|thumb|Print Backup TAN List]]&lt;br /&gt;
&lt;br /&gt;
4. Repeat the process to register additional tokens.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Deactivating a Token ==&lt;br /&gt;
&lt;br /&gt;
Click &#039;&#039;&#039;Disable&#039;&#039;&#039; next to the Token entry on the &#039;&#039;&#039;My Tokens&#039;&#039;&#039; screen.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Deleting a Token ==&lt;br /&gt;
&lt;br /&gt;
After a Token has been disabled a new button labeled &#039;&#039;&#039;Delete&#039;&#039;&#039; will appear. Click on it to delete the token.&lt;br /&gt;
&lt;br /&gt;
= Returning Users =&lt;br /&gt;
&lt;br /&gt;
Returning users who have already activated one or more tokens must first verify their token before they can create new tokens or deactivate/delete old ones.&lt;br /&gt;
If you no longer have valid tokens, you will not be able to create or manage tokens. &lt;br /&gt;
In this case, read the section [[Registration/2FA#Lost_Token|Lost Token]].&lt;br /&gt;
[[File:BwIDM-totp.png|center|400px|thumb|Returning users must first verify their token.]]&lt;br /&gt;
&lt;br /&gt;
= Lost Token =&lt;br /&gt;
&lt;br /&gt;
If you have lost a token, please create a new one.&lt;br /&gt;
If you change your phone, please migrate your tokens first or register your new mobile app under &amp;quot;My Tokens&amp;quot;.&lt;br /&gt;
&#039;&#039;&#039;If you no longer have valid tokens (mobile app, hardware token, Yubikey or backup TAN), you will need to contact the [https://bw-support.scc.kit.edu/ ticket system].&#039;&#039;&#039;&lt;br /&gt;
Please note that this process may take some time and also means additional work for the operators.&lt;/div&gt;</summary>
		<author><name>C Mosch</name></author>
	</entry>
	<entry>
		<id>https://wiki.bwhpc.de/wiki/index.php?title=Registration/2FA&amp;diff=10005</id>
		<title>Registration/2FA</title>
		<link rel="alternate" type="text/html" href="https://wiki.bwhpc.de/wiki/index.php?title=Registration/2FA&amp;diff=10005"/>
		<updated>2022-02-15T19:12:35Z</updated>

		<summary type="html">&lt;p&gt;C Mosch: /* Registering a new Software Token using a Mobile APP */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Generate a Second Factor (2FA) =&lt;br /&gt;
&lt;br /&gt;
To improve security a &#039;&#039;&#039;2-factor authentication mechanism (2FA)&#039;&#039;&#039; is being enforced for logins to bwUniCluster/bwForClusters. In addition to the service password a second value, the &#039;&#039;&#039;second factor&#039;&#039;&#039;, has to be entered on every login.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== How 2FA works ==&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
It is very important that the device that generates the One-Time Passwords and the device which is used to log into the bwUniCluster/bwForClusters are not the same.&lt;br /&gt;
Otherwise an attacker who gains access to your system can steal both the service password and the secret key of the Software Token application, which allows them to generate One-Time Passwords and log into the HPC system without your knowledge.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
[[File:2fa token code.jpg|right|200px|thumb|Hardware Token for TOTP]]&lt;br /&gt;
On the bwUniCluster/bwForClusters we use six-digit, auto-generated, time-dependent &#039;&#039;&#039;one-time passwords&#039;&#039;&#039; (TOTP). These passwords are generated by a piece of software which is part of a special hardware device (a &#039;&#039;&#039;hardware token&#039;&#039;&#039;) or of a normal application running on a common device (a &#039;&#039;&#039;software token&#039;&#039;&#039;).&lt;br /&gt;
&lt;br /&gt;
The Token has to be synchronized with a central server before it can be used for authentication and then generates an endless stream of six-digit values (TOTPs) which can only be used once and are only valid during a very short interval of time. This makes it much harder for potential attackers to access the HPC system, even if they know the regular service password.&lt;br /&gt;
&lt;br /&gt;
Typically a new TOTP value is generated every 30 seconds. When the current TOTP value has once been used successfully for a login, it is depleted and one has to wait up to 30 seconds for the next TOTP value. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:Otpapp.png|right|150px|thumb|Source: https://getaegis.app]]&lt;br /&gt;
&lt;br /&gt;
The most common solution is to use a mobile device (e.g. your smartphone or tablet) as a Software Token by installing one of the following apps:&lt;br /&gt;
* Google Authenticator for [https://play.google.com/store/apps/details?id=com.google.android.apps.authenticator2 Android] or [https://apps.apple.com/de/app/google-authenticator/id388497605 iOS]&lt;br /&gt;
* Microsoft Authenticator for [https://play.google.com/store/apps/details?id=com.azure.authenticator Android] or [https://apps.apple.com/de/app/microsoft-authenticator/id983156458 iOS] ([https://www.microsoft.com/de-de/security/mobile-authenticator-app Web Page])&lt;br /&gt;
* LastPass Authenticator for [https://play.google.com/store/apps/details?id=com.lastpass.authenticator Android], [https://apps.apple.com/us/app/lastpass-authenticator/id1079110004 iOS] or [https://lastpass.com/auth/ Windows]&lt;br /&gt;
* Aegis Authenticator for [https://play.google.com/store/apps/details?id=com.beemdevelopment.aegis Android (Google Play)] or [https://f-droid.org/en/packages/com.beemdevelopment.aegis/ Android (F-Droid)] ([https://getaegis.app/ Web Page])&lt;br /&gt;
* andOTP Authenticator for [https://play.google.com/store/apps/details?id=org.shadowice.flocke.andotp Android (Google Play)] or [https://f-droid.org/packages/org.shadowice.flocke.andotp/ Android (F-Droid)] ([https://github.com/andOTP/andOTP GitHub])&lt;br /&gt;
* OTP Auth for [https://apps.apple.com/app/otp-auth/id659877384 iOS]&lt;br /&gt;
* (Authy for [https://play.google.com/store/apps/details?id=com.authy.authy Android], [https://apps.apple.com/us/app/authy/id494168017 iOS], [https://authy.com/download/ Mac, Windows or Linux]) requires account&lt;br /&gt;
* (On Linux you can use [https://keepassxc.org/ KeepassXC] or [https://github.com/paolostivanin/OTPClient otpclient])&lt;br /&gt;
&lt;br /&gt;
These are only suggestions. You can use any application compatible with the [https://tools.ietf.org/html/rfc6238 TOTP] standard.&lt;br /&gt;
&lt;br /&gt;
If you don&#039;t want to use a smartphone, we recommend using a hardware token, such as Yubikey or another TOTP-compatible device. [https://www.yubico.com/resources/glossary/yubico-otp/ Yubico OTP] is also supported if you want to use your Yubikey without depending on having a six-digit code displayed. But you can also use the Yubikey as a generator for six-digit [https://www.yubico.com/resources/glossary/oath-totp/ TOTP].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Token Management =&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
* Create at least two separate tokens: &#039;&#039;&#039;FIRST&#039;&#039;&#039; set up a software/hardware TOTP token. &#039;&#039;&#039;THEN&#039;&#039;&#039; create and print a &amp;quot;backup TAN list&amp;quot;. Never create the &amp;quot;backup TAN list&amp;quot; first.&lt;br /&gt;
* If you lose access to all your tokens, you will not be able to create new tokens and support will have to reset your tokens manually.&lt;br /&gt;
* The &amp;quot;backup TAN list&amp;quot; should always be created and printed in a &#039;&#039;&#039;second step&#039;&#039;&#039;. The printout should be kept in a separate place for emergencies.&lt;br /&gt;
* Please disable all privacy tools, ad blockers and further add-ons when registering new tokens. These tools prevent the registration website from generating new security tokens. When there are still problems to enter the TOTP activation code &amp;quot;Current code&amp;quot; please try again with a new clean web browser profile.&lt;br /&gt;
* Please clean up your second factors as soon as you have created new tokens. Tokens that can no longer be used (e.g. because not initialized, smartphone/Yubikey lost, etc.) or an old backup TAN list where you have already used all TANs or there is no printout should be deactivated and deleted.&lt;br /&gt;
* Returning users who have already activated one or more tokens must first verify their token before they can create new tokens, see section [[Registration/2FA#Returning_Users|Returning Users]].&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;bwUniCluster/bwForCluster Tokens&#039;&#039;&#039; are generally managed via the &#039;&#039;&#039;Index -&amp;gt; My Tokens&#039;&#039;&#039; menu entry on the registration pages for the clusters. Here you can register, activate, deactivate and delete tokens.&lt;br /&gt;
&lt;br /&gt;
To activate the second factor, &#039;&#039;&#039;please perform the following steps:&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
1. &#039;&#039;&#039;Select the registration server of the cluster&#039;&#039;&#039; for which you want to create a second factor and login to it:&amp;lt;/br&amp;gt; &amp;amp;rarr; [https://login.bwidm.de/user/twofa.xhtml Registration server for &#039;&#039;&#039;bwUniCluster 2.0&#039;&#039;&#039; and &#039;&#039;&#039;bwForCluster JUSTUS 2&#039;&#039;&#039;] (2FA tokens are valid for both clusters; KIT members can reuse their existing hardware and software tokens)&amp;lt;/br&amp;gt; &amp;amp;rarr; [https://bwservices.uni-heidelberg.de//user/twofa.xhtml Registration server for &#039;&#039;&#039;bwForCluster MLS&amp;amp;WISO&#039;&#039;&#039;]&lt;br /&gt;
[[File:BwIDM-twofa.png|center|600px|thumb|My Tokens]]&lt;br /&gt;
&lt;br /&gt;
2. &#039;&#039;&#039;Register a new &amp;quot;[[Registration/2FA#Registering_a_new_Software_Token_using_a_Mobile_APP|Smartphone Token]]&amp;quot;&#039;&#039;&#039; or if you own a [https://www.yubico.com/ Yubikey]&#039;&#039;&#039; register a new &amp;quot;[[Registration/2FA#Registering_a_new_Yubikey_OTP_Token|Yubikey Token]]&amp;quot;&#039;&#039;&#039; or &#039;&#039;&#039;&amp;quot;[[Registration/2FA#Registering_a_new_Yubikey_OATH_TOTP_Token|Yubikey OATH TOTP Token]]&amp;quot;&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
3. &#039;&#039;&#039;Register a new &amp;quot;[[Registration/2FA#Backup_TAN_List|TAN List]]&amp;quot; (backup TAN list)&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
4. Repeat step 2. for additional tokens.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Registering a new Software Token using a Mobile APP ==&lt;br /&gt;
&lt;br /&gt;
1. Registering a new Token starts with a click &#039;&#039;&#039;NEW SMARTPHONE TOKEN&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-token.png|center|600px|thumb|Create a new Token]]&lt;br /&gt;
&lt;br /&gt;
2. A new window opens. Click &#039;&#039;&#039;Start&#039;&#039;&#039; to generate a new &#039;&#039;&#039;QR code&#039;&#039;&#039;.&lt;br /&gt;
This may take a while.&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
The QR code contains a key which has to remain secret.&lt;br /&gt;
Only use the QR code to link your software token app with bwIDM/bwServices in the next step.&lt;br /&gt;
Do not save the QR code, print it out or share it with someone else.&lt;br /&gt;
|}&lt;br /&gt;
[[File:BwIDM-qr.png|center|600px|thumb|QR Code for Mobile App]]&lt;br /&gt;
&lt;br /&gt;
3. Start the software token app on your separate device and scan the QR code.&lt;br /&gt;
The exact process is a little bit different in every app, but is usually started by pressing on a button with a plus (+) sign or an icon of a QR code.&lt;br /&gt;
&lt;br /&gt;
4. Once the QR code has been loaded into your Software Token app there should be a new entry called &#039;&#039;&#039;bwIDM&#039;&#039;&#039; (bwUniCluster and JUSTUS 2) or &#039;&#039;&#039;bwServices&#039;&#039;&#039; (MLS&amp;amp;WISO).&lt;br /&gt;
Generate an One-Time-Password by pressing on this entry or selecting the appropriate button/menu item.&lt;br /&gt;
You will receive a six-digit code.&lt;br /&gt;
Enter this code into the field labeled &amp;quot;Current code:&amp;quot; in your bwIDM browser window to prove that the connection has worked and then click &#039;&#039;&#039;CHECK&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
5. If everything worked as expected, you will be returned to the &#039;&#039;&#039;My Tokens&#039;&#039;&#039; screen and there will be a new entry for your software token.&lt;br /&gt;
[[File:BwIDM-app.png|center|400px|thumb|Success]]&lt;br /&gt;
&lt;br /&gt;
6. Repeat the process to register additional tokens.&lt;br /&gt;
Please register at least the &amp;quot;Backup TAN list&amp;quot; in addition to the hardware/software token you plan to use regularly.&lt;br /&gt;
