Two Factor Authentication Guide
Two Factor Authentication Guide
TWO FACTOR AUTHENTICATION (OR 2FA) IS A TWO STEP VERIFICATION PROCESS THAT PROVIDES AN
EXTRA LAYER OF SECURITY FOR YOU WHEN ACCESSING YOUR ACCOUNT WITHIN ONLINE SERVICES.
The benefits of 2FA are a higher level of protection for your Online Services account and the data held within it. This is because 2FA reduces
the risk of an intruder gaining access to it.
2FA is free and Nominet has used RFC 6238 for implementing 2FA which is based on time based passcodes.
CONTENT
1 . INSTRUC TIONS
SIGN UP TO 2FA
ADD A NE W DE VICE
DELE TE A DE VICE
3. TROUBLESHOOTING
4. GLOSSARY
SIGN UP TO THE TWO FACTOR AUTHENTICATION SERVICE
BEFORE YOU START GOOGLE AUTHENTICATOR ONLINE SERVICES
You need to decide which device you will use to We recommend that you start by downloading
generate your 2FA. The Google Authenticator is Google Authenticator on your chosen device:
widely used and recommended by Nominet. • Open the relevant app store
Another frequently used application is Authy apps. • Search for and download Google Authenticator. If you
are using a Windows phone, search for ‘Authenticator’
* If you do not see this message, go to ‘Login settings’ in Online
The device could be a smartphone, tablet, laptop or Services and select Two-Factor Authentication – ‘Add/manage
CLICK HERE to see an example • Name your device so you can easily identify it within Online
OR Services later e.g. Richard’s smartphone
• Click next
Scan the QR code from Online Services
The account will be set up as Nominet Online Services
Select ‘Done’
GOOGLE AUTHENTICATOR
Click to log in
You need to know which device you plan We recommend that you start by downloading Login to Online Services using
to add. Google Authenticator on your chosen device: Go to 2 Factor Authentication
online
services
• Open the relevant app store
The device could be a smartphone, tablet, laptop or • Search for and download Google Authenticator. If you
PC. are using a Windows phone, search for ‘Authenticator’
Go to ‘Login Settings’
TIP CLICK HERE to see an example • Name your device so you can easily identify it within Online
OR Services later e.g. Richard’s smartphone
To replace a device simply follow the
steps for: • Click next
Scan the QR code from Online Services
a) Delete a device The account will be set up as Nominet Online Services
b) Add a new device
Go to ‘Login settings’
BACK TO CONTENTS
FREQUENTLY ASKED QUESTIONS
• How many devices can I set up per Online Services contact?
The recommended way of managing access to Online Services is that contact logins are used by a single user only.
A single user should find 5 devices sufficient for the 2FA login process.
• If I have set-up more than one device, which one do I use to generate my 6 digit passcode?
You can use any of the devices associated with your contact login. The app on each one will generate a unique and valid 6 digit code for
you to input into Online Services when you log in.
• I have more than one contact login – can I set up 2FA across all my logins using the same device?
Yes, you can use the same device for multiple contact logins. Make sure you name each account name within Google Authenticator or
Authy app something to help you identify the login it applies to, e.g. ‘Nominet OS [email protected]’.
BACK TO CONTENTS
FREQUENTLY ASKED QUESTIONS
• What is RFC 6238?
RFC 6238 is a standard for implementing two factor authentication. Online Services should work with apps using this implementation. Nominet
has successfully tested the Google Authenticator app and Authy app and are therefore recommended to users.
• There are many third party implementations of Google Authenticator, including applications for PalmOS, Chrome OS and Java. If you can
successfully get the app to work with Online Services then it is fine for you to use it. However Nominet advisors cannot provide any support for
these implementations and we cannot vouch for their security.
BACK TO CONTENTS
TROUBLESHOOTING
• I get an error when inputting my 16 digit set up key
Please check that the characters have been inputted correctly. The 16 digit setup key will not contain the number zero ‘0’ or the number one ‘1’. If
you are still having difficulties please contact our Customer Service team on +44 (0)1865 332233 or by emailing [email protected].
If anyone else uses the same contact email as you for Online Services, they may have been locked out of the account without your knowledge. An
email confirming this will have been sent to the email address used for the account.
If you are still having difficulties please contact our Customer Service team on +44 (0)1865 332233 or by emailing [email protected].
BACK TO CONTENTS
TROUBLESHOOTING
• What happens if I have lost the device with 2FA installed?
If you have another device associated with your contact login then you should:
Once we are able to verify your identity we will delete the lost device from your contact login for you.
BACK TO CONTENTS
GLOSSARY
2FA or Two Factor Authentication
2FA is a two step verification process which provides an extra layer of security for you when accessing your account within Online Services
2FA passcode
A time-limited 6 digit code generated by the Google Authenticator app or plugin and which is needed alongside your username and password each time you log
into Online Services if you have signed up for the 2FA service. The Google Authenticator app or plugin generates a new, unique passcode every 30 seconds.
Contact email
The email address you use to log into Online Services
Google Authenticator
The 2FA app or plugin that is used to implement 2FA within Nominet Online Services
Password
The password you use to log into Online Services
Passphrase
The additional passphrase you may have set up (that you use) to log into Online Services once you have entered your username and password.
The passphrase provides an additional layer of security when logging into Online Services, but 2FA improves on this by requiring the user to generate a passcode
on a separate device.
BACK TO CONTENTS