The Incommon Federation wiki has moved.

Please visit the new InCommon Federation Library wiki for updated content. Remember to update your bookmarks.

Click in the link above if you are not automatically redirected in 15 seconds.



You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 5 Next »

Password Reset for Site Administrators

InCommon Operations supports automated two-factor password reset for site administrators. The first factor involves an email account (“something you know”) while the second factor involves a phone (“something you have”).

Watch a video demo (flash) of two-factor password reset in action.

In the future, InCommon will also provide two-factor authentication on your login account itself. Together, two-factor authentication and two-factor password reset make it very difficult for a bad guy to gain control of your login credentials.

Two-factor password reset and two-factor authentication are being deployed in phases. Two-factor password reset is available now. Two-factor authentication will be available early in 2013.

When you initially registered as a site administrator, InCommon Operations verified your trusted email address and your trusted phone number, both of which were obtained from your Executive when your organization joined InCommon. This information is used for the purposes of two-factor password reset. It is all you need to reset your password.

To reset your password, follow these steps:

  1. To begin the password reset process, follow this link: TBD
  2. Enter your fully qualified username at the prompt.
  3. The system sends a custom link via an email message to the trusted email address associated with the entered username.
  4. Click the link in the email message to launch a secure landing page in a browser window.
  5. The system sends a five-digit PIN via an automated phone call to your trusted phone number.
  6. Enter the PIN on the web page to authorize a password reset.
  7. If the password reset attempt is successful, you will receive an email notification.

Please report any problems or make suggestions for improvement by emailing admin@incommon.org

How It Works

The process of clicking a link in an email message is actually a type of federated login. Specifically, we implement a protocol called Simple Authentication for the Web [1] or SAW. You have probably used a form of SAW to reset a password at one time or another. It is the most common method of password reset in existence today. By itself, however, SAW is only as strong as the email account it depends on.

The Duo Verify API is used to generate the one-time password (OTP) sent to your phone. The system sends an OTP in a recorded voice message. (Duo Verify also has the ability to send an OTP via SMS to a mobile phone but the password reset app doesn't support that yet.)

Used together, SAW and Duo Verify provide strong password reset capabilities.

Password Policy

Currently, every site administrator is issued a strong password for authentication purposes. This password consists of a minimum of ten (10) alphanumeric characters. If you forget or lose your password, you can reset it yourself using the above automated process.

If your trusted email address or trusted phone number changes, talk to your Executive. Only your InCommon Executive may change your contact information.

References

[1] T. W. van der Horst and K. E. Seamons, “Simple Authentication for the Web,” in Intl. Conf. on Security and Privacy in Communications Networks, 2007, pp. 473–482. http://www.ucrec.org/pubs/upload/836_van%20der%20Horst2008.pdf

#trackbackRdf ($trackbackUtils.getContentIdentifier($page) $page.title $trackbackUtils.getPingUrl($page))
  • No labels