&lt;br /&gt;
== Registering a new Yubikey OTP Token ==&lt;br /&gt;
&lt;br /&gt;
[https://developers.yubico.com/OTP/OTPs_Explained.html Yubikey OTP] is even easier and you don&#039;t need a device that displays the six-digit code or extra software.&lt;br /&gt;
New Yubikeys are already configured to provide Yubikey OTP in slot 1.&lt;br /&gt;
If you need to configure your Yubikey, read this [[Registration/2FA/Yubikey|documentation]].&lt;br /&gt;
&lt;br /&gt;
1. If you want to use [https://www.yubico.com/resources/glossary/yubico-otp/ Yubico OTP], you can click &#039;&#039;&#039;NEW YUBIKEY TOKEN&#039;&#039;&#039; instead.&lt;br /&gt;
[[File:BwIDM-token.png|center|600px|thumb|Generate Yubikey OTP]]&lt;br /&gt;
&lt;br /&gt;
2. Yubikey OTP is configured to slot 1 on new Yubikeys, so you only need to click in the text box and then touch the metal part of your Yubikey.&lt;br /&gt;
Please refer to this [[Registration/2FA/Yubikey|documentation]] on how to configure your Yubikey.&lt;br /&gt;
[[File:BwIDM-yubikey.png|center|400px|thumb|Yubikey OTP]]&lt;br /&gt;
&lt;br /&gt;
3. If everything worked as expected, you will be returned to the &#039;&#039;&#039;My Tokens&#039;&#039;&#039; screen and there will be a new entry for your Yubikey.&lt;br /&gt;
[[File:BwIDM-yubikey2.png|center|400px|thumb|Success]]&lt;br /&gt;
&lt;br /&gt;
4. Repeat the process to register additional tokens.&lt;br /&gt;
Please register at least the &amp;quot;Backup TAN list&amp;quot; in addition to the hardware/software token you plan to use regularly.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Registering a new Yubikey OATH TOTP Token ==&lt;br /&gt;
&lt;br /&gt;
[https://developers.yubico.com/OATH/ Yubikey OATH TOTP] generates the TANs on your Yubikey and therefore you can use different computers and Android phones to generate these codes.&lt;br /&gt;
Please download and install [https://developers.yubico.com/OATH/YubiKey_OATH_software.html Yubico Authenticator] for Desktop (or Android) first.&lt;br /&gt;
Insert your Yubikey in your computer.&lt;br /&gt;
&amp;quot;Yubikey OTP&amp;quot; (not &amp;quot;Yubikey OATH TOTP&amp;quot;) is even easier and you don&#039;t need a device that displays the six-digit code or extra software (go to step [[Registration/2FA#Yubikey_OTP|Yubikey OTP]]).&lt;br /&gt;
&lt;br /&gt;
1. Registering a new Token starts with a click &#039;&#039;&#039;NEW SMARTPHONE TOKEN&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-token.png|center|600px|thumb|Create a new Token]]&lt;br /&gt;
&lt;br /&gt;
2. A new window opens. Click &#039;&#039;&#039;Start&#039;&#039;&#039; to generate a new &#039;&#039;&#039;QR code&#039;&#039;&#039;.&lt;br /&gt;
This may take a while.&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
The QR code contains a key which has to remain secret.&lt;br /&gt;
Only use the QR code to link your software token app with bwIDM/bwServices in the next step.&lt;br /&gt;
Do not save the QR code, print it out or share it with someone else.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
3. Start the Yubico Authenticator on your OS, click the three vertical dots in the upper right corner and select &#039;&#039;&#039;Scan QR code&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-yubi1.png|center|600px|thumb|QR Code and Yubico Authenticator on Linux]]&lt;br /&gt;
&lt;br /&gt;
4. Yubico Authenticator automatically translates the QR code to a new entry called &#039;&#039;&#039;bwIDM&#039;&#039;&#039; or &#039;&#039;&#039;bwServices&#039;&#039;&#039; (MLS&amp;amp;WISO).&lt;br /&gt;
Click &#039;&#039;&#039;Add account&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-yubi2.png|center|600px|thumb|Create new TOTP on Yubico Authenticator]]&lt;br /&gt;
&lt;br /&gt;
5. You will receive a six-digit code.&lt;br /&gt;
Enter this code into the field labeled &amp;quot;Current code:&amp;quot; in your bwIDM browser window to prove that the connection has worked and then click &#039;&#039;&#039;CHECK&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-yubi3.png|center|600px|thumb|Verify TOTP]]&lt;br /&gt;
&lt;br /&gt;
6. If everything worked as expected, you will be returned to the &#039;&#039;&#039;My Tokens&#039;&#039;&#039; screen and there will be a new entry for your software token.&lt;br /&gt;
[[File:BwIDM-app.png|center|400px|thumb|Success]]&lt;br /&gt;
&lt;br /&gt;
7. Repeat the process to register additional tokens.&lt;br /&gt;
Please register at least the &amp;quot;Backup TAN list&amp;quot; in addition to the hardware/software token you plan to use regularly.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Backup TAN List ==&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
Passwords from the &amp;quot;Backup TAN list&amp;quot; should only be used if no other token is left.&lt;br /&gt;
Please do not use the Backup TANs for regular cluster login, because you have only a limited number of TANs.&lt;br /&gt;
Each TAN can only be used once.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
1. Please create at least one &amp;quot;Backup TAN list&amp;quot; by clicking &#039;&#039;&#039;CREATE NEW TAN LIST&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-token.png|center|600px|thumb|Generate Backup TAN list]]&lt;br /&gt;
&lt;br /&gt;
2. Click &#039;&#039;&#039;START&#039;&#039;&#039;. You will be redirected to the &#039;&#039;&#039;My Tokens&#039;&#039;&#039; screen and there will be a new entry for your backup TANs.&lt;br /&gt;
[[File:BwIDM-tan.png|center|400px|thumb|Success]]&lt;br /&gt;
&lt;br /&gt;
3. Click &#039;&#039;&#039;SHOW TANS&#039;&#039;&#039;, print the codes and keep then in a separate place for emergencies.&lt;br /&gt;
[[File:JUSTUS-2-2FA-backup-TAN-list.png|center|800px|thumb|Print Backup TAN List]]&lt;br /&gt;
&lt;br /&gt;
4. Repeat the process to register additional tokens.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Deactivating a Token ==&lt;br /&gt;
&lt;br /&gt;
Click &#039;&#039;&#039;Disable&#039;&#039;&#039; next to the Token entry on the &#039;&#039;&#039;My Tokens&#039;&#039;&#039; screen.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Deleting a Token ==&lt;br /&gt;
&lt;br /&gt;
After a Token has been disabled a new button labeled &#039;&#039;&#039;Delete&#039;&#039;&#039; will appear. Click on it to delete the token.&lt;br /&gt;
&lt;br /&gt;
= Returning Users =&lt;br /&gt;
&lt;br /&gt;
Returning users who have already activated one or more tokens must first verify their token before they can create new tokens or deactivate/delete old ones.&lt;br /&gt;
If you no longer have valid tokens, you will not be able to create or manage tokens. &lt;br /&gt;
In this case, read the section [[Registration/2FA#Lost_Token|Lost Token]].&lt;br /&gt;
[[File:BwIDM-totp.png|center|400px|thumb|Returning users must first verify their token.]]&lt;br /&gt;
&lt;br /&gt;
= Lost Token =&lt;br /&gt;
&lt;br /&gt;
If you have lost a token, please create a new one.&lt;br /&gt;
If you change your phone, please migrate your tokens first or register your new mobile app under &amp;quot;My Tokens&amp;quot;.&lt;br /&gt;
&#039;&#039;&#039;If you no longer have valid tokens (mobile app, hardware token, Yubikey or backup TAN), you will need to contact the [https://bw-support.scc.kit.edu/ ticket system].&#039;&#039;&#039;&lt;br /&gt;
Please note that this process may take some time and also means additional work for the operators.&lt;/div&gt;</summary>
		<author><name>C Mosch</name></author>
	</entry>
	<entry>
		<id>https://wiki.bwhpc.de/wiki/index.php?title=Registration/2FA&amp;diff=10004</id>
		<title>Registration/2FA</title>
		<link rel="alternate" type="text/html" href="https://wiki.bwhpc.de/wiki/index.php?title=Registration/2FA&amp;diff=10004"/>
		<updated>2022-02-15T19:12:06Z</updated>

		<summary type="html">&lt;p&gt;C Mosch: /* Registering a new Software Token using a Mobile APP */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Generate a Second Factor (2FA) =&lt;br /&gt;
&lt;br /&gt;
To improve security a &#039;&#039;&#039;2-factor authentication mechanism (2FA)&#039;&#039;&#039; is being enforced for logins to bwUniCluster/bwForClusters. In addition to the service password a second value, the &#039;&#039;&#039;second factor&#039;&#039;&#039;, has to be entered on every login.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== How 2FA works ==&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
It is very important that the device that generates the One-Time Passwords and the device which is used to log into the bwUniCluster/bwForClusters are not the same.&lt;br /&gt;
Otherwise an attacker who gains access to your system can steal both the service password and the secret key of the Software Token application, which allows them to generate One-Time Passwords and log into the HPC system without your knowledge.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
[[File:2fa token code.jpg|right|200px|thumb|Hardware Token for TOTP]]&lt;br /&gt;
On the bwUniCluster/bwForClusters we use six-digit, auto-generated, time-dependent &#039;&#039;&#039;one-time passwords&#039;&#039;&#039; (TOTP). These passwords are generated by a piece of software which is part of a special hardware device (a &#039;&#039;&#039;hardware token&#039;&#039;&#039;) or of a normal application running on a common device (a &#039;&#039;&#039;software token&#039;&#039;&#039;).&lt;br /&gt;
&lt;br /&gt;
The Token has to be synchronized with a central server before it can be used for authentication and then generates an endless stream of six-digit values (TOTPs) which can only be used once and are only valid during a very short interval of time. This makes it much harder for potential attackers to access the HPC system, even if they know the regular service password.&lt;br /&gt;
&lt;br /&gt;
Typically a new TOTP value is generated every 30 seconds. When the current TOTP value has once been used successfully for a login, it is depleted and one has to wait up to 30 seconds for the next TOTP value. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:Otpapp.png|right|150px|thumb|Source: https://getaegis.app]]&lt;br /&gt;
&lt;br /&gt;
The most common solution is to use a mobile device (e.g. your smartphone or tablet) as a Software Token by installing one of the following apps:&lt;br /&gt;
* Google Authenticator for [https://play.google.com/store/apps/details?id=com.google.android.apps.authenticator2 Android] or [https://apps.apple.com/de/app/google-authenticator/id388497605 iOS]&lt;br /&gt;
* Microsoft Authenticator for [https://play.google.com/store/apps/details?id=com.azure.authenticator Android] or [https://apps.apple.com/de/app/microsoft-authenticator/id983156458 iOS] ([https://www.microsoft.com/de-de/security/mobile-authenticator-app Web Page])&lt;br /&gt;
* LastPass Authenticator for [https://play.google.com/store/apps/details?id=com.lastpass.authenticator Android], [https://apps.apple.com/us/app/lastpass-authenticator/id1079110004 iOS] or [https://lastpass.com/auth/ Windows]&lt;br /&gt;
* Aegis Authenticator for [https://play.google.com/store/apps/details?id=com.beemdevelopment.aegis Android (Google Play)] or [https://f-droid.org/en/packages/com.beemdevelopment.aegis/ Android (F-Droid)] ([https://getaegis.app/ Web Page])&lt;br /&gt;
* andOTP Authenticator for [https://play.google.com/store/apps/details?id=org.shadowice.flocke.andotp Android (Google Play)] or [https://f-droid.org/packages/org.shadowice.flocke.andotp/ Android (F-Droid)] ([https://github.com/andOTP/andOTP GitHub])&lt;br /&gt;
* OTP Auth for [https://apps.apple.com/app/otp-auth/id659877384 iOS]&lt;br /&gt;
* (Authy for [https://play.google.com/store/apps/details?id=com.authy.authy Android], [https://apps.apple.com/us/app/authy/id494168017 iOS], [https://authy.com/download/ Mac, Windows or Linux]) requires account&lt;br /&gt;
* (On Linux you can use [https://keepassxc.org/ KeepassXC] or [https://github.com/paolostivanin/OTPClient otpclient])&lt;br /&gt;
&lt;br /&gt;
These are only suggestions. You can use any application compatible with the [https://tools.ietf.org/html/rfc6238 TOTP] standard.&lt;br /&gt;
&lt;br /&gt;
If you don&#039;t want to use a smartphone, we recommend using a hardware token, such as Yubikey or another TOTP-compatible device. [https://www.yubico.com/resources/glossary/yubico-otp/ Yubico OTP] is also supported if you want to use your Yubikey without depending on having a six-digit code displayed. But you can also use the Yubikey as a generator for six-digit [https://www.yubico.com/resources/glossary/oath-totp/ TOTP].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Token Management =&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
