Two-factor OATH authentication with Google Authenticator¶
Google Authenticator allows for adding a dynamic component to a static password for increased account security.
- Select > .
- Find and click the user for whom you want to add the OATH authentication method.
- Click .
- From the Type drop-down list, select
OATH
.
data:image/s3,"s3://crabby-images/718e2/718e245f02bc8e28122536ad205fd62c1927142f" alt="../../_images/authentication_method_type.png"
- Enter password’s static part.
data:image/s3,"s3://crabby-images/7b7a7/7b7a7022365b2bc38f1b33c631826ad7eceac183" alt="../../_images/authentication_method_static.png"
- From the Token type drop-down list, select
HOTP (counter-based)
.
data:image/s3,"s3://crabby-images/7cd89/7cd89fb717d0acf12d95e6e60eb8ea247e653bb9" alt="../../_images/authentication_method_token_type.png"
- Enter a secret that will be used by Google Authenticator or click . to generate it automatically.
data:image/s3,"s3://crabby-images/c3642/c3642992de85db1ce7df347ab33f705d3bde0030" alt="../../_images/authentication_method_secret.png"
Note
The secret must be a Base32
encoded value.
- In the Length field, enter
6
.
data:image/s3,"s3://crabby-images/80a09/80a0942441ad82532f8475fba57f51238877191a" alt="../../_images/authentication_method_length.png"
- Click .
- Launch Google Authenticator and add new service.
Manual entry | QR Code |
---|---|
![]()
![]()
Note Click . on the user edit form in the Authentication section to reveal the secret. ![]()
![]()
![]() |
![]() |
- When logging in, the password string consists of a static password defined in the authentication method and dynamic part generated by the Google Authenticator, e.g.
password481418
.
data:image/s3,"s3://crabby-images/fce30/fce3007faa918de16121ed9b8428ee3c3299dcee" alt="../../_images/google_authenticator_token.png"
Related topics: