Account Update: Difference between revisions
Mmaciejewski (talk | contribs) No edit summary |
Mmaciejewski (talk | contribs) |
||
| (13 intermediate revisions by the same user not shown) | |||
| Line 3: | Line 3: | ||
As part of this change, NMRhub accounts are being migrated to a new account management system. Every account requires a one-time password reset, so all users must complete the setup below. | As part of this change, NMRhub accounts are being migrated to a new account management system. Every account requires a one-time password reset, so all users must complete the setup below. | ||
Before you start, | Before you start, set up an authenticator app. Most people use a phone app, but a desktop app or certain password managers works too. The process takes just a few minutes and has three parts: resetting your password, setting security questions, and adding NMRhub to your authenticator app. | ||
<div style="border: 1px solid #a2a9b1; border-left: 8px solid #fc3; background-color: #fef6e7; padding: 0.75em 1em; margin: 1em 0;"> | <div style="border: 1px solid #a2a9b1; border-left: 8px solid #fc3; background-color: #fef6e7; padding: 0.75em 1em; margin: 1em 0;"> | ||
| Line 12: | Line 12: | ||
Go to the [https://nmrhub.org/user-dashboard NMRhub User Dashboard] and begin logging in with your current NMRhub username and password. You will not be able to finish logging in yet. Instead, the system sends a password reset email to the institutional email address associated with your NMRhub account. | Go to the [https://nmrhub.org/user-dashboard NMRhub User Dashboard] and begin logging in with your current NMRhub username and password. You will not be able to finish logging in yet. Instead, the system sends a password reset email to the institutional email address associated with your NMRhub account. | ||
[[File:Email check.png| | [[File:Email check.png|thumb|300px|center|NMRhub confirms that the reset email has been sent.]] | ||
The email comes from '''support@nmrhub.org''' and looks like this: | The email comes from '''support@nmrhub.org''' and looks like this: | ||
| Line 32: | Line 32: | ||
</blockquote> | </blockquote> | ||
The | The link in this email expires after 24 hours. If the link expires, return to the login page and start again to receive a new one. | ||
=== If the email does not arrive === | === If the email does not arrive === | ||
* Allow a few minutes for delivery, then check your spam or junk folder. | * Allow a few minutes for delivery, then check your spam or junk folder. | ||
* If you no longer have access to the institutional email address on your NMRhub account, head to [https://nmrhub.org/forgot-password NMRhub Forgot Password page] and login with your ORCID iD to follow the same recovery/upgrade | * If you no longer have access to the institutional email address on your NMRhub account, head to [https://nmrhub.org/forgot-password NMRhub Forgot Password page] and login with your ORCID iD to follow the same recovery/upgrade workflow. | ||
== Step 2: Reset your password and set security questions == | == Step 2: Reset your password and set security questions == | ||
| Line 45: | Line 45: | ||
'''Reset your password.''' Enter a new password that meets the NMRhub password complexity rules. Note: If you have reset your password recently, this screen is skipped and you go straight to the security questions. | '''Reset your password.''' Enter a new password that meets the NMRhub password complexity rules. Note: If you have reset your password recently, this screen is skipped and you go straight to the security questions. | ||
'''Set your security questions.''' Create and answer the security questions. These are used to verify your identity if you are locked out , so create questions and answers that you will not forget and which are secure. | '''Set your security questions.''' Create and answer the security questions. These are used to verify your identity if you are locked out, so create questions and answers that you will not forget and which are secure. | ||
[[File:Questions.png| | [[File:Questions.png|thumb|300px|center|The security question screen.]] | ||
Record your answers somewhere safe, such as your password manager. Answers are case insensitive. | |||
[[File:Qrcode.png| | == Step 3: Add NMRhub to your authenticator app == | ||
You will be shown a QR code. Open your authenticator app, choose the option to add a new account, and scan the code. | |||
[[File:Qrcode.png|thumb|300px|center|Scan this QR code with your authenticator app.]] | |||
Most TOTP authenticators work, including Google Authenticator, Authy, Duo Mobile, Okta Verify, Microsoft Authenticator, and FreeOTP. You do not need a phone: desktop authenticators and password managers such as 1Password also work, and can either capture the QR code from your screen or accept the setup key shown with it, which you can type in by hand. | |||
Once added, your app will display a six digit code for NMRhub that changes every 30 seconds. | |||
<div style="border: 1px solid #a2a9b1; border-left: 8px solid #36c; background-color: #eaf3ff; padding: 0.75em 1em; margin: 1em 0;"> | |||
'''If the QR code setup goes wrong,''' click the link in your email again. It is valid for 24 hours, and if it has expired you can start the login process again to get a new one. You will not be asked to reset your password a second time, only to confirm your security questions, and then you can scan a new QR code. You can also add additional authenticators later. | |||
</div> | |||
== Step 4: Log in == | == Step 4: Log in == | ||
Return to the NMRhub login page and sign in with your username and new password. You will then be prompted for a one-time password (OTP). Open your authenticator app, read the current six digit code for NMRhub, and enter it. Note that codes expire every 30 seconds and most apps show a countdown. If close to the end of the countdown, wait till the code refreshes so you have longer to enter the code. | |||
[[File:Keycloak.png|thumb|300px|center|The one-time password prompt.]] | |||
You will also be prompted for a one-time password when you connect to NMRbox over RealVNC or SSH, transfer files with [[FileZilla]], and access the NMRbox and NAN websites. Each prompt needs a fresh code from your app. You will be asked again if you switch devices or locations, or after a set amount of time. | |||
RealVNC works the same way as the websites: enter the six digit code from your authenticator app when prompted. | |||
=== Connecting with SSH and FileZilla === | |||
Separate guides cover connecting to NMRbox with SSH and transferring files with FileZilla. | |||
=== If you lose access to your authenticator app === | |||
[[ | If you replace your phone, lose it, or delete the app, return to [[#Step 1: Start the login process|Step 1]] and begin logging in as usual. You will receive a new email link, confirm your security questions, and then scan a new QR code for your new device. | ||
Latest revision as of 21:03, 14 September 2026
Starting Tuesday, September 22, 2026, all NMRhub users will be required to use two-factor authentication (2FA) to log in to NMRhub services. This includes the NMRhub, NMRbox, and NAN websites, SSH and RealVNC connections to NMRbox servers, and FileZilla file transfers to and from NMRbox servers.
As part of this change, NMRhub accounts are being migrated to a new account management system. Every account requires a one-time password reset, so all users must complete the setup below.
Before you start, set up an authenticator app. Most people use a phone app, but a desktop app or certain password managers works too. The process takes just a few minutes and has three parts: resetting your password, setting security questions, and adding NMRhub to your authenticator app.
A note on phishing: this process starts with you. You will only receive a password reset email from support@nmrhub.org after you begin logging in at NMRhub. If you receive a reset email you did not request, do not click the link. Forward it to support@nmrhub.org instead.
Step 1: Start the login process
Go to the NMRhub User Dashboard and begin logging in with your current NMRhub username and password. You will not be able to finish logging in yet. Instead, the system sends a password reset email to the institutional email address associated with your NMRhub account.