* Create at least two separate tokens: &#039;&#039;&#039;FIRST&#039;&#039;&#039; set up a software/hardware TOTP token. &#039;&#039;&#039;THEN&#039;&#039;&#039; create and print a &amp;quot;backup TAN list&amp;quot;. Never create the &amp;quot;backup TAN list&amp;quot; first.&lt;br /&gt;
* If you lose access to all your tokens, you will not be able to create new tokens and support will have to reset your tokens manually.&lt;br /&gt;
* The &amp;quot;backup TAN list&amp;quot; should always be created and printed in a &#039;&#039;&#039;second step&#039;&#039;&#039;. The printout should be kept in a separate place for emergencies.&lt;br /&gt;
* Please disable all privacy tools, ad blockers and further add-ons when registering new tokens. These tools prevent the registration website from generating new security tokens. When there are still problems to enter the TOTP activation code &amp;quot;Current code&amp;quot; please try again with a new clean web browser profile.&lt;br /&gt;
* Please clean up your second factors as soon as you have created new tokens. Tokens that can no longer be used (e.g. because not initialized, smartphone/Yubikey lost, etc.) or an old backup TAN list where you have already used all TANs or there is no printout should be deactivated and deleted.&lt;br /&gt;
* Returning users who have already activated one or more tokens must first verify their token before they can create new tokens, see section [[Registration/2FA#Returning_Users|Returning Users]].&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;bwUniCluster/bwForCluster Tokens&#039;&#039;&#039; are generally managed via the &#039;&#039;&#039;Index -&amp;gt; My Tokens&#039;&#039;&#039; menu entry on the registration pages for the clusters. Here you can register, activate, deactivate and delete tokens.&lt;br /&gt;
&lt;br /&gt;
To activate the second factor, &#039;&#039;&#039;please perform the following steps:&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
1. &#039;&#039;&#039;Select the registration server of the cluster&#039;&#039;&#039; for which you want to create a second factor and login to it:&amp;lt;/br&amp;gt; &amp;amp;rarr; [https://login.bwidm.de/user/twofa.xhtml Registration server for &#039;&#039;&#039;bwUniCluster 2.0&#039;&#039;&#039; and &#039;&#039;&#039;bwForCluster JUSTUS 2&#039;&#039;&#039;] (2FA tokens are valid for both clusters; KIT members can reuse their existing hardware and software tokens)&amp;lt;/br&amp;gt; &amp;amp;rarr; [https://bwservices.uni-heidelberg.de//user/twofa.xhtml Registration server for &#039;&#039;&#039;bwForCluster MLS&amp;amp;WISO&#039;&#039;&#039;]&lt;br /&gt;
[[File:BwIDM-twofa.png|center|600px|thumb|My Tokens]]&lt;br /&gt;
&lt;br /&gt;
2. &#039;&#039;&#039;Register a new &amp;quot;[[Registration/2FA#Registering_a_new_Software_Token_using_a_Mobile_APP|Smartphone Token]]&amp;quot;&#039;&#039;&#039; or if you own a [https://www.yubico.com/ Yubikey]&#039;&#039;&#039; register a new &amp;quot;[[Registration/2FA#Registering_a_new_Yubikey_OTP_Token|Yubikey Token]]&amp;quot;&#039;&#039;&#039; or &#039;&#039;&#039;&amp;quot;[[Registration/2FA#Registering_a_new_Yubikey_OATH_TOTP_Token|Yubikey OATH TOTP Token]]&amp;quot;&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
3. &#039;&#039;&#039;Register a new &amp;quot;[[Registration/2FA#Backup_TAN_List|TAN List]]&amp;quot; (backup TAN list)&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
4. Repeat step 2. for additional tokens.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Registering a new Software Token using a Mobile APP ==&lt;br /&gt;
&lt;br /&gt;
1. Registering a new Token starts with a click &#039;&#039;&#039;NEW SMARTPHONE TOKEN&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-token.png|center|600px|thumb|Create a new Token]]&lt;br /&gt;
&lt;br /&gt;
2. A new window opens. Click &#039;&#039;&#039;Start&#039;&#039;&#039; to generate a new &#039;&#039;&#039;QR code&#039;&#039;&#039;.&lt;br /&gt;
This may take a while.&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
The QR code contains a key which has to remain secret.&lt;br /&gt;
Only use the QR code to link your software token app with bwIDM/bwServices in the next step.&lt;br /&gt;
Do not save the QR code, print it out or share it with someone else.&lt;br /&gt;
|}&lt;br /&gt;
[[File:BwIDM-qr.png|center|600px|thumb|QR Code for Mobile App]]&lt;br /&gt;
&lt;br /&gt;
3. Start the software token app on your separate device and scan the QR code.&lt;br /&gt;
The exact process is a little bit different in every app, but is usually started by pressing on a button with a plus (+) sign or an icon of a QR code.&lt;br /&gt;
&lt;br /&gt;
4. Once the QR code has been loaded into your Software Token app there should be a new entry called &#039;&#039;&#039;bwIDM&#039;&#039;&#039; (bwUniCluster and JUSTUS 2) or &#039;&#039;&#039;bwServices&#039;&#039;&#039; (MLS&amp;amp;WISO).&lt;br /&gt;
Generate an One-Time-Password by pressing on this entry or selecting the appropriate button/menu item.&lt;br /&gt;
You will receive a six-digit code.&lt;br /&gt;
Enter this code into the field labeled &amp;quot;Current code:&amp;quot; in your bwIDM browser window to prove that the connection has worked and then click &#039;&#039;&#039;Check&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
5. If everything worked as expected, you will be returned to the &#039;&#039;&#039;My Tokens&#039;&#039;&#039; screen and there will be a new entry for your software token.&lt;br /&gt;
[[File:BwIDM-app.png|center|400px|thumb|Success]]&lt;br /&gt;
&lt;br /&gt;
6. Repeat the process to register additional tokens.&lt;br /&gt;
Please register at least the &amp;quot;Backup TAN list&amp;quot; in addition to the hardware/software token you plan to use regularly.&lt;br /&gt;
&lt;br /&gt;
== Registering a new Yubikey OTP Token ==&lt;br /&gt;
&lt;br /&gt;
[https://developers.yubico.com/OTP/OTPs_Explained.html Yubikey OTP] is even easier and you don&#039;t need a device that displays the six-digit code or extra software.&lt;br /&gt;
New Yubikeys are already configured to provide Yubikey OTP in slot 1.&lt;br /&gt;
If you need to configure your Yubikey, read this [[Registration/2FA/Yubikey|documentation]].&lt;br /&gt;
&lt;br /&gt;
1. If you want to use [https://www.yubico.com/resources/glossary/yubico-otp/ Yubico OTP], you can click &#039;&#039;&#039;NEW YUBIKEY TOKEN&#039;&#039;&#039; instead.&lt;br /&gt;
[[File:BwIDM-token.png|center|600px|thumb|Generate Yubikey OTP]]&lt;br /&gt;
&lt;br /&gt;
2. Yubikey OTP is configured to slot 1 on new Yubikeys, so you only need to click in the text box and then touch the metal part of your Yubikey.&lt;br /&gt;
Please refer to this [[Registration/2FA/Yubikey|documentation]] on how to configure your Yubikey.&lt;br /&gt;
[[File:BwIDM-yubikey.png|center|400px|thumb|Yubikey OTP]]&lt;br /&gt;
&lt;br /&gt;
3. If everything worked as expected, you will be returned to the &#039;&#039;&#039;My Tokens&#039;&#039;&#039; screen and there will be a new entry for your Yubikey.&lt;br /&gt;
[[File:BwIDM-yubikey2.png|center|400px|thumb|Success]]&lt;br /&gt;
&lt;br /&gt;
4. Repeat the process to register additional tokens.&lt;br /&gt;
Please register at least the &amp;quot;Backup TAN list&amp;quot; in addition to the hardware/software token you plan to use regularly.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Registering a new Yubikey OATH TOTP Token ==&lt;br /&gt;
&lt;br /&gt;
[https://developers.yubico.com/OATH/ Yubikey OATH TOTP] generates the TANs on your Yubikey and therefore you can use different computers and Android phones to generate these codes.&lt;br /&gt;
Please download and install [https://developers.yubico.com/OATH/YubiKey_OATH_software.html Yubico Authenticator] for Desktop (or Android) first.&lt;br /&gt;
Insert your Yubikey in your computer.&lt;br /&gt;
&amp;quot;Yubikey OTP&amp;quot; (not &amp;quot;Yubikey OATH TOTP&amp;quot;) is even easier and you don&#039;t need a device that displays the six-digit code or extra software (go to step [[Registration/2FA#Yubikey_OTP|Yubikey OTP]]).&lt;br /&gt;
&lt;br /&gt;
1. Registering a new Token starts with a click &#039;&#039;&#039;NEW SMARTPHONE TOKEN&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-token.png|center|600px|thumb|Create a new Token]]&lt;br /&gt;
&lt;br /&gt;
2. A new window opens. Click &#039;&#039;&#039;Start&#039;&#039;&#039; to generate a new &#039;&#039;&#039;QR code&#039;&#039;&#039;.&lt;br /&gt;
This may take a while.&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
The QR code contains a key which has to remain secret.&lt;br /&gt;
Only use the QR code to link your software token app with bwIDM/bwServices in the next step.&lt;br /&gt;
Do not save the QR code, print it out or share it with someone else.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
3. Start the Yubico Authenticator on your OS, click the three vertical dots in the upper right corner and select &#039;&#039;&#039;Scan QR code&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-yubi1.png|center|600px|thumb|QR Code and Yubico Authenticator on Linux]]&lt;br /&gt;
&lt;br /&gt;
4. Yubico Authenticator automatically translates the QR code to a new entry called &#039;&#039;&#039;bwIDM&#039;&#039;&#039; or &#039;&#039;&#039;bwServices&#039;&#039;&#039; (MLS&amp;amp;WISO).&lt;br /&gt;
Click &#039;&#039;&#039;Add account&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-yubi2.png|center|600px|thumb|Create new TOTP on Yubico Authenticator]]&lt;br /&gt;
&lt;br /&gt;
5. You will receive a six-digit code.&lt;br /&gt;
Enter this code into the field labeled &amp;quot;Current code:&amp;quot; in your bwIDM browser window to prove that the connection has worked and then click &#039;&#039;&#039;CHECK&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-yubi3.png|center|600px|thumb|Verify TOTP]]&lt;br /&gt;
&lt;br /&gt;
6. If everything worked as expected, you will be returned to the &#039;&#039;&#039;My Tokens&#039;&#039;&#039; screen and there will be a new entry for your software token.&lt;br /&gt;
[[File:BwIDM-app.png|center|400px|thumb|Success]]&lt;br /&gt;
&lt;br /&gt;
7. Repeat the process to register additional tokens.&lt;br /&gt;
Please register at least the &amp;quot;Backup TAN list&amp;quot; in addition to the hardware/software token you plan to use regularly.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Backup TAN List ==&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
Passwords from the &amp;quot;Backup TAN list&amp;quot; should only be used if no other token is left.&lt;br /&gt;
Please do not use the Backup TANs for regular cluster login, because you have only a limited number of TANs.&lt;br /&gt;
Each TAN can only be used once.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
1. Please create at least one &amp;quot;Backup TAN list&amp;quot; by clicking &#039;&#039;&#039;CREATE NEW TAN LIST&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-token.png|center|600px|thumb|Generate Backup TAN list]]&lt;br /&gt;
&lt;br /&gt;
2. Click &#039;&#039;&#039;START&#039;&#039;&#039;. You will be redirected to the &#039;&#039;&#039;My Tokens&#039;&#039;&#039; screen and there will be a new entry for your backup TANs.&lt;br /&gt;
[[File:BwIDM-tan.png|center|400px|thumb|Success]]&lt;br /&gt;
&lt;br /&gt;
3. Click &#039;&#039;&#039;SHOW TANS&#039;&#039;&#039;, print the codes and keep then in a separate place for emergencies.&lt;br /&gt;
[[File:JUSTUS-2-2FA-backup-TAN-list.png|center|800px|thumb|Print Backup TAN List]]&lt;br /&gt;
&lt;br /&gt;
4. Repeat the process to register additional tokens.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Deactivating a Token ==&lt;br /&gt;
&lt;br /&gt;
Click &#039;&#039;&#039;Disable&#039;&#039;&#039; next to the Token entry on the &#039;&#039;&#039;My Tokens&#039;&#039;&#039; screen.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Deleting a Token ==&lt;br /&gt;
&lt;br /&gt;
After a Token has been disabled a new button labeled &#039;&#039;&#039;Delete&#039;&#039;&#039; will appear. Click on it to delete the token.&lt;br /&gt;
&lt;br /&gt;
= Returning Users =&lt;br /&gt;
&lt;br /&gt;
Returning users who have already activated one or more tokens must first verify their token before they can create new tokens or deactivate/delete old ones.&lt;br /&gt;
If you no longer have valid tokens, you will not be able to create or manage tokens. &lt;br /&gt;
In this case, read the section [[Registration/2FA#Lost_Token|Lost Token]].&lt;br /&gt;
[[File:BwIDM-totp.png|center|400px|thumb|Returning users must first verify their token.]]&lt;br /&gt;
&lt;br /&gt;
= Lost Token =&lt;br /&gt;
&lt;br /&gt;
If you have lost a token, please create a new one.&lt;br /&gt;
