See below for enforcing two-factor authentication in Vault for Secrets.
Enforcing two-factor authentication for the current user
See below for enforcing two-factor authentication for the current user.
To enforce two-factor authentication for the current user
- Log in to the Cryptographic Security Platform Vault for Secrets webGUI.
- In the top menu bar, click Settings.
- In the Two-Factor Authentication field, click Set up Two-Factor Authentication.
In the Enable Two-Factor dialog box, select the HOTP or TOTP radio button.
- Scan the generated barcode with your authorization app.
- Enter the six-digit verification code from your app in the dialog box.
- Click Continue. Cryptographic Security Platform Vault verifies the code and displays a message indicating success or failure. If the code is not correct, re-enter it.
- After the code has been accepted, click Done.
When you log into the Vault web GUI:
Enter a valid OTP along with your standard account password on the login page. Do not add any characters or spaces between your account password and the one-time password generated by your authorization app. For example, if your password is
XyZ123$, and your OTP is32325, you enterXyZ123$32325in the password field.- If you use TOTP, make sure your password doesn't expire before you submit the login request.
Enforcing two-factor authentication for all users
See below for enforcing two-factor authentication for all Vault users
To enforce two-factor authentication for all users
- Log into the Vault web GUI using an account with Security Admin privileges.
- In the top menu bar, click Settings.
- In the System Settings section, click Two-Factor Authentication Settings.
- On the Two-Factor Authentication Settings page, select ENFORCED.
- Click Apply.