Skip to content

Commit 4d7ebeb

Browse files
rkronbergnyholmju
andauthored
MFA update (#2612)
* WIP MFA update * fix links * update web interfaces instructions * typo --------- Co-authored-by: Juha Nyholm <[email protected]>
1 parent 6b26c2a commit 4d7ebeb

File tree

8 files changed

+29
-56
lines changed

8 files changed

+29
-56
lines changed

csc-overrides/assets/snippets/mfa-update.md

Lines changed: 2 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,5 @@
22
Since 22 April 2025, the web interfaces of Puhti and Mahti require
33
multi-factor authentication (MFA).
44

5-
1. [Test whether **Haka MFA** is already enabled for you](/accounts/mfa.md#mfa-instructions-for-users-logging-in-with-haka-credentials).
6-
* If your home organization has enabled MFA for Haka login, you do not need to activate MFA separately for CSC services. It is highly preferred that you use the Haka MFA of your home organization if possible.
7-
2. [If Haka MFA is not enabled or if your home organization does not offer Haka, activate **CSC MFA** following these instructions](/accounts/mfa.md#how-to-activate-mfa).
5+
1. If your home organization has enabled MFA for Haka login, you do not need to activate MFA separately for CSC services. It is highly preferred that you use the Haka MFA of your home organization if possible.
6+
2. If Haka MFA is not enabled or if your home organization does not offer Haka, [activate **CSC MFA** following these instructions](/accounts/mfa.md#how-to-activate-csc-mfa).

docs/accounts/how-to-create-new-user-account.md

Lines changed: 6 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -5,8 +5,7 @@ search:
55

66
# How to create new CSC user account
77

8-
There are two different types of CSC user accounts: ordinary accounts for general use (which you can get with or
9-
without Haka or Virtu) and machine-to-machine robot accounts for managing services.
8+
There are two different types of CSC user accounts: ordinary accounts for general use (which you can get with or without Haka or Virtu) and machine-to-machine robot accounts for managing services.
109

1110
!!! Note
1211

@@ -20,17 +19,16 @@ without Haka or Virtu) and machine-to-machine robot accounts for managing servic
2019
If you are trying to access the [LUMI web interface](https://www.lumi.csc.fi) or [LUMI-O](https://www.auth.lumidata.eu),
2120
please see the [LUMI documentation](https://docs.lumi-supercomputer.eu/firststeps/accessLUMI/) on how to get an account.
2221

23-
If your home organization is a member of the Haka or Virtu federation, you
24-
can create an account yourself.
22+
If your home organization is a member of the Haka or Virtu federation, you can create an account yourself. For registration, you will need a mobile device that has an authentication app for setting up the multi-factor authentication
2523

2624
1. Go to [MyCSC](http://my.csc.fi).
27-
1. Click _Log in_ or _Getting started_.
28-
1. Click _Virtu_ or _Haka_ depending on which federation your home
29-
organization is a member of.
25+
1. Click _Create account_
26+
1. Click _Virtu_ or _Haka_ depending on which federation your home organization is a member of.
3027
1. Select your home organization and log in to their identity service.
3128
1. Fill in your information on the _Sign up_ page.
3229
1. You will receive an email message containing a link to MyCSC where you can set your CSC account password.
33-
1. You will receive your CSC user account information via email.
30+
1. If you are signing up with _Virtu_ you will be prompted to [set up your CSC MFA](../accounts/mfa.md#step-2-scan-qr-code) after setting your CSC accounts password. If you are signing up with _Haka_, you might already have a working MFA login integrated with your Haka login, and you will be asked to sign in with the Haka MFA. If your home organisation doesn't provide Haka MFA, you will be guided to set up CSC MFA.
31+
1. You will receive a confirmation via email after successfully registering your CSC user account.
3432

3533
## Getting an account without Haka or Virtu
3634

Loading
-67.6 KB
Loading

docs/accounts/mfa.md

Lines changed: 17 additions & 37 deletions
Original file line numberDiff line numberDiff line change
@@ -12,35 +12,23 @@ CSC’s MFA uses a time-based one-time passcode (TOTP) system, which works with
1212