If you change your phone, please migrate your tokens first or register your new mobile app under &amp;quot;My Tokens&amp;quot;.&lt;br /&gt;
&#039;&#039;&#039;If you no longer have valid tokens (mobile app, hardware token, Yubikey or backup TAN), you will need to contact the [https://bw-support.scc.kit.edu/ ticket system].&#039;&#039;&#039;&lt;br /&gt;
Please note that this process may take some time and also means additional work for the operators.&lt;/div&gt;</summary>
		<author><name>C Mosch</name></author>
	</entry>
	<entry>
		<id>https://wiki.bwhpc.de/wiki/index.php?title=Registration/2FA&amp;diff=10003</id>
		<title>Registration/2FA</title>
		<link rel="alternate" type="text/html" href="https://wiki.bwhpc.de/wiki/index.php?title=Registration/2FA&amp;diff=10003"/>
		<updated>2022-02-15T18:41:24Z</updated>

		<summary type="html">&lt;p&gt;C Mosch: /* Token Management */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Generate a Second Factor (2FA) =&lt;br /&gt;
&lt;br /&gt;
To improve security a &#039;&#039;&#039;2-factor authentication mechanism (2FA)&#039;&#039;&#039; is being enforced for logins to bwUniCluster/bwForClusters. In addition to the service password a second value, the &#039;&#039;&#039;second factor&#039;&#039;&#039;, has to be entered on every login.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== How 2FA works ==&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
It is very important that the device that generates the One-Time Passwords and the device which is used to log into the bwUniCluster/bwForClusters are not the same.&lt;br /&gt;
Otherwise an attacker who gains access to your system can steal both the service password and the secret key of the Software Token application, which allows them to generate One-Time Passwords and log into the HPC system without your knowledge.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
[[File:2fa token code.jpg|right|200px|thumb|Hardware Token for TOTP]]&lt;br /&gt;
On the bwUniCluster/bwForClusters we use six-digit, auto-generated, time-dependent &#039;&#039;&#039;one-time passwords&#039;&#039;&#039; (TOTP). These passwords are generated by a piece of software which is part of a special hardware device (a &#039;&#039;&#039;hardware token&#039;&#039;&#039;) or of a normal application running on a common device (a &#039;&#039;&#039;software token&#039;&#039;&#039;).&lt;br /&gt;
&lt;br /&gt;
The Token has to be synchronized with a central server before it can be used for authentication and then generates an endless stream of six-digit values (TOTPs) which can only be used once and are only valid during a very short interval of time. This makes it much harder for potential attackers to access the HPC system, even if they know the regular service password.&lt;br /&gt;
&lt;br /&gt;
Typically a new TOTP value is generated every 30 seconds. When the current TOTP value has once been used successfully for a login, it is depleted and one has to wait up to 30 seconds for the next TOTP value. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:Otpapp.png|right|150px|thumb|Source: https://getaegis.app]]&lt;br /&gt;
&lt;br /&gt;
The most common solution is to use a mobile device (e.g. your smartphone or tablet) as a Software Token by installing one of the following apps:&lt;br /&gt;
* Google Authenticator for [https://play.google.com/store/apps/details?id=com.google.android.apps.authenticator2 Android] or [https://apps.apple.com/de/app/google-authenticator/id388497605 iOS]&lt;br /&gt;
* Microsoft Authenticator for [https://play.google.com/store/apps/details?id=com.azure.authenticator Android] or [https://apps.apple.com/de/app/microsoft-authenticator/id983156458 iOS] ([https://www.microsoft.com/de-de/security/mobile-authenticator-app Web Page])&lt;br /&gt;
* LastPass Authenticator for [https://play.google.com/store/apps/details?id=com.lastpass.authenticator Android], [https://apps.apple.com/us/app/lastpass-authenticator/id1079110004 iOS] or [https://lastpass.com/auth/ Windows]&lt;br /&gt;
* Aegis Authenticator for [https://play.google.com/store/apps/details?id=com.beemdevelopment.aegis Android (Google Play)] or [https://f-droid.org/en/packages/com.beemdevelopment.aegis/ Android (F-Droid)] ([https://getaegis.app/ Web Page])&lt;br /&gt;
* andOTP Authenticator for [https://play.google.com/store/apps/details?id=org.shadowice.flocke.andotp Android (Google Play)] or [https://f-droid.org/packages/org.shadowice.flocke.andotp/ Android (F-Droid)] ([https://github.com/andOTP/andOTP GitHub])&lt;br /&gt;
* OTP Auth for [https://apps.apple.com/app/otp-auth/id659877384 iOS]&lt;br /&gt;
* (Authy for [https://play.google.com/store/apps/details?id=com.authy.authy Android], [https://apps.apple.com/us/app/authy/id494168017 iOS], [https://authy.com/download/ Mac, Windows or Linux]) requires account&lt;br /&gt;
* (On Linux you can use [https://keepassxc.org/ KeepassXC] or [https://github.com/paolostivanin/OTPClient otpclient])&lt;br /&gt;
&lt;br /&gt;
These are only suggestions. You can use any application compatible with the [https://tools.ietf.org/html/rfc6238 TOTP] standard.&lt;br /&gt;
&lt;br /&gt;
If you don&#039;t want to use a smartphone, we recommend using a hardware token, such as Yubikey or another TOTP-compatible device. [https://www.yubico.com/resources/glossary/yubico-otp/ Yubico OTP] is also supported if you want to use your Yubikey without depending on having a six-digit code displayed. But you can also use the Yubikey as a generator for six-digit [https://www.yubico.com/resources/glossary/oath-totp/ TOTP].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Token Management =&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
* Create at least two separate tokens: &#039;&#039;&#039;FIRST&#039;&#039;&#039; set up a software/hardware TOTP token. &#039;&#039;&#039;THEN&#039;&#039;&#039; create and print a &amp;quot;backup TAN list&amp;quot;. Never create the &amp;quot;backup TAN list&amp;quot; first.&lt;br /&gt;
* If you lose access to all your tokens, you will not be able to create new tokens and support will have to reset your tokens manually.&lt;br /&gt;
* The &amp;quot;backup TAN list&amp;quot; should always be created and printed in a &#039;&#039;&#039;second step&#039;&#039;&#039;. The printout should be kept in a separate place for emergencies.&lt;br /&gt;
* Please disable all privacy tools, ad blockers and further add-ons when registering new tokens. These tools prevent the registration website from generating new security tokens. When there are still problems to enter the TOTP activation code &amp;quot;Current code&amp;quot; please try again with a new clean web browser profile.&lt;br /&gt;
* Please clean up your second factors as soon as you have created new tokens. Tokens that can no longer be used (e.g. because not initialized, smartphone/Yubikey lost, etc.) or an old backup TAN list where you have already used all TANs or there is no printout should be deactivated and deleted.&lt;br /&gt;
* Returning users who have already activated one or more tokens must first verify their token before they can create new tokens, see section [[Registration/2FA#Returning_Users|Returning Users]].&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;bwUniCluster/bwForCluster Tokens&#039;&#039;&#039; are generally managed via the &#039;&#039;&#039;Index -&amp;gt; My Tokens&#039;&#039;&#039; menu entry on the registration pages for the clusters. Here you can register, activate, deactivate and delete tokens.&lt;br /&gt;
&lt;br /&gt;
To activate the second factor, &#039;&#039;&#039;please perform the following steps:&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
1. &#039;&#039;&#039;Select the registration server of the cluster&#039;&#039;&#039; for which you want to create a second factor and login to it:&amp;lt;/br&amp;gt; &amp;amp;rarr; [https://login.bwidm.de/user/twofa.xhtml Registration server for &#039;&#039;&#039;bwUniCluster 2.0&#039;&#039;&#039; and &#039;&#039;&#039;bwForCluster JUSTUS 2&#039;&#039;&#039;] (2FA tokens are valid for both clusters; KIT members can reuse their existing hardware and software tokens)&amp;lt;/br&amp;gt; &amp;amp;rarr; [https://bwservices.uni-heidelberg.de//user/twofa.xhtml Registration server for &#039;&#039;&#039;bwForCluster MLS&amp;amp;WISO&#039;&#039;&#039;]&lt;br /&gt;
[[File:BwIDM-twofa.png|center|600px|thumb|My Tokens]]&lt;br /&gt;
&lt;br /&gt;
2. &#039;&#039;&#039;Register a new &amp;quot;[[Registration/2FA#Registering_a_new_Software_Token_using_a_Mobile_APP|Smartphone Token]]&amp;quot;&#039;&#039;&#039; or if you own a [https://www.yubico.com/ Yubikey]&#039;&#039;&#039; register a new &amp;quot;[[Registration/2FA#Registering_a_new_Yubikey_OTP_Token|Yubikey Token]]&amp;quot;&#039;&#039;&#039; or &#039;&#039;&#039;&amp;quot;[[Registration/2FA#Registering_a_new_Yubikey_OATH_TOTP_Token|Yubikey OATH TOTP Token]]&amp;quot;&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
3. &#039;&#039;&#039;Register a new &amp;quot;[[Registration/2FA#Backup_TAN_List|TAN List]]&amp;quot; (backup TAN list)&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
4. Repeat step 2. for additional tokens.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Registering a new Software Token using a Mobile APP ==&lt;br /&gt;
&lt;br /&gt;
1. Registering a new Token starts with a click &#039;&#039;&#039;NEW SMARTPHONE TOKEN&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-token.png|center|600px|thumb|Create a new Token]]&lt;br /&gt;
&lt;br /&gt;
2. A new window opens. Click &#039;&#039;&#039;Start&#039;&#039;&#039; to generate a new &#039;&#039;&#039;QR code&#039;&#039;&#039;.&lt;br /&gt;
This may take a while.&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
The QR code contains a key which has to remain secret.&lt;br /&gt;
Only use the QR code to link your software token app with bwIDM/bwServices in the next step.&lt;br /&gt;
Do not save the QR code, print it out or share it with someone else.&lt;br /&gt;
|}&lt;br /&gt;
[[File:BwIDM-qr.png|center|600px|thumb|QR Code for Mobile App]]&lt;br /&gt;
&lt;br /&gt;
3. Start the software token app on your separate device and scan the QR code.&lt;br /&gt;
The exact process is a little bit different in every app, but is usually started by pressing on a button with a plus (+) sign or an icon of a QR code.&lt;br /&gt;
&lt;br /&gt;
4. Once the QR code has been loaded into your Software Token app there should be a new entry called &#039;&#039;&#039;bwIDM&#039;&#039;&#039; or &#039;&#039;&#039;bwServices&#039;&#039;&#039; (MLS&amp;amp;WISO).&lt;br /&gt;
Generate an One-Time-Password by pressing on this entry or selecting the appropriate button/menu item.&lt;br /&gt;
You will receive a six-digit code.&lt;br /&gt;
Enter this code into the field labeled &amp;quot;Current code:&amp;quot; in your bwIDM browser window to prove that the connection has worked and then click &#039;&#039;&#039;Check&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
5. If everything worked as expected, you will be returned to the &#039;&#039;&#039;My Tokens&#039;&#039;&#039; screen and there will be a new entry for your software token.&lt;br /&gt;
[[File:BwIDM-app.png|center|400px|thumb|Success]]&lt;br /&gt;
&lt;br /&gt;
6. Repeat the process to register additional tokens.&lt;br /&gt;
Please register at least the &amp;quot;Backup TAN list&amp;quot; in addition to the hardware/software token you plan to use regularly.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Registering a new Yubikey OTP Token ==&lt;br /&gt;
&lt;br /&gt;
[https://developers.yubico.com/OTP/OTPs_Explained.html Yubikey OTP] is even easier and you don&#039;t need a device that displays the six-digit code or extra software.&lt;br /&gt;
New Yubikeys are already configured to provide Yubikey OTP in slot 1.&lt;br /&gt;
If you need to configure your Yubikey, read this [[Registration/2FA/Yubikey|documentation]].&lt;br /&gt;
&lt;br /&gt;
1. If you want to use [https://www.yubico.com/resources/glossary/yubico-otp/ Yubico OTP], you can click &#039;&#039;&#039;NEW YUBIKEY TOKEN&#039;&#039;&#039; instead.&lt;br /&gt;
[[File:BwIDM-token.png|center|600px|thumb|Generate Yubikey OTP]]&lt;br /&gt;
&lt;br /&gt;
2. Yubikey OTP is configured to slot 1 on new Yubikeys, so you only need to click in the text box and then touch the metal part of your Yubikey.&lt;br /&gt;
Please refer to this [[Registration/2FA/Yubikey|documentation]] on how to configure your Yubikey.&lt;br /&gt;
[[File:BwIDM-yubikey.png|center|400px|thumb|Yubikey OTP]]&lt;br /&gt;
&lt;br /&gt;
3. If everything worked as expected, you will be returned to the &#039;&#039;&#039;My Tokens&#039;&#039;&#039; screen and there will be a new entry for your Yubikey.&lt;br /&gt;
[[File:BwIDM-yubikey2.png|center|400px|thumb|Success]]&lt;br /&gt;
&lt;br /&gt;
4. Repeat the process to register additional tokens.&lt;br /&gt;
Please register at least the &amp;quot;Backup TAN list&amp;quot; in addition to the hardware/software token you plan to use regularly.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Registering a new Yubikey OATH TOTP Token ==&lt;br /&gt;
&lt;br /&gt;
[https://developers.yubico.com/OATH/ Yubikey OATH TOTP] generates the TANs on your Yubikey and therefore you can use different computers and Android phones to generate these codes.&lt;br /&gt;
Please download and install [https://developers.yubico.com/OATH/YubiKey_OATH_software.html Yubico Authenticator] for Desktop (or Android) first.&lt;br /&gt;
Insert your Yubikey in your computer.&lt;br /&gt;
&amp;quot;Yubikey OTP&amp;quot; (not &amp;quot;Yubikey OATH TOTP&amp;quot;) is even easier and you don&#039;t need a device that displays the six-digit code or extra software (go to step [[Registration/2FA#Yubikey_OTP|Yubikey OTP]]).&lt;br /&gt;
&lt;br /&gt;
1. Registering a new Token starts with a click &#039;&#039;&#039;NEW SMARTPHONE TOKEN&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-token.png|center|600px|thumb|Create a new Token]]&lt;br /&gt;
&lt;br /&gt;
2. A new window opens. Click &#039;&#039;&#039;Start&#039;&#039;&#039; to generate a new &#039;&#039;&#039;QR code&#039;&#039;&#039;.&lt;br /&gt;
This may take a while.&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
The QR code contains a key which has to remain secret.&lt;br /&gt;
Only use the QR code to link your software token app with bwIDM/bwServices in the next step.&lt;br /&gt;
Do not save the QR code, print it out or share it with someone else.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
3. Start the Yubico Authenticator on your OS, click the three vertical dots in the upper right corner and select &#039;&#039;&#039;Scan QR code&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-yubi1.png|center|600px|thumb|QR Code and Yubico Authenticator on Linux]]&lt;br /&gt;
&lt;br /&gt;
4. Yubico Authenticator automatically translates the QR code to a new entry called &#039;&#039;&#039;bwIDM&#039;&#039;&#039; or &#039;&#039;&#039;bwServices&#039;&#039;&#039; (MLS&amp;amp;WISO).&lt;br /&gt;
Click &#039;&#039;&#039;Add account&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-yubi2.png|center|600px|thumb|Create new TOTP on Yubico Authenticator]]&lt;br /&gt;
&lt;br /&gt;
5. You will receive a six-digit code.&lt;br /&gt;
Enter this code into the field labeled &amp;quot;Current code:&amp;quot; in your bwIDM browser window to prove that the connection has worked and then click &#039;&#039;&#039;CHECK&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-yubi3.png|center|600px|thumb|Verify TOTP]]&lt;br /&gt;
&lt;br /&gt;
6. If everything worked as expected, you will be returned to the &#039;&#039;&#039;My Tokens&#039;&#039;&#039; screen and there will be a new entry for your software token.&lt;br /&gt;
[[File:BwIDM-app.png|center|400px|thumb|Success]]&lt;br /&gt;
&lt;br /&gt;
7. Repeat the process to register additional tokens.&lt;br /&gt;
Please register at least the &amp;quot;Backup TAN list&amp;quot; in addition to the hardware/software token you plan to use regularly.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Backup TAN List ==&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
Passwords from the &amp;quot;Backup TAN list&amp;quot; should only be used if no other token is left.&lt;br /&gt;
Please do not use the Backup TANs for regular cluster login, because you have only a limited number of TANs.&lt;br /&gt;
Each TAN can only be used once.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
1. Please create at least one &amp;quot;Backup TAN list&amp;quot; by clicking &#039;&#039;&#039;CREATE NEW TAN LIST&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-token.png|center|600px|thumb|Generate Backup TAN list]]&lt;br /&gt;
&lt;br /&gt;
2. Click &#039;&#039;&#039;START&#039;&#039;&#039;. You will be redirected to the &#039;&#039;&#039;My Tokens&#039;&#039;&#039; screen and there will be a new entry for your backup TANs.&lt;br /&gt;
[[File:BwIDM-tan.png|center|400px|thumb|Success]]&lt;br /&gt;
&lt;br /&gt;
3. Click &#039;&#039;&#039;SHOW TANS&#039;&#039;&#039;, print the codes and keep then in a separate place for emergencies.&lt;br /&gt;
[[File:JUSTUS-2-2FA-backup-TAN-list.png|center|800px|thumb|Print Backup TAN List]]&lt;br /&gt;
&lt;br /&gt;
4. Repeat the process to register additional tokens.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Deactivating a Token ==&lt;br /&gt;
&lt;br /&gt;
Click &#039;&#039;&#039;Disable&#039;&#039;&#039; next to the Token entry on the &#039;&#039;&#039;My Tokens&#039;&#039;&#039; screen.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Deleting a Token ==&lt;br /&gt;
&lt;br /&gt;
After a Token has been disabled a new button labeled &#039;&#039;&#039;Delete&#039;&#039;&#039; will appear. Click on it to delete the token.&lt;br /&gt;
&lt;br /&gt;
= Returning Users =&lt;br /&gt;
&lt;br /&gt;
Returning users who have already activated one or more tokens must first verify their token before they can create new tokens or deactivate/delete old ones.&lt;br /&gt;
If you no longer have valid tokens, you will not be able to create or manage tokens. &lt;br /&gt;
In this case, read the section [[Registration/2FA#Lost_Token|Lost Token]].&lt;br /&gt;
[[File:BwIDM-totp.png|center|400px|thumb|Returning users must first verify their token.]]&lt;br /&gt;
&lt;br /&gt;
= Lost Token =&lt;br /&gt;
&lt;br /&gt;
If you have lost a token, please create a new one.&lt;br /&gt;
If you change your phone, please migrate your tokens first or register your new mobile app under &amp;quot;My Tokens&amp;quot;.&lt;br /&gt;
&#039;&#039;&#039;If you no longer have valid tokens (mobile app, hardware token, Yubikey or backup TAN), you will need to contact the [https://bw-support.scc.kit.edu/ ticket system].&#039;&#039;&#039;&lt;br /&gt;
Please note that this process may take some time and also means additional work for the operators.&lt;/div&gt;</summary>
		<author><name>C Mosch</name></author>
	</entry>
	<entry>
		<id>https://wiki.bwhpc.de/wiki/index.php?title=Registration/2FA&amp;diff=10002</id>
		<title>Registration/2FA</title>
		<link rel="alternate" type="text/html" href="https://wiki.bwhpc.de/wiki/index.php?title=Registration/2FA&amp;diff=10002"/>
		<updated>2022-02-15T18:38:38Z</updated>

		<summary type="html">&lt;p&gt;C Mosch: /* Token Management */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;= Generate a Second Factor (2FA) =&lt;br /&gt;
&lt;br /&gt;
To improve security a &#039;&#039;&#039;2-factor authentication mechanism (2FA)&#039;&#039;&#039; is being enforced for logins to bwUniCluster/bwForClusters. In addition to the service password a second value, the &#039;&#039;&#039;second factor&#039;&#039;&#039;, has to be entered on every login.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== How 2FA works ==&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
It is very important that the device that generates the One-Time Passwords and the device which is used to log into the bwUniCluster/bwForClusters are not the same.&lt;br /&gt;
Otherwise an attacker who gains access to your system can steal both the service password and the secret key of the Software Token application, which allows them to generate One-Time Passwords and log into the HPC system without your knowledge.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
[[File:2fa token code.jpg|right|200px|thumb|Hardware Token for TOTP]]&lt;br /&gt;
On the bwUniCluster/bwForClusters we use six-digit, auto-generated, time-dependent &#039;&#039;&#039;one-time passwords&#039;&#039;&#039; (TOTP). These passwords are generated by a piece of software which is part of a special hardware device (a &#039;&#039;&#039;hardware token&#039;&#039;&#039;) or of a normal application running on a common device (a &#039;&#039;&#039;software token&#039;&#039;&#039;).&lt;br /&gt;
&lt;br /&gt;
The Token has to be synchronized with a central server before it can be used for authentication and then generates an endless stream of six-digit values (TOTPs) which can only be used once and are only valid during a very short interval of time. This makes it much harder for potential attackers to access the HPC system, even if they know the regular service password.&lt;br /&gt;
&lt;br /&gt;
Typically a new TOTP value is generated every 30 seconds. When the current TOTP value has once been used successfully for a login, it is depleted and one has to wait up to 30 seconds for the next TOTP value. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[File:Otpapp.png|right|150px|thumb|Source: https://getaegis.app]]&lt;br /&gt;
&lt;br /&gt;
The most common solution is to use a mobile device (e.g. your smartphone or tablet) as a Software Token by installing one of the following apps:&lt;br /&gt;
* Google Authenticator for [https://play.google.com/store/apps/details?id=com.google.android.apps.authenticator2 Android] or [https://apps.apple.com/de/app/google-authenticator/id388497605 iOS]&lt;br /&gt;
* Microsoft Authenticator for [https://play.google.com/store/apps/details?id=com.azure.authenticator Android] or [https://apps.apple.com/de/app/microsoft-authenticator/id983156458 iOS] ([https://www.microsoft.com/de-de/security/mobile-authenticator-app Web Page])&lt;br /&gt;
* LastPass Authenticator for [https://play.google.com/store/apps/details?id=com.lastpass.authenticator Android], [https://apps.apple.com/us/app/lastpass-authenticator/id1079110004 iOS] or [https://lastpass.com/auth/ Windows]&lt;br /&gt;
* Aegis Authenticator for [https://play.google.com/store/apps/details?id=com.beemdevelopment.aegis Android (Google Play)] or [https://f-droid.org/en/packages/com.beemdevelopment.aegis/ Android (F-Droid)] ([https://getaegis.app/ Web Page])&lt;br /&gt;
* andOTP Authenticator for [https://play.google.com/store/apps/details?id=org.shadowice.flocke.andotp Android (Google Play)] or [https://f-droid.org/packages/org.shadowice.flocke.andotp/ Android (F-Droid)] ([https://github.com/andOTP/andOTP GitHub])&lt;br /&gt;
* OTP Auth for [https://apps.apple.com/app/otp-auth/id659877384 iOS]&lt;br /&gt;
* (Authy for [https://play.google.com/store/apps/details?id=com.authy.authy Android], [https://apps.apple.com/us/app/authy/id494168017 iOS], [https://authy.com/download/ Mac, Windows or Linux]) requires account&lt;br /&gt;
* (On Linux you can use [https://keepassxc.org/ KeepassXC] or [https://github.com/paolostivanin/OTPClient otpclient])&lt;br /&gt;
&lt;br /&gt;
These are only suggestions. You can use any application compatible with the [https://tools.ietf.org/html/rfc6238 TOTP] standard.&lt;br /&gt;
&lt;br /&gt;
If you don&#039;t want to use a smartphone, we recommend using a hardware token, such as Yubikey or another TOTP-compatible device. [https://www.yubico.com/resources/glossary/yubico-otp/ Yubico OTP] is also supported if you want to use your Yubikey without depending on having a six-digit code displayed. But you can also use the Yubikey as a generator for six-digit [https://www.yubico.com/resources/glossary/oath-totp/ TOTP].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
= Token Management =&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
* Create at least two separate tokens: &#039;&#039;&#039;FIRST&#039;&#039;&#039; set up a software/hardware TOTP token. &#039;&#039;&#039;THEN&#039;&#039;&#039; create and print a &amp;quot;backup TAN list&amp;quot;. Never create the &amp;quot;backup TAN list&amp;quot; first.&lt;br /&gt;
* If you lose access to all your tokens, you will not be able to create new tokens and support will have to reset your tokens manually.&lt;br /&gt;
* The &amp;quot;backup TAN list&amp;quot; should always be created and printed in a &#039;&#039;&#039;second step&#039;&#039;&#039;. The printout should be kept in a separate place for emergencies.&lt;br /&gt;
* Please disable all privacy tools, ad blockers and further add-ons when registering new tokens. These tools prevent the registration website from generating new security tokens. When there are still problems please try again with a new clean web browser profile.&lt;br /&gt;
* Please clean up your second factors as soon as you have created new tokens. Tokens that can no longer be used (e.g. because not initialized, smartphone/Yubikey lost, etc.) or an old backup TAN list where you have already used all TANs or there is no printout should be deactivated and deleted.&lt;br /&gt;
