Table of Contents

Using Multi-factor Authentication with TSM/ISP

This HowTo only covers the use of the IBM Security Verify app and respectively for the required QR code the generator from FreeOTP, other TOTP apps and QR generators will work similarly.

Preparation

Creating a QR code using FreeOTP.github.io

Create admin accounts with MFA / enable MFA for admin accountsr

Use the base32string next to the Random button as Shared Secret when creating / changing the TSM admin account:

REGister Admin <NAME> <password> [other options] MFARequired=Yes SHAREDSecret=<base32string> 

respectively

UPDate Admin <Name> MFARequired=Yes SHAREDSecret=<base32string> 

setting up the TOTP app

Logon with MFA

When logging in as admin, the admin CLI still asks for username and password, but with MFA the latter consists of two parts: the admin password + the 6-number TOTP token, so e.g. for the combination of

the ont-time MFA password is Admin4TSM238291

Acknowledgment

Thanks to Bruno Friess / Exstor for his introduction to the topic at GSE meetings and at the GWDG TSM JourFixe.