Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Password

...

Reset

...

for

...

Site

...

Administrators

{:=}{info} [Reset My Password|https://service1.internet2.edu/siteadmin/password_reset] *now*! (or [watch a flash video demo|http://www.incommon.org/v/pw_reset/]) {info}{div} InCommon Operations supports automated _two-factor password reset_ for site administrators. The first factor involves an email account (“something you know”) while the second factor involves a phone (“something you have”). Watch a [video demo|http://www.incommon.org/v/pw_reset/] of two-factor password reset in action. In the future, InCommon will also require _two-factor authentication_ on your login account itself. Together, two-factor authentication and two-factor password reset make it very difficult for a bad guy to gain control of your login credentials. {note}Two-factor password reset and two-factor authentication are being deployed in phases. Two-factor password reset is available now. Two-factor authentication will be available early in 2013.{note} When you initially registered as a site administrator, InCommon Operations verified your trusted email address and your trusted phone number, both of which were obtained from your Executive when your organization joined InCommon. This information is used for the purposes of two-factor password reset. It is all you need to reset your password. To reset your password, follow these steps: # To begin the password reset process, click this link: [https://service1.internet2.edu/siteadmin/password_reset] # Enter your email address at the prompt. # The system sends a custom link via an email message to your trusted email address. # Click the link in the email message to launch a secure landing page in a browser window. # The system sends a five-digit PIN via an automated phone call to your trusted phone number. # Enter the PIN on the web page to authorize a password reset. # If the password reset attempt is successful, you will receive an email notification. Please report any problems or make suggestions for improvement by emailing admin@incommon.org h3. How It Works The process of clicking a link in an email message is actually a type of federated login. Specifically, we implement a protocol called _Simple Authentication for the Web_ \[[1|#refs]\] or SAW. You have probably used a form of SAW to reset a password at one time or another. It is the most common method of password reset in existence today. By itself, however, SAW is only as strong as the email account it depends on. The [Duo Verify API|http://www.duosecurity.com/docs/duoverify] is used to generate the one-time password (OTP) sent to your phone. The system sends an OTP in a recorded voice message. (Duo Verify also has the ability to send an OTP via SMS to a mobile phone but the password reset app doesn't support that yet.) Used together, SAW and Duo Verify provide strong password reset capabilities. h3. Password Policy Currently, every site administrator is issued a strong password for authentication purposes. This password consists of a minimum of ten (10) alphanumeric characters. If you forget or lose your password, you can reset it yourself using the above automated process. If your trusted email address or trusted phone number changes, talk to your Executive. Only your InCommon Executive may change your contact information. {anchor:refs} h3. References \[1\] T. W. van der Horst and K. E. Seamons, “Simple Authentication for the Web,” in _Intl. Conf. on Security and Privacy in Communications Networks_, 2007, pp. 473–482. [http://www.ucrec.org/pubs/upload/836_van%20der%20Horst2008.pdf]
Div
style
float:right
;margin-left:2em;margin-bottom:1ex
Note

Reset My Login Password now!
(or watch a flash video demo)

InCommon Operations supports automated two-factor password reset for site administrators. The first factor involves an email account (“something you know”) while the second factor involves a phone (“something you have”). Watch a video demo of two-factor password reset in action.

As a new site administrator, InCommon Operations verified your email address and your phone number, both of which were obtained from your Executive when your organization joined InCommon. This information is used for the purposes of two-factor password reset as well. It is all you need to reset your password.

Tip

If your verified email address or verified phone number changes, talk to your Executive. Only your InCommon Executive may change your contact information.

To reset your login password, sit at your verified phone location and follow these steps:

  1. To begin the password reset process, click the link in the upper righthand corner of this document.
  2. Perform two-step identity verification:
    1. Request an email invitation by entering your email address at the prompt and pressing the button (screen shot)
    2. Click the link in the email to launch a secure landing page in a browser window (screen shot)
    3. Request an one-time PIN by pressing a button that sends a PIN via an automated voice message to your phone number (screen shot)
    4. Verify the one-time PIN by entering it on the web page and pressing the button (screen shot)
  3. Create a new password: (screen shot)
    1. Enter a new password at the prompt
    2. Confirm the new password at the second prompt
    3. Submit the new password by pressing a button

That's it! You are now ready to log into the Federation Manager.

Please report any problems or make suggestions for improvement by contacting admin at incommon dot org

Password Policy

Currently, every site administrator is issued a strong password for authentication purposes. If you forget or lose your login password, you can reset it yourself using the above automated process. If you are unable to reset your password for any reason, please contact us at admin at incommon dot org.

The level of assurance associated with your email password is unknown and so we have the following policy regarding your login password:

Warning
titleInCommon Operations Password Policy
  • Your login password SHOULD be different than your email password.

Attachments