* Returning users who have already activated one or more tokens must first verify their token before they can create new tokens, see section [[Registration/2FA#Returning_Users|Returning Users]].&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
&#039;&#039;&#039;bwUniCluster/bwForCluster Tokens&#039;&#039;&#039; are generally managed via the &#039;&#039;&#039;Index -&amp;gt; My Tokens&#039;&#039;&#039; menu entry on the registration pages for the clusters. Here you can register, activate, deactivate and delete tokens.&lt;br /&gt;
&lt;br /&gt;
To activate the second factor, &#039;&#039;&#039;please perform the following steps:&#039;&#039;&#039;&lt;br /&gt;
&lt;br /&gt;
1. &#039;&#039;&#039;Select the registration server of the cluster&#039;&#039;&#039; for which you want to create a second factor and login to it:&amp;lt;/br&amp;gt; &amp;amp;rarr; [https://login.bwidm.de/user/twofa.xhtml Registration server for &#039;&#039;&#039;bwUniCluster 2.0&#039;&#039;&#039; and &#039;&#039;&#039;bwForCluster JUSTUS 2&#039;&#039;&#039;] (2FA tokens are valid for both clusters; KIT members can reuse their existing hardware and software tokens)&amp;lt;/br&amp;gt; &amp;amp;rarr; [https://bwservices.uni-heidelberg.de//user/twofa.xhtml Registration server for &#039;&#039;&#039;bwForCluster MLS&amp;amp;WISO&#039;&#039;&#039;]&lt;br /&gt;
[[File:BwIDM-twofa.png|center|600px|thumb|My Tokens]]&lt;br /&gt;
&lt;br /&gt;
2. &#039;&#039;&#039;Register a new &amp;quot;[[Registration/2FA#Registering_a_new_Software_Token_using_a_Mobile_APP|Smartphone Token]]&amp;quot;&#039;&#039;&#039; or if you own a [https://www.yubico.com/ Yubikey]&#039;&#039;&#039; register a new &amp;quot;[[Registration/2FA#Registering_a_new_Yubikey_OTP_Token|Yubikey Token]]&amp;quot;&#039;&#039;&#039; or &#039;&#039;&#039;&amp;quot;[[Registration/2FA#Registering_a_new_Yubikey_OATH_TOTP_Token|Yubikey OATH TOTP Token]]&amp;quot;&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
3. &#039;&#039;&#039;Register a new &amp;quot;[[Registration/2FA#Backup_TAN_List|TAN List]]&amp;quot; (backup TAN list)&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
4. Repeat step 2. for additional tokens.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Registering a new Software Token using a Mobile APP ==&lt;br /&gt;
&lt;br /&gt;
1. Registering a new Token starts with a click &#039;&#039;&#039;NEW SMARTPHONE TOKEN&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-token.png|center|600px|thumb|Create a new Token]]&lt;br /&gt;
&lt;br /&gt;
2. A new window opens. Click &#039;&#039;&#039;Start&#039;&#039;&#039; to generate a new &#039;&#039;&#039;QR code&#039;&#039;&#039;.&lt;br /&gt;
This may take a while.&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
The QR code contains a key which has to remain secret.&lt;br /&gt;
Only use the QR code to link your software token app with bwIDM/bwServices in the next step.&lt;br /&gt;
Do not save the QR code, print it out or share it with someone else.&lt;br /&gt;
|}&lt;br /&gt;
[[File:BwIDM-qr.png|center|600px|thumb|QR Code for Mobile App]]&lt;br /&gt;
&lt;br /&gt;
3. Start the software token app on your separate device and scan the QR code.&lt;br /&gt;
The exact process is a little bit different in every app, but is usually started by pressing on a button with a plus (+) sign or an icon of a QR code.&lt;br /&gt;
&lt;br /&gt;
4. Once the QR code has been loaded into your Software Token app there should be a new entry called &#039;&#039;&#039;bwIDM&#039;&#039;&#039; or &#039;&#039;&#039;bwServices&#039;&#039;&#039; (MLS&amp;amp;WISO).&lt;br /&gt;
Generate an One-Time-Password by pressing on this entry or selecting the appropriate button/menu item.&lt;br /&gt;
You will receive a six-digit code.&lt;br /&gt;
Enter this code into the field labeled &amp;quot;Current code:&amp;quot; in your bwIDM browser window to prove that the connection has worked and then click &#039;&#039;&#039;Check&#039;&#039;&#039;.&lt;br /&gt;
&lt;br /&gt;
5. If everything worked as expected, you will be returned to the &#039;&#039;&#039;My Tokens&#039;&#039;&#039; screen and there will be a new entry for your software token.&lt;br /&gt;
[[File:BwIDM-app.png|center|400px|thumb|Success]]&lt;br /&gt;
&lt;br /&gt;
6. Repeat the process to register additional tokens.&lt;br /&gt;
Please register at least the &amp;quot;Backup TAN list&amp;quot; in addition to the hardware/software token you plan to use regularly.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Registering a new Yubikey OTP Token ==&lt;br /&gt;
&lt;br /&gt;
[https://developers.yubico.com/OTP/OTPs_Explained.html Yubikey OTP] is even easier and you don&#039;t need a device that displays the six-digit code or extra software.&lt;br /&gt;
New Yubikeys are already configured to provide Yubikey OTP in slot 1.&lt;br /&gt;
If you need to configure your Yubikey, read this [[Registration/2FA/Yubikey|documentation]].&lt;br /&gt;
&lt;br /&gt;
1. If you want to use [https://www.yubico.com/resources/glossary/yubico-otp/ Yubico OTP], you can click &#039;&#039;&#039;NEW YUBIKEY TOKEN&#039;&#039;&#039; instead.&lt;br /&gt;
[[File:BwIDM-token.png|center|600px|thumb|Generate Yubikey OTP]]&lt;br /&gt;
&lt;br /&gt;
2. Yubikey OTP is configured to slot 1 on new Yubikeys, so you only need to click in the text box and then touch the metal part of your Yubikey.&lt;br /&gt;
Please refer to this [[Registration/2FA/Yubikey|documentation]] on how to configure your Yubikey.&lt;br /&gt;
[[File:BwIDM-yubikey.png|center|400px|thumb|Yubikey OTP]]&lt;br /&gt;
&lt;br /&gt;
3. If everything worked as expected, you will be returned to the &#039;&#039;&#039;My Tokens&#039;&#039;&#039; screen and there will be a new entry for your Yubikey.&lt;br /&gt;
[[File:BwIDM-yubikey2.png|center|400px|thumb|Success]]&lt;br /&gt;
&lt;br /&gt;
4. Repeat the process to register additional tokens.&lt;br /&gt;
Please register at least the &amp;quot;Backup TAN list&amp;quot; in addition to the hardware/software token you plan to use regularly.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Registering a new Yubikey OATH TOTP Token ==&lt;br /&gt;
&lt;br /&gt;
[https://developers.yubico.com/OATH/ Yubikey OATH TOTP] generates the TANs on your Yubikey and therefore you can use different computers and Android phones to generate these codes.&lt;br /&gt;
Please download and install [https://developers.yubico.com/OATH/YubiKey_OATH_software.html Yubico Authenticator] for Desktop (or Android) first.&lt;br /&gt;
Insert your Yubikey in your computer.&lt;br /&gt;
&amp;quot;Yubikey OTP&amp;quot; (not &amp;quot;Yubikey OATH TOTP&amp;quot;) is even easier and you don&#039;t need a device that displays the six-digit code or extra software (go to step [[Registration/2FA#Yubikey_OTP|Yubikey OTP]]).&lt;br /&gt;
&lt;br /&gt;
1. Registering a new Token starts with a click &#039;&#039;&#039;NEW SMARTPHONE TOKEN&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-token.png|center|600px|thumb|Create a new Token]]&lt;br /&gt;
&lt;br /&gt;
2. A new window opens. Click &#039;&#039;&#039;Start&#039;&#039;&#039; to generate a new &#039;&#039;&#039;QR code&#039;&#039;&#039;.&lt;br /&gt;
This may take a while.&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
The QR code contains a key which has to remain secret.&lt;br /&gt;
Only use the QR code to link your software token app with bwIDM/bwServices in the next step.&lt;br /&gt;
Do not save the QR code, print it out or share it with someone else.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
3. Start the Yubico Authenticator on your OS, click the three vertical dots in the upper right corner and select &#039;&#039;&#039;Scan QR code&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-yubi1.png|center|600px|thumb|QR Code and Yubico Authenticator on Linux]]&lt;br /&gt;
&lt;br /&gt;
4. Yubico Authenticator automatically translates the QR code to a new entry called &#039;&#039;&#039;bwIDM&#039;&#039;&#039; or &#039;&#039;&#039;bwServices&#039;&#039;&#039; (MLS&amp;amp;WISO).&lt;br /&gt;
Click &#039;&#039;&#039;Add account&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-yubi2.png|center|600px|thumb|Create new TOTP on Yubico Authenticator]]&lt;br /&gt;
&lt;br /&gt;
5. You will receive a six-digit code.&lt;br /&gt;
Enter this code into the field labeled &amp;quot;Current code:&amp;quot; in your bwIDM browser window to prove that the connection has worked and then click &#039;&#039;&#039;CHECK&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-yubi3.png|center|600px|thumb|Verify TOTP]]&lt;br /&gt;
&lt;br /&gt;
6. If everything worked as expected, you will be returned to the &#039;&#039;&#039;My Tokens&#039;&#039;&#039; screen and there will be a new entry for your software token.&lt;br /&gt;
[[File:BwIDM-app.png|center|400px|thumb|Success]]&lt;br /&gt;
&lt;br /&gt;
7. Repeat the process to register additional tokens.&lt;br /&gt;
Please register at least the &amp;quot;Backup TAN list&amp;quot; in addition to the hardware/software token you plan to use regularly.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Backup TAN List ==&lt;br /&gt;
&lt;br /&gt;
{|style=&amp;quot;background:#deffee; width:100%;&amp;quot;&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
[[Image:Attention.svg|center|25px]]&lt;br /&gt;
|style=&amp;quot;padding:5px; background:#cef2e0; text-align:left&amp;quot;|&lt;br /&gt;
Passwords from the &amp;quot;Backup TAN list&amp;quot; should only be used if no other token is left.&lt;br /&gt;
Please do not use the Backup TANs for regular cluster login, because you have only a limited number of TANs.&lt;br /&gt;
Each TAN can only be used once.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
1. Please create at least one &amp;quot;Backup TAN list&amp;quot; by clicking &#039;&#039;&#039;CREATE NEW TAN LIST&#039;&#039;&#039;.&lt;br /&gt;
[[File:BwIDM-token.png|center|600px|thumb|Generate Backup TAN list]]&lt;br /&gt;
&lt;br /&gt;
2. Click &#039;&#039;&#039;START&#039;&#039;&#039;. You will be redirected to the &#039;&#039;&#039;My Tokens&#039;&#039;&#039; screen and there will be a new entry for your backup TANs.&lt;br /&gt;
[[File:BwIDM-tan.png|center|400px|thumb|Success]]&lt;br /&gt;
&lt;br /&gt;
3. Click &#039;&#039;&#039;SHOW TANS&#039;&#039;&#039;, print the codes and keep then in a separate place for emergencies.&lt;br /&gt;
[[File:JUSTUS-2-2FA-backup-TAN-list.png|center|800px|thumb|Print Backup TAN List]]&lt;br /&gt;
&lt;br /&gt;
4. Repeat the process to register additional tokens.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Deactivating a Token ==&lt;br /&gt;
&lt;br /&gt;
Click &#039;&#039;&#039;Disable&#039;&#039;&#039; next to the Token entry on the &#039;&#039;&#039;My Tokens&#039;&#039;&#039; screen.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
== Deleting a Token ==&lt;br /&gt;
&lt;br /&gt;
After a Token has been disabled a new button labeled &#039;&#039;&#039;Delete&#039;&#039;&#039; will appear. Click on it to delete the token.&lt;br /&gt;
&lt;br /&gt;
= Returning Users =&lt;br /&gt;
&lt;br /&gt;
Returning users who have already activated one or more tokens must first verify their token before they can create new tokens or deactivate/delete old ones.&lt;br /&gt;
If you no longer have valid tokens, you will not be able to create or manage tokens. &lt;br /&gt;
In this case, read the section [[Registration/2FA#Lost_Token|Lost Token]].&lt;br /&gt;
[[File:BwIDM-totp.png|center|400px|thumb|Returning users must first verify their token.]]&lt;br /&gt;
&lt;br /&gt;
= Lost Token =&lt;br /&gt;
&lt;br /&gt;
If you have lost a token, please create a new one.&lt;br /&gt;
If you change your phone, please migrate your tokens first or register your new mobile app under &amp;quot;My Tokens&amp;quot;.&lt;br /&gt;
&#039;&#039;&#039;If you no longer have valid tokens (mobile app, hardware token, Yubikey or backup TAN), you will need to contact the [https://bw-support.scc.kit.edu/ ticket system].&#039;&#039;&#039;&lt;br /&gt;
Please note that this process may take some time and also means additional work for the operators.&lt;/div&gt;</summary>
		<author><name>C Mosch</name></author>
	</entry>
	<entry>
		<id>https://wiki.bwhpc.de/wiki/index.php?title=JUSTUS2/Login&amp;diff=9991</id>
		<title>JUSTUS2/Login</title>
		<link rel="alternate" type="text/html" href="https://wiki.bwhpc.de/wiki/index.php?title=JUSTUS2/Login&amp;diff=9991"/>
		<updated>2022-02-10T22:43:00Z</updated>

		<summary type="html">&lt;p&gt;C Mosch: /* Further reading */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
= Login to JUSTUS 2 =&lt;br /&gt;
&lt;br /&gt;
== Prerequisites for login ==&lt;br /&gt;
&lt;br /&gt;
* You have registered your account at the registration server for JUSTUS 2.&lt;br /&gt;
