# Multi-factor Authentication Primer with PUBLIC SSO

**URL:** https://ps.zoethical.org/t/multi-factor-authentication-primer-with-public-sso/5039
**Category:** Share
**Tags:** sso, deprecated, documentation
**Created:** [September 24, 2021, 6:42am UTC](https://ps.zoethical.org/t/multi-factor-authentication-primer-with-public-sso/5039 "2021-09-24T06:42:23Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![how](https://ps.zoethical.org/user_avatar/ps.zoethical.org/how/32/2236_2.png) [@how](https://ps.zoethical.org/u/how)
#### Post date: [September 24, 2021, 6:42am UTC](https://ps.zoethical.org/t/multi-factor-authentication-primer-with-public-sso/5039/1 "2021-09-24T06:42:24Z")

</div>

## Objectives

- Single Sign On (SSO) using PUBLIC SSO
- Multi-Factor Authentication (MFA)
- One-Time Password (OTP)
- Backup MFA on multiple devices (phone and laptop)

## Requirements

### On your phone

Install [FreeOTP](https://freeotp.github.io/) from the [F-Droid](https://f-droid.org/packages/org.fedorahosted.freeotp) repositories.

### On your laptop

We’ll be using [`pass`](https://www.passwordstore.org/) with the OTP extension.

E.g., on Debian:

```shell
sudo apt install pass pass-extension-otp zbarimg

```

## Setup SSO and OTP

This section covers the SSO account registration and MFA setup for your phone.

- Register an account at [https://public.cat/auth/realms/public/account](https://public.cat/auth/realms/public/account)
- Setup a device for MFA at [https://public.cat/auth/realms/public/account/#/security/signingin](https://public.cat/auth/realms/public/account/#/security/signingin) under “Set up Authenticator Application”
- Scan QR-code from FreeOTP
- Complete device registration

### Register a backup OTP device

Note that the interest of MFA is to _require multiple devices_ as an additional security mechanism in case one device is stolen. But if your _only_ MFA device is stolen, then you’re locked out of your account, which is in itself a denial-of-service attack. Therefore it’s important when using MFA to anticipate this situation and create a backup device. In this example we’ll use a laptop running `pass`. Note that this password store should not be kept with your laptop – as it would defeat the _multi-factor_ – and probably stored somewhere safe, e.g., in a remote `git` repository that you can access when needed from any machine you happen to use. You could even save that git repository inside a [`tomb`](https://www.dyne.org/software/tomb/) for extra security.

Also note that the following sequence should be done quite fast since the session might time out: so read it first and get prepared to perform it under a minute or two.

- Login to [https://public.cat/auth/realms/public/account](https://public.cat/auth/realms/public/account)
- Proceed to MFA with your primary device
- Go to “[Set up Authentication Application](https://public.cat/auth/realms/public/account/#/security/signingin)”
- Save QR-code image to `~/otp.png`
- Save OTP credentials to pass:  
`zbarimg -q --raw ~/otp.png | pass otp insert public.cat/public-sso/"$USER"-otp`
- Get a new OTP to paste in the form to complete device register
- Logout and test your new MFA device
- Remove the QR-code that contains your secret! `rm -r ~/otp.png`

Now you can use `pass otp public.cat/public-sso/"$USER"-otp` to retrieve an OTP from the command line in case you lost your phone.

---

<div class="post-metadata">

### Author: ![how](https://ps.zoethical.org/user_avatar/ps.zoethical.org/how/32/2236_2.png) [@how](https://ps.zoethical.org/u/how)
#### Post date: [March 27, 2024, 2:56pm UTC](https://ps.zoethical.org/t/multi-factor-authentication-primer-with-public-sso/5039/2 "2024-03-27T14:56:52Z")

</div>



---

<div class="post-metadata">

### Author: ![how](https://ps.zoethical.org/user_avatar/ps.zoethical.org/how/32/2236_2.png) [@how](https://ps.zoethical.org/u/how)
#### Post date: [March 27, 2024, 2:56pm UTC](https://ps.zoethical.org/t/multi-factor-authentication-primer-with-public-sso/5039/3 "2024-03-27T14:56:56Z")

</div>


