Home
Contents
CLOSE
AuthLite Interactive Documentation
FEATURES: What can AuthLite Do? TOKEN TYPES: What "Factors" are supported? INSTALL: How and where to install AuthLite? CONFIGURE AuthLite for your needs CHOOSE USERS: Choose 2-factor Users ENFORCE 2-factor Logons ADMINISTER AuthLite Tokens LDAP logon support/enforcement VPN and RADIUS Configuration How to Log In Event Logging
CLOSE
Enter Username
Enter Username
New user: enter password
New user: enter password
Select to add a YubiKey or OATH token
Select to add a YubiKey or OATH token

Prerequisites

  • First, Set up the self-service provisioning portal web application
  • Program and Import your YubiKeys (unless you only want to use OATH tokens)
  • Distribute your programmed and imported (but still unassigned) YubiKeys out to your users

First Portal Login

  • Each user browses to the Intranet URL of your provisioning portal
  • Enter the username and hit Submit

  • If this user is not in any AuthLite Group yet, they are now asked for their password

Adding a YubiKey

  • After logging in to the portal, select "Add YubiKey"
  • Plug in the YubiKey to a USB port
  • In the YubiKey Passcode field and touch the YubiKey button to enter an OTP from this key.
  • Click “Add” and then the YubiKey will automatically be associated with this user account, and the user will be added to the “New Users” Group

Adding an OATH Token

  • After logging in to the portal, select "Add OATH Token"
  • If this token is going to be used to log on to domain servers or online workstations, choose “Online”. If you are defining an OATH token that will be used for offline workstations disconnected from the domain, choose “Offline”. (A single OATH record cannot do both tasks, because the workstations must know the OATH secret for offline tokens, and this causes them to be less secure than the online tokens.)
  • Click “Add” and then a QR code will be displayed. The user can snap this with the Google Authenticator app on their phone, and then click “Done”. The new OATH token will automatically be associated with this user account, and the user will be added to the “New Users” Group.

Logging in later to manage tokens

  • After enrolling in AuthLite, the user can also log in to this portal again to add/manage their tokens.
  • Since they are already AuthLite users with at least one token, they must supply their password and an OTP token to gain access.  (This prevents an attacker with knowledge of the password from using this portal to "bypass" 2-factor restrictions by minting new tokens for the user.)