** If this is still missing, then please log in to the [https://wiki.bwhpc.de/e/Registration/bwForCluster/JUSTUS2 registration server of JUSTUS2] and click on &amp;quot;Register&amp;quot; in section &amp;quot;JUSTUS 2&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
* You have set a service password for JUSTUS 2.&lt;br /&gt;
** If you have not done so already, then please log in to the [https://wiki.bwhpc.de/e/Registration/Password registration server of JUSTUS2] and select &amp;quot;Set Password&amp;quot; in section &amp;quot;JUSTUS 2&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
* You have set up a time-based one-time password (TOTP) for the two factor authentication (2FA) log in.&lt;br /&gt;
** If this is still missing, then please follow the instructions for registering a new 2FA token on the following page: [https://wiki.bwhpc.de/e/Registration/2FA BwForCluster User Access/2FA Tokens].&lt;br /&gt;
&lt;br /&gt;
* Your IP is within the IP range of your university. Either you are working on a computer on your campus or you are connected via a virtual private network (VPN) to your university.&lt;br /&gt;
** If you have an external IP (i.e. home office) and you are not connected via VPN to your university, you can not connect to JUSTUS 2. Please consult the documentation of your university how to connect to your university via VPN.&lt;br /&gt;
&lt;br /&gt;
== Login to JUSTUS 2 ==&lt;br /&gt;
&lt;br /&gt;
When all prerequisites are fulfilled you can access the bwForCluster JUSTUS 2 for Computational Chemistry and Quantum Sciences via [[ssh]]. Only the secure shell ssh is allowed for login. &lt;br /&gt;
&lt;br /&gt;
From Linux machines, you can log in using &lt;br /&gt;
&lt;br /&gt;
 ssh &amp;lt;UserID&amp;gt;@justus2.uni-ulm.de&lt;br /&gt;
&lt;br /&gt;
During log in you must enter the current TOTP value (6-digit number) created with help of the TOTP app on your smartphone and your service password.&lt;br /&gt;
&lt;br /&gt;
To run graphical applications, you can use the -X flag to openssh:&lt;br /&gt;
&lt;br /&gt;
 ssh -X &amp;lt;UserID&amp;gt;@justus2.uni-ulm.de&lt;br /&gt;
&lt;br /&gt;
For better performance on slow connections you should use e.g. [[VNC]].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The bwForCluster Chemistry in Ulm  has four dedicated login nodes. The selection of the login node is done automatically. If you are logging in multiple times, different sessions might run &lt;br /&gt;
on different login nodes.&lt;br /&gt;
&lt;br /&gt;
The names of the four login nodes are justus2-login01.rz.uni-ulm.de, justus2-login02.rz.uni-ulm.de, justus2-login03.rz.uni-ulm.de, justus2-login04.rz.uni-ulm.de. &lt;br /&gt;
&lt;br /&gt;
These names can be used to access a specific one of the login nodes. In general, you should use justus2.uni-ulm.de to allow us to balance the load over the four login nodes.&lt;br /&gt;
&lt;br /&gt;
== About UserID / Username ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;UserID&amp;gt; of the ssh command is a placeholder for your username at your home &lt;br /&gt;
organization and a prefix denoting your organization. Prefixes and resulting user names are as follows:&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;border:3px solid darkgray; margin: 5em auto 5em auto;&amp;quot; width=&amp;quot;60%&amp;quot;&lt;br /&gt;
|- &lt;br /&gt;
!scope=&amp;quot;row&amp;quot; {{Darkgray}} |  Site &lt;br /&gt;
!scope=&amp;quot;row&amp;quot; {{Darkgray}}| Prefix&lt;br /&gt;
!scope=&amp;quot;row&amp;quot; {{Darkgray}}|  Username&lt;br /&gt;
|-&lt;br /&gt;
| Freiburg&lt;br /&gt;
| fr&lt;br /&gt;
| fr_username&lt;br /&gt;
|-&lt;br /&gt;
|Heidelberg&lt;br /&gt;
|hd&lt;br /&gt;
|hd_username&lt;br /&gt;
|-&lt;br /&gt;
|Hohenheim&lt;br /&gt;
|ho&lt;br /&gt;
|ho_username&lt;br /&gt;
|-&lt;br /&gt;
|Karlsruhe&lt;br /&gt;
|ka&lt;br /&gt;
|ka_username&lt;br /&gt;
|-&lt;br /&gt;
|Konstanz&lt;br /&gt;
|kn&lt;br /&gt;
|kn_username&lt;br /&gt;
|-&lt;br /&gt;
|Mannheim&lt;br /&gt;
|ma&lt;br /&gt;
|ma_username&lt;br /&gt;
|-&lt;br /&gt;
|Stuttgart&lt;br /&gt;
|st&lt;br /&gt;
|st_username&lt;br /&gt;
|-&lt;br /&gt;
|Tübingen&lt;br /&gt;
|tu&lt;br /&gt;
|tu_username&lt;br /&gt;
|-&lt;br /&gt;
|Ulm&lt;br /&gt;
|ul&lt;br /&gt;
|ul_username&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Allowed activities on login nodes ==&lt;br /&gt;
&lt;br /&gt;
The login nodes are the access point to the compute system and its $HOME directory. The login nodes are shared with all the users of the cluster. Therefore, your activities on the login nodes are limited to primarily set up your batch jobs. Your activities may also be:&lt;br /&gt;
* compilation of your program code and&lt;br /&gt;
* short pre- and postprocessing of your batch jobs.&lt;br /&gt;
&lt;br /&gt;
To guarantee usability for all users of the bwForCluster you must not run your compute jobs on the login nodes. Compute jobs must be submitted as&lt;br /&gt;
[[BwForCluster_JUSTUS_2_Slurm_HOWTO|Batch Jobs]]. Any compute job running on the login nodes will be terminated without any notice.&lt;br /&gt;
&lt;br /&gt;
= Further reading =&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Scientific software is made accessible using the [[Environment Modules]] system&lt;br /&gt;
&lt;br /&gt;
* Compute jobs must be submitted as [[BwForCluster_JUSTUS_2_Slurm_HOWTO|Batch Jobs]]&lt;br /&gt;
&lt;br /&gt;
* Jobs needing disk space will need to request it in their job script. See [[BwForCluster_JUSTUS_2_Slurm_HOWTO#How_to_request_local_scratch_.28SSD.2FNVMe.29_at_job_submission.3F|Batch Jobs - request local scratch]]&lt;br /&gt;
&lt;br /&gt;
* What hardware is available is described in [https://wiki.bwhpc.de/e/Hardware_and_Architecture_(bwForCluster_JUSTUS_2) Hardware and Architecture of bwForCluster JUSTUS 2]&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
[[Category:BwForCluster_JUSTUS_2]][[Category:Access]]&lt;/div&gt;</summary>
		<author><name>C Mosch</name></author>
	</entry>
	<entry>
		<id>https://wiki.bwhpc.de/wiki/index.php?title=JUSTUS2/Login&amp;diff=9990</id>
		<title>JUSTUS2/Login</title>
		<link rel="alternate" type="text/html" href="https://wiki.bwhpc.de/wiki/index.php?title=JUSTUS2/Login&amp;diff=9990"/>
		<updated>2022-02-10T22:41:14Z</updated>

		<summary type="html">&lt;p&gt;C Mosch: /* Prerequisites for login */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
= Login to JUSTUS 2 =&lt;br /&gt;
&lt;br /&gt;
== Prerequisites for login ==&lt;br /&gt;
&lt;br /&gt;
* You have registered your account at the registration server for JUSTUS 2.&lt;br /&gt;
** If this is still missing, then please log in to the [https://wiki.bwhpc.de/e/Registration/bwForCluster/JUSTUS2 registration server of JUSTUS2] and click on &amp;quot;Register&amp;quot; in section &amp;quot;JUSTUS 2&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
* You have set a service password for JUSTUS 2.&lt;br /&gt;
** If you have not done so already, then please log in to the [https://wiki.bwhpc.de/e/Registration/Password registration server of JUSTUS2] and select &amp;quot;Set Password&amp;quot; in section &amp;quot;JUSTUS 2&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
* You have set up a time-based one-time password (TOTP) for the two factor authentication (2FA) log in.&lt;br /&gt;
** If this is still missing, then please follow the instructions for registering a new 2FA token on the following page: [https://wiki.bwhpc.de/e/Registration/2FA BwForCluster User Access/2FA Tokens].&lt;br /&gt;
&lt;br /&gt;
* Your IP is within the IP range of your university. Either you are working on a computer on your campus or you are connected via a virtual private network (VPN) to your university.&lt;br /&gt;
** If you have an external IP (i.e. home office) and you are not connected via VPN to your university, you can not connect to JUSTUS 2. Please consult the documentation of your university how to connect to your university via VPN.&lt;br /&gt;
&lt;br /&gt;
== Login to JUSTUS 2 ==&lt;br /&gt;
&lt;br /&gt;
When all prerequisites are fulfilled you can access the bwForCluster JUSTUS 2 for Computational Chemistry and Quantum Sciences via [[ssh]]. Only the secure shell ssh is allowed for login. &lt;br /&gt;
&lt;br /&gt;
From Linux machines, you can log in using &lt;br /&gt;
&lt;br /&gt;
 ssh &amp;lt;UserID&amp;gt;@justus2.uni-ulm.de&lt;br /&gt;
&lt;br /&gt;
During log in you must enter the current TOTP value (6-digit number) created with help of the TOTP app on your smartphone and your service password.&lt;br /&gt;
&lt;br /&gt;
To run graphical applications, you can use the -X flag to openssh:&lt;br /&gt;
&lt;br /&gt;
 ssh -X &amp;lt;UserID&amp;gt;@justus2.uni-ulm.de&lt;br /&gt;
&lt;br /&gt;
For better performance on slow connections you should use e.g. [[VNC]].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The bwForCluster Chemistry in Ulm  has four dedicated login nodes. The selection of the login node is done automatically. If you are logging in multiple times, different sessions might run &lt;br /&gt;
on different login nodes.&lt;br /&gt;
&lt;br /&gt;
The names of the four login nodes are justus2-login01.rz.uni-ulm.de, justus2-login02.rz.uni-ulm.de, justus2-login03.rz.uni-ulm.de, justus2-login04.rz.uni-ulm.de. &lt;br /&gt;
&lt;br /&gt;
These names can be used to access a specific one of the login nodes. In general, you should use justus2.uni-ulm.de to allow us to balance the load over the four login nodes.&lt;br /&gt;
&lt;br /&gt;
== About UserID / Username ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;UserID&amp;gt; of the ssh command is a placeholder for your username at your home &lt;br /&gt;
organization and a prefix denoting your organization. Prefixes and resulting user names are as follows:&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;border:3px solid darkgray; margin: 5em auto 5em auto;&amp;quot; width=&amp;quot;60%&amp;quot;&lt;br /&gt;
|- &lt;br /&gt;
!scope=&amp;quot;row&amp;quot; {{Darkgray}} |  Site &lt;br /&gt;
!scope=&amp;quot;row&amp;quot; {{Darkgray}}| Prefix&lt;br /&gt;
!scope=&amp;quot;row&amp;quot; {{Darkgray}}|  Username&lt;br /&gt;
|-&lt;br /&gt;
| Freiburg&lt;br /&gt;
| fr&lt;br /&gt;
| fr_username&lt;br /&gt;
|-&lt;br /&gt;
|Heidelberg&lt;br /&gt;
|hd&lt;br /&gt;
|hd_username&lt;br /&gt;
|-&lt;br /&gt;
|Hohenheim&lt;br /&gt;
|ho&lt;br /&gt;
|ho_username&lt;br /&gt;
|-&lt;br /&gt;
|Karlsruhe&lt;br /&gt;
|ka&lt;br /&gt;
|ka_username&lt;br /&gt;
|-&lt;br /&gt;
|Konstanz&lt;br /&gt;
|kn&lt;br /&gt;
|kn_username&lt;br /&gt;
|-&lt;br /&gt;
|Mannheim&lt;br /&gt;
|ma&lt;br /&gt;
|ma_username&lt;br /&gt;
|-&lt;br /&gt;
|Stuttgart&lt;br /&gt;
|st&lt;br /&gt;
|st_username&lt;br /&gt;
|-&lt;br /&gt;
|Tübingen&lt;br /&gt;
|tu&lt;br /&gt;
|tu_username&lt;br /&gt;
|-&lt;br /&gt;
|Ulm&lt;br /&gt;
|ul&lt;br /&gt;
|ul_username&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Allowed activities on login nodes ==&lt;br /&gt;
&lt;br /&gt;
The login nodes are the access point to the compute system and its $HOME directory. The login nodes are shared with all the users of the cluster. Therefore, your activities on the login nodes are limited to primarily set up your batch jobs. Your activities may also be:&lt;br /&gt;
* compilation of your program code and&lt;br /&gt;
* short pre- and postprocessing of your batch jobs.&lt;br /&gt;
&lt;br /&gt;
To guarantee usability for all users of the bwForCluster you must not run your compute jobs on the login nodes. Compute jobs must be submitted as&lt;br /&gt;
[[BwForCluster_JUSTUS_2_Slurm_HOWTO|Batch Jobs]]. Any compute job running on the login nodes will be terminated without any notice.&lt;br /&gt;
&lt;br /&gt;
= Further reading =&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Scientific software is made accessible using the [[Environment Modules]] system&lt;br /&gt;
&lt;br /&gt;
* Compute jobs must be submitted as [[BwForCluster_JUSTUS_2_Slurm_HOWTO|Batch Jobs]]&lt;br /&gt;
&lt;br /&gt;
* Jobs needing disk space will need to request it in their job script. See [[BwForCluster_JUSTUS_2_Slurm_HOWTO#How_to_request_local_scratch_.28SSD.2FNVMe.29_at_job_submission.3F|Batch Jobs - request local scratch]]&lt;br /&gt;
&lt;br /&gt;
* What hardware is available is described in [[Hardware and Architecture (bwForCluster JUSTUS 2]]&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
[[Category:BwForCluster_JUSTUS_2]][[Category:Access]]&lt;/div&gt;</summary>
		<author><name>C Mosch</name></author>
	</entry>
	<entry>
		<id>https://wiki.bwhpc.de/wiki/index.php?title=JUSTUS2/Login&amp;diff=9989</id>
		<title>JUSTUS2/Login</title>
		<link rel="alternate" type="text/html" href="https://wiki.bwhpc.de/wiki/index.php?title=JUSTUS2/Login&amp;diff=9989"/>