1313
If your home organization has enabled multi-factor authentication for Haka login, you do not need to activate it separately for CSC services. **It is recommended to use your home organization’s Haka authentication if available.**
1414

15-
Otherwise, you must activate MFA once to access CSC research services.
15+
Otherwise, you must [enable CSC provided multi-factor authentication (CSC MFA)](#how-to-activate-csc-mfa) to access CSC services for research.
1616

1717
CSC is gradually rolling out MFA across all of our services. Currently, the following CSC services utilize multi-factor authentication:
1818

1919
* **SD Connect**
2020
* **SD Desktop**
2121
* **Puhti web interface**
2222
* **Mahti web interface**
23-
* Coming soon:
24-
* **MyCSC**
23+
* **MyCSC**
2524

2625
## MFA Instructions for users logging in with Haka credentials
2726

28-
Your home organization may already offer multi-factor authentication during the Haka login process (Haka MFA). We recommend using your home organization's multi-factor authentication, if available. Note that when logging in with CSC user name and password in the web interface, the MyCSC MFA will always be used. Both home organization MFA and the MyCSC MFA can be set up at the same time.
29-
30-
Please first check if you already have functioning Haka MFA. To check:
31-
32-
1. Visit the 'Profile' section of the [MyCSC portal](https://my.csc.fi/)
33-
2. Use the 'Test your Multi-Factor Authentication capabilities' function on the right-hand side by pressing 'Test'. **Remember to log in with Haka during the test**.
34-
35-
### Possible outcomes
36-
37-
* Haka MFA is working. In that case no further action is required from you.
38-
* Haka MFA is **not** working, and you receive an error message indicating that you need to activate Haka MFA following your home organization's instructions. CSC doesn't handle issues related to Haka MFA, for this matter, please contact your **home organization**.
39-
* Haka MFA is not working, and you receive a message stating that Haka MFA is not enabled in your organization. In that case you should activate CSC multi-factor authentication (CSC MFA). [See instructions below](#how-to-activate-mfa).
27+
Your home organization may already offer multi-factor authentication during the Haka login process (Haka MFA). We recommend using your home organization's multi-factor authentication, if available. Note that when logging in with CSC user name and password in the web interface, CSC MFA will always be used. Both home organization MFA and CSC MFA can be set up at the same time.
4028

4129
## Users logging in with Virtu credentials, CSC login or Lifescience login
4230

43-
Activate CSC's multi-factor authentication (CSC MFA) in MyCSC. [See instructions below](#how-to-activate-mfa).
31+
Activate CSC MFA in MyCSC. [See instructions below](#how-to-activate-csc-mfa).
4432

4533
## What you need before setting up CSC MFA
4634

@@ -49,11 +37,11 @@ Before enabling MFA, make sure you have:
4937
* A CSC user account and password. If you don’t have an account yet, register through the MyCSC customer portal. [Read the instructions here](how-to-create-new-user-account.md).
5038
* A mobile device that is compatible with an authentication app (essentially any modern smartphone).
5139

52-
## How to activate MFA
40+
## How to activate CSC MFA
5341

54-
### Step 1: Install authentication app
42+
### Prerequisite: Install authentication app
5543

56-
To use MFA, install **an authentication app** on your mobile phone. **If you already have an authentication app on your phone, [skip to step 2](#step-2-log-in-to-mycsc).**
44+
To use CSC MFA, install **an authentication app** on your mobile phone. **If you already have an authentication app on your phone, [skip to step 1](#step-1-log-in-to-the-csc-mfa-activation-page-in-mycsc).**
5745

5846
Some commonly used apps include:
5947

@@ -63,35 +51,27 @@ Some commonly used apps include:
6351

6452
Follow the installation instructions provided by your chosen app.
6553

66-
### Step 2: Log in to MyCSC
67-
68-
Log in to the [**MyCSC**](https://my.csc.fi/) website with your username and password, and click the **Profile** icon in the top right corner of the page. A dropdown menu will open, allowing you to select **Profile** (highlighted in the image below).
54+
### Step 1: Log in to the CSC MFA activation page in MyCSC
6955

