Two-factor authentication in the Keimeno backend

Two-factor authentication, or 2FA for short, protects your administrator account in addition to your personal password. After logging in with username and password, the Keimeno backend requests a one-time six-digit security code. A stolen or guessed password alone is therefore not sufficient to log in to the backend.

Which methods are available?

One of the following methods can be activated for each administrator account:

  • Authenticator app: The security code is generated on a smartphone or another personal device.
  • Email: When you log in, the backend sends a one-time security code to the email address stored in the administrator account.

The authenticator app is usually the preferred method because it also works without mobile reception and does not depend on the delivery of an email. The email method is a convenient alternative but requires reliably configured email delivery.

Requirements

  • You need an active administrator account in the Keimeno backend.
  • To activate 2FA, you must open your own account or an account that you are allowed to administer.
  • For the app method, you need a TOTP-compatible authenticator app.
  • For the email method, a valid email address must be stored in the administrator account.
  • The CMS email delivery must be fully set up and tested for the email method.

Setting up 2FA for an administrator account

  1. Log in to the Keimeno backend.
  2. Open the user or staff management.
  3. Edit the desired administrator account.
  4. Click Enable two-factor authentication.
  5. In the setup window, select either Authenticator app or Email.
  6. Confirm the setup with a valid six-digit security code.

Activation is only saved after the entered security code has been successfully verified. A setup that has been started but not confirmed does not activate 2FA.

Setup with an authenticator app

  1. In the setup window, open the Authenticator app section.
  2. Open your authenticator app and add a new account.
  3. Scan the QR code displayed in the Keimeno backend.
  4. Enter the current six-digit code shown in the app into the input field.
  5. Click Enable authenticator app.

If the QR code cannot be scanned or displayed on the server, you can show the setup key in the setup window. Enter this key manually in the authenticator app. The app must support manual setup with SHA-512.

Important: The setup key is confidential. Do not photograph, send, or store it in unprotected notes. Anyone who knows this key can generate valid security codes.

Setup with an email code

  1. First check whether the correct email address is stored in the administrator account.
  2. In the setup window, open the Email section.
  3. Click Send security code.
  4. Retrieve the email and also check the spam folder if necessary.
  5. Enter the received six-digit code into the input field.
  6. Click Enable email method.

The email code is valid for ten minutes and can only be used once. A new code can be requested no sooner than after 60 seconds. After several incorrect entries, verification is limited to protect the account.

If no message arrives, check the administrator account's email address and the central email server configuration. The delivery route, sender address, and SMTP or Microsoft 365 settings must be functional.

Logging in with 2FA enabled

  1. Open the login page of the Keimeno backend.
  2. Enter your username and password.
  3. Then enter the six-digit security code.
  4. Confirm the login.

When using an authenticator app, the code is displayed directly in the app and is renewed regularly. With the email method, the backend sends a one-time code to the stored address. If an email code is no longer valid, a new code can be requested on the login page after the waiting period has expired.

Trusting a private device

After successfully entering a code, the option Trust this private device for 30 days may be offered. If you enable this option, no additional security code is normally required on this device for subsequent logins within this period.

Use this feature only on personal and protected devices. Do not enable it on shared computers, public workstations, or other people's mobile devices.

Allowed devices can be viewed and revoked in the trusted devices management. After removal, a security code must be entered again the next time you log in on this device.

Disabling or reconfiguring 2FA

Two-factor authentication can be disabled in the administrator account editing view. The associated trusted devices are revoked at the same time, and existing administrator sessions are secured accordingly.

When using an authenticator app, the old entry should then also be removed from the app. If 2FA is to be activated again afterwards, the backend generates a new setup key or starts a new email verification.

Loss of the second factor

If there is no longer any access to the authenticator app or the email inbox, the login cannot be completed in the usual way. In this case, contact an authorized main administrator. They can securely disable two-factor authentication for the affected account and allow a new setup.

Deactivation should only take place after a clear verification of identity. Security codes, passwords, and setup keys must never be shared by phone, chat, or unencrypted email.

Recommendations for secure operation

  • Enable 2FA for all accounts with administrative permissions.
  • Prefer an authenticator app where this is organizationally possible.
  • Continue to use a long and unique password.
  • Protect the smartphone with a PIN, password, or biometric lock.
  • Only trust your own, encrypted, and regularly updated devices.
  • Remove trusted devices that are no longer used in a timely manner.
  • Treat unexpected email codes as a possible sign of an unauthorized login attempt.
  • Immediately disable administrator accounts that are no longer needed or whose users have left.

Common issues

The code from the authenticator app is rejected

Check whether you are using the correct account entry. Also make sure that the smartphone's date and time are synchronized automatically. As the codes are time-based, an incorrect device time can lead to rejection.

The email code does not arrive

Check the spam folder, recipient address, and email server configuration. Wait at least 60 seconds before requesting another code. An email that has been accepted by the mail server is not necessarily already delivered to the inbox.

The code has expired

Authenticator codes change regularly. Use the code currently displayed. Email codes lose their validity after ten minutes and must then be requested again.

Login is blocked after several attempts

The backend limits repeated failed attempts to protect against automated attacks. Wait for the displayed lockout period to expire and then try again with a new or currently displayed code.

Summary

Two-factor authentication complements the password with a second proof that is only valid for a short time. In the Keimeno backend, this can be provided either by an authenticator app or by a security code sent via email. Setup is only active after successful code verification. For administrator accounts, 2FA should generally be enabled and only temporarily skipped on personal devices.