		<updated>2022-02-10T22:39:39Z</updated>

		<summary type="html">&lt;p&gt;C Mosch: /* Prerequisites for login */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
= Login to JUSTUS 2 =&lt;br /&gt;
&lt;br /&gt;
== Prerequisites for login ==&lt;br /&gt;
&lt;br /&gt;
* You have registered your account at the registration server for JUSTUS 2.&lt;br /&gt;
** If this is still missing, then please log in to the [https://wiki.bwhpc.de/e/Registration/bwForCluster/JUSTUS2 registration server of JUSTUS2] and click on &amp;quot;Register&amp;quot; in section &amp;quot;JUSTUS 2&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
* You have set a service password for JUSTUS 2.&lt;br /&gt;
** If you have not done so already, then please log in to the [https://wiki.bwhpc.de/e/Registration/Password registration server of JUSTUS2] and select &amp;quot;Set Password&amp;quot; in section &amp;quot;JUSTUS 2&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
* You have set up a time-based one-time password (TOTP) for the two factor authentication (2FA) log in.&lt;br /&gt;
** If this is still missing, then please follow the instructions for registering a new 2FA token on the following page: [[BwForCluster User Access/2FA Tokens]].&lt;br /&gt;
&lt;br /&gt;
* Your IP is within the IP range of your university. Either you are working on a computer on your campus or you are connected via a virtual private network (VPN) to your university.&lt;br /&gt;
** If you have an external IP (i.e. home office) and you are not connected via VPN to your university, you can not connect to JUSTUS 2. Please consult the documentation of your university how to connect to your university via VPN.&lt;br /&gt;
&lt;br /&gt;
== Login to JUSTUS 2 ==&lt;br /&gt;
&lt;br /&gt;
When all prerequisites are fulfilled you can access the bwForCluster JUSTUS 2 for Computational Chemistry and Quantum Sciences via [[ssh]]. Only the secure shell ssh is allowed for login. &lt;br /&gt;
&lt;br /&gt;
From Linux machines, you can log in using &lt;br /&gt;
&lt;br /&gt;
 ssh &amp;lt;UserID&amp;gt;@justus2.uni-ulm.de&lt;br /&gt;
&lt;br /&gt;
During log in you must enter the current TOTP value (6-digit number) created with help of the TOTP app on your smartphone and your service password.&lt;br /&gt;
&lt;br /&gt;
To run graphical applications, you can use the -X flag to openssh:&lt;br /&gt;
&lt;br /&gt;
 ssh -X &amp;lt;UserID&amp;gt;@justus2.uni-ulm.de&lt;br /&gt;
&lt;br /&gt;
For better performance on slow connections you should use e.g. [[VNC]].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The bwForCluster Chemistry in Ulm  has four dedicated login nodes. The selection of the login node is done automatically. If you are logging in multiple times, different sessions might run &lt;br /&gt;
on different login nodes.&lt;br /&gt;
&lt;br /&gt;
The names of the four login nodes are justus2-login01.rz.uni-ulm.de, justus2-login02.rz.uni-ulm.de, justus2-login03.rz.uni-ulm.de, justus2-login04.rz.uni-ulm.de. &lt;br /&gt;
&lt;br /&gt;
These names can be used to access a specific one of the login nodes. In general, you should use justus2.uni-ulm.de to allow us to balance the load over the four login nodes.&lt;br /&gt;
&lt;br /&gt;
== About UserID / Username ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;UserID&amp;gt; of the ssh command is a placeholder for your username at your home &lt;br /&gt;
organization and a prefix denoting your organization. Prefixes and resulting user names are as follows:&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;border:3px solid darkgray; margin: 5em auto 5em auto;&amp;quot; width=&amp;quot;60%&amp;quot;&lt;br /&gt;
|- &lt;br /&gt;
!scope=&amp;quot;row&amp;quot; {{Darkgray}} |  Site &lt;br /&gt;
!scope=&amp;quot;row&amp;quot; {{Darkgray}}| Prefix&lt;br /&gt;
!scope=&amp;quot;row&amp;quot; {{Darkgray}}|  Username&lt;br /&gt;
|-&lt;br /&gt;
| Freiburg&lt;br /&gt;
| fr&lt;br /&gt;
| fr_username&lt;br /&gt;
|-&lt;br /&gt;
|Heidelberg&lt;br /&gt;
|hd&lt;br /&gt;
|hd_username&lt;br /&gt;
|-&lt;br /&gt;
|Hohenheim&lt;br /&gt;
|ho&lt;br /&gt;
|ho_username&lt;br /&gt;
|-&lt;br /&gt;
|Karlsruhe&lt;br /&gt;
|ka&lt;br /&gt;
|ka_username&lt;br /&gt;
|-&lt;br /&gt;
|Konstanz&lt;br /&gt;
|kn&lt;br /&gt;
|kn_username&lt;br /&gt;
|-&lt;br /&gt;
|Mannheim&lt;br /&gt;
|ma&lt;br /&gt;
|ma_username&lt;br /&gt;
|-&lt;br /&gt;
|Stuttgart&lt;br /&gt;
|st&lt;br /&gt;
|st_username&lt;br /&gt;
|-&lt;br /&gt;
|Tübingen&lt;br /&gt;
|tu&lt;br /&gt;
|tu_username&lt;br /&gt;
|-&lt;br /&gt;
|Ulm&lt;br /&gt;
|ul&lt;br /&gt;
|ul_username&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Allowed activities on login nodes ==&lt;br /&gt;
&lt;br /&gt;
The login nodes are the access point to the compute system and its $HOME directory. The login nodes are shared with all the users of the cluster. Therefore, your activities on the login nodes are limited to primarily set up your batch jobs. Your activities may also be:&lt;br /&gt;
* compilation of your program code and&lt;br /&gt;
* short pre- and postprocessing of your batch jobs.&lt;br /&gt;
&lt;br /&gt;
To guarantee usability for all users of the bwForCluster you must not run your compute jobs on the login nodes. Compute jobs must be submitted as&lt;br /&gt;
[[BwForCluster_JUSTUS_2_Slurm_HOWTO|Batch Jobs]]. Any compute job running on the login nodes will be terminated without any notice.&lt;br /&gt;
&lt;br /&gt;
= Further reading =&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Scientific software is made accessible using the [[Environment Modules]] system&lt;br /&gt;
&lt;br /&gt;
* Compute jobs must be submitted as [[BwForCluster_JUSTUS_2_Slurm_HOWTO|Batch Jobs]]&lt;br /&gt;
&lt;br /&gt;
* Jobs needing disk space will need to request it in their job script. See [[BwForCluster_JUSTUS_2_Slurm_HOWTO#How_to_request_local_scratch_.28SSD.2FNVMe.29_at_job_submission.3F|Batch Jobs - request local scratch]]&lt;br /&gt;
&lt;br /&gt;
* What hardware is available is described in [[Hardware and Architecture (bwForCluster JUSTUS 2]]&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
[[Category:BwForCluster_JUSTUS_2]][[Category:Access]]&lt;/div&gt;</summary>
		<author><name>C Mosch</name></author>
	</entry>
	<entry>
		<id>https://wiki.bwhpc.de/wiki/index.php?title=JUSTUS2/Login&amp;diff=9988</id>
		<title>JUSTUS2/Login</title>
		<link rel="alternate" type="text/html" href="https://wiki.bwhpc.de/wiki/index.php?title=JUSTUS2/Login&amp;diff=9988"/>
		<updated>2022-02-10T22:37:48Z</updated>

		<summary type="html">&lt;p&gt;C Mosch: /* Prerequisites for login */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;br /&gt;
= Login to JUSTUS 2 =&lt;br /&gt;
&lt;br /&gt;
== Prerequisites for login ==&lt;br /&gt;
&lt;br /&gt;
* You have registered your account at the registration server for JUSTUS 2.&lt;br /&gt;
** If this is still missing, then please log in to the [https://wiki.bwhpc.de/e/Registration/bwForCluster/JUSTUS2 registration server of JUSTUS2] and click on &amp;quot;Register&amp;quot; in section &amp;quot;JUSTUS 2&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
* You have set a service password for JUSTUS 2.&lt;br /&gt;
** If you have not done so already, then please log in to the [https://wiki.bwhpc.de/e/BwForCluster_User_Access#Personal_registration_at_a_bwForCluster_-_account_creation registration server of JUSTUS2] and select &amp;quot;Set Password&amp;quot; in section &amp;quot;JUSTUS 2&amp;quot;.&lt;br /&gt;
&lt;br /&gt;
* You have set up a time-based one-time password (TOTP) for the two factor authentication (2FA) log in.&lt;br /&gt;
** If this is still missing, then please follow the instructions for registering a new 2FA token on the following page: [[BwForCluster User Access/2FA Tokens]].&lt;br /&gt;
&lt;br /&gt;
* Your IP is within the IP range of your university. Either you are working on a computer on your campus or you are connected via a virtual private network (VPN) to your university.&lt;br /&gt;
** If you have an external IP (i.e. home office) and you are not connected via VPN to your university, you can not connect to JUSTUS 2. Please consult the documentation of your university how to connect to your university via VPN.&lt;br /&gt;
&lt;br /&gt;
== Login to JUSTUS 2 ==&lt;br /&gt;
&lt;br /&gt;
When all prerequisites are fulfilled you can access the bwForCluster JUSTUS 2 for Computational Chemistry and Quantum Sciences via [[ssh]]. Only the secure shell ssh is allowed for login. &lt;br /&gt;
&lt;br /&gt;
From Linux machines, you can log in using &lt;br /&gt;
&lt;br /&gt;
 ssh &amp;lt;UserID&amp;gt;@justus2.uni-ulm.de&lt;br /&gt;
&lt;br /&gt;
During log in you must enter the current TOTP value (6-digit number) created with help of the TOTP app on your smartphone and your service password.&lt;br /&gt;
&lt;br /&gt;
To run graphical applications, you can use the -X flag to openssh:&lt;br /&gt;
&lt;br /&gt;
 ssh -X &amp;lt;UserID&amp;gt;@justus2.uni-ulm.de&lt;br /&gt;
&lt;br /&gt;
For better performance on slow connections you should use e.g. [[VNC]].&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
The bwForCluster Chemistry in Ulm  has four dedicated login nodes. The selection of the login node is done automatically. If you are logging in multiple times, different sessions might run &lt;br /&gt;
on different login nodes.&lt;br /&gt;
&lt;br /&gt;
The names of the four login nodes are justus2-login01.rz.uni-ulm.de, justus2-login02.rz.uni-ulm.de, justus2-login03.rz.uni-ulm.de, justus2-login04.rz.uni-ulm.de. &lt;br /&gt;
&lt;br /&gt;
These names can be used to access a specific one of the login nodes. In general, you should use justus2.uni-ulm.de to allow us to balance the load over the four login nodes.&lt;br /&gt;
&lt;br /&gt;
== About UserID / Username ==&lt;br /&gt;
&lt;br /&gt;
&amp;lt;UserID&amp;gt; of the ssh command is a placeholder for your username at your home &lt;br /&gt;
organization and a prefix denoting your organization. Prefixes and resulting user names are as follows:&lt;br /&gt;
&lt;br /&gt;
{| style=&amp;quot;border:3px solid darkgray; margin: 5em auto 5em auto;&amp;quot; width=&amp;quot;60%&amp;quot;&lt;br /&gt;
|- &lt;br /&gt;
!scope=&amp;quot;row&amp;quot; {{Darkgray}} |  Site &lt;br /&gt;
!scope=&amp;quot;row&amp;quot; {{Darkgray}}| Prefix&lt;br /&gt;
!scope=&amp;quot;row&amp;quot; {{Darkgray}}|  Username&lt;br /&gt;
|-&lt;br /&gt;
| Freiburg&lt;br /&gt;
| fr&lt;br /&gt;
| fr_username&lt;br /&gt;
|-&lt;br /&gt;
|Heidelberg&lt;br /&gt;
|hd&lt;br /&gt;
|hd_username&lt;br /&gt;
|-&lt;br /&gt;
|Hohenheim&lt;br /&gt;
|ho&lt;br /&gt;
|ho_username&lt;br /&gt;
|-&lt;br /&gt;
|Karlsruhe&lt;br /&gt;
|ka&lt;br /&gt;
|ka_username&lt;br /&gt;
|-&lt;br /&gt;
|Konstanz&lt;br /&gt;
|kn&lt;br /&gt;
|kn_username&lt;br /&gt;
|-&lt;br /&gt;
|Mannheim&lt;br /&gt;
|ma&lt;br /&gt;
|ma_username&lt;br /&gt;
|-&lt;br /&gt;
|Stuttgart&lt;br /&gt;
|st&lt;br /&gt;
|st_username&lt;br /&gt;
|-&lt;br /&gt;
|Tübingen&lt;br /&gt;
|tu&lt;br /&gt;
|tu_username&lt;br /&gt;
|-&lt;br /&gt;
|Ulm&lt;br /&gt;
|ul&lt;br /&gt;
|ul_username&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
== Allowed activities on login nodes ==&lt;br /&gt;
&lt;br /&gt;
The login nodes are the access point to the compute system and its $HOME directory. The login nodes are shared with all the users of the cluster. Therefore, your activities on the login nodes are limited to primarily set up your batch jobs. Your activities may also be:&lt;br /&gt;
* compilation of your program code and&lt;br /&gt;
* short pre- and postprocessing of your batch jobs.&lt;br /&gt;
&lt;br /&gt;
To guarantee usability for all users of the bwForCluster you must not run your compute jobs on the login nodes. Compute jobs must be submitted as&lt;br /&gt;
[[BwForCluster_JUSTUS_2_Slurm_HOWTO|Batch Jobs]]. Any compute job running on the login nodes will be terminated without any notice.&lt;br /&gt;
&lt;br /&gt;
= Further reading =&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
* Scientific software is made accessible using the [[Environment Modules]] system&lt;br /&gt;
&lt;br /&gt;
* Compute jobs must be submitted as [[BwForCluster_JUSTUS_2_Slurm_HOWTO|Batch Jobs]]&lt;br /&gt;
&lt;br /&gt;
* Jobs needing disk space will need to request it in their job script. See [[BwForCluster_JUSTUS_2_Slurm_HOWTO#How_to_request_local_scratch_.28SSD.2FNVMe.29_at_job_submission.3F|Batch Jobs - request local scratch]]&lt;br /&gt;
&lt;br /&gt;
* What hardware is available is described in [[Hardware and Architecture (bwForCluster JUSTUS 2]]&lt;br /&gt;
&lt;br /&gt;
----&lt;br /&gt;
[[Category:BwForCluster_JUSTUS_2]][[Category:Access]]&lt;/div&gt;</summary>
		<author><name>C Mosch</name></author>
	</entry>
</feed>