The email comes from support@nmrhub.org and looks like this:
Dear <user>,
We received a request to reset your password for NMRhub username: <username>
Please click here and follow the prompts to update your password.
If you did not request a password reset, please contact us at: support@nmrhub.org
Thank you,
NMRhub Support Team
UConn Health
The link in this email expires after 24 hours. If the link expires, return to the login page and start again to receive a new one.
If the email does not arrive
- Allow a few minutes for delivery, then check your spam or junk folder.
- If you no longer have access to the institutional email address on your NMRhub account, head to NMRhub Forgot Password page and login with your ORCID iD to follow the same recovery/upgrade workflow.
Step 2: Reset your password and set security questions
Click the link in the email. You will be guided through two screens.
Reset your password. Enter a new password that meets the NMRhub password complexity rules. Note: If you have reset your password recently, this screen is skipped and you go straight to the security questions.
Set your security questions. Create and answer the security questions. These are used to verify your identity if you are locked out, so create questions and answers that you will not forget and which are secure.

Record your answers somewhere safe, such as your password manager. Answers are case insensitive.
Step 3: Add NMRhub to your authenticator app
You will be shown a QR code. Open your authenticator app, choose the option to add a new account, and scan the code.

Most TOTP authenticators work, including Google Authenticator, Authy, Duo Mobile, Okta Verify, Microsoft Authenticator, and FreeOTP. You do not need a phone: desktop authenticators and password managers such as 1Password also work, and can either capture the QR code from your screen or accept the setup key shown with it, which you can type in by hand.
Once added, your app will display a six digit code for NMRhub that changes every 30 seconds.
If the QR code setup goes wrong, click the link in your email again. It is valid for 24 hours, and if it has expired you can start the login process again to get a new one. You will not be asked to reset your password a second time, only to confirm your security questions, and then you can scan a new QR code. You can also add additional authenticators later.
Step 4: Log in
Return to the NMRhub login page and sign in with your username and new password. You will then be prompted for a one-time password (OTP). Open your authenticator app, read the current six digit code for NMRhub, and enter it. Note that codes expire every 30 seconds and most apps show a countdown. If close to the end of the countdown, wait till the code refreshes so you have longer to enter the code.

You will also be prompted for a one-time password when you connect to NMRbox over RealVNC or SSH, transfer files with FileZilla, and access the NMRbox and NAN websites. Each prompt needs a fresh code from your app. You will be asked again if you switch devices or locations, or after a set amount of time.
RealVNC works the same way as the websites: enter the six digit code from your authenticator app when prompted.
Connecting with SSH and FileZilla
Separate guides cover connecting to NMRbox with SSH and transferring files with FileZilla.
If you lose access to your authenticator app
If you replace your phone, lose it, or delete the app, return to Step 1 and begin logging in as usual. You will receive a new email link, confirm your security questions, and then scan a new QR code for your new device.