70-
![Profile view in MyCSC](images/small/mfa-profile-banner.png 'Profile view banner')
56+
Open the [**CSC MFA activation page**](https://my.csc.fi/mfa-activation-login) in your web browser and log in using your preferred login method (Haka, Virtu or CSC login).
7157

72-
If you have forgotten your CSC user account password, [**here's how you can change it**](../accounts/how-to-change-password.md).
58+
If you are using CSC login and have forgotten your CSC user account password, [**here's how you can change it**](../accounts/how-to-change-password.md).
7359

74-
### Step 3: Start the activation of multi-factor authentication
75-
76-
In the **Profile** section, click **Enable** in the Multi-Factor Authentication banner.
77-
78-
![enable MFA banner](images/small/mfa-enable-mfa-banner.png 'Multi-factor authentication banner')
79-
80-
### Step 4: Scan QR code
60+
### Step 2: Scan QR code
8161

8262
Scan the QR code displayed on the screen using your authentication app.
8363

84-
![read QR code](images/small/mfa-scan-qr-code.png 'Read the QR.code')
64+
![scan QR code](images/small/mfa-scan-qr-code.png 'Scan the QR code')
8565

86-
### Step 5: Enter verification code
66+
### Step 3: Enter verification code
8767

88-
After scanning the QR code, press **Continue**. Complete the task that your authentication app requires. Once the task is completed, **your MFA setup is complete.**
89-
90-
![type in 6-digit code](images/small/mfa-enter-verification-code.png 'Type in 6-digit code')
68+
Complete the task that your authentication app requires. Once the task is completed, **fill in the verification code from your authentication app** in the input field on the CSC MFA activation page and click the **Enable Multi-Factor Auhtentication** button.
9169

9270
![authentication app screen](images/small/haka-one-time-code.jpeg 'The 6-digit code on your phone')
9371

94-
### Step 6: Finish
72+
![fill in 6-digit code](images/small/mfa-enter-verification-code.png 'Fill in 6-digit code')
73+
74+
### Step 4: Finish
9575

9676
Your CSC account is now secured with multi-factor authentication!
9777

docs/computing/webinterface/connecting.md

Lines changed: 2 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -2,12 +2,8 @@
22

33
--8<-- "mfa-update.md"
44

5-
1. Ensure that you have a CSC account and have enabled multi-factor
6-
authentication (MFA):
7-
1. Haka users:
8-
[Check if Haka MFA is already enabled by your organization](../../accounts/mfa.md#mfa-instructions-for-users-logging-in-with-haka-credentials).
9-
2. If Haka MFA is not enabled, or you do not have Haka credentials:
10-
[Activate CSC MFA](../../accounts/mfa.md#how-to-activate-mfa).
5+
1. Ensure that you have a CSC account:
6+
* [Instructions for creating a new CSC user account](../../accounts/how-to-create-new-user-account.md).
117
2. Using a web browser, go to [www.puhti.csc.fi](https://www.puhti.csc.fi) or
128
[www.mahti.csc.fi](https://www.mahti.csc.fi).
139
3. On the landing page, click on "Log in" and select an appropriate

docs/support/faq/issues-with-mfa.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -15,4 +15,4 @@ To solve the problem:
1515
2. If the previous step does not work, please delete the CSC MFA secret from
1616
your phone and start from the very beginning, including scanning the QR
1717
code (i.e. reset MFA completely).
18-
1. [See instructions](../../accounts/mfa.md#how-to-activate-mfa).
18+
1. [See instructions](../../accounts/mfa.md#how-to-activate-csc-mfa).

docs/support/wn/comp-new.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -48,7 +48,7 @@ required to
4848
organization. [Please use the test page in MyCSC](https://my.csc.fi/test-mfa)
4949
(select **Haka MFA**). It is highly preferred to use the Haka MFA of your home organization, if possible.
5050
If Haka MFA is not enabled or if your home organization does not offer Haka,
51-
[please activate **CSC MFA** following these instructions](../../accounts/mfa.md#how-to-activate-mfa).
51+
[please activate **CSC MFA** following these instructions](../../accounts/mfa.md#how-to-activate-csc-mfa).
5252

5353
**Motivation:** With this change we are improving the security of our
5454
computing, data, and cloud services.

0 commit comments

Comments
 (0)