Account Update: Difference between revisions

From Network for Advanced NMR
Jump to navigationJump to search
Qcheng (talk | contribs)
 
(27 intermediate revisions by 4 users not shown)
Line 1: Line 1:
Starting '''9/22/2026,''' NMRhub users will be required to use [[wikipedia:Multi-factor_authentication|Two factor authentication (2FA)]] to log into NMRhub services including NMRhub, NMRbox and NAN websites, connections to NMRbox servers via SSH or RealVNC, as well as FileZilla file copies to and from NMRbox servers. In addition, as part of the 2FA implementation, NMRhub accounts will be migrated to a new user account management system which requires a one-time password reset for all NMRhub accounts.  All NMRhub users should followed the process below to complete the initial setup steps include resetting password, setting password recovery questions and adding NMRhub in an authenticator application.
Starting '''Tuesday, September 22, 2026''', all NMRhub users will be required to use [[wikipedia:Multi-factor authentication|two-factor authentication (2FA)]] to log in to NMRhub services. This includes the NMRhub, NMRbox, and NAN websites, SSH and RealVNC connections to NMRbox servers, and [[FileZilla]] file transfers to and from NMRbox servers.


== Step 1: Log into NMRhub to Generate the Magic Link ==
As part of this change, NMRhub accounts are being migrated to a new account management system. Every account requires a one-time password reset, so all users must complete the setup below.
Log into NMRhub with your current NMRhub account and password. An email from support@nmrhub.org that contains a magic link will be sent to the email address associated with your NMRhub account to start the 2FA set up process.


[[File:Email check.png|frameless|600x600px]]
Before you start, set up an authenticator app. Most people use a phone app, but a desktop app or certain password managers works too. The process takes just a few minutes and has three parts: resetting your password, setting security questions, and adding NMRhub to your authenticator app.


The email is as below:<blockquote>''Dear <user>,''
<div style="border: 1px solid #a2a9b1; border-left: 8px solid #fc3; background-color: #fef6e7; padding: 0.75em 1em; margin: 1em 0;">
'''A note on phishing:''' this process starts with you. You will only receive a password reset email from support@nmrhub.org after you begin logging in at NMRhub. If you receive a reset email you did not request, do not click the link. Forward it to support@nmrhub.org instead.
</div>


== Step 1: Start the login process ==
Go to the [https://nmrhub.org/user-dashboard NMRhub User Dashboard] and begin logging in with your current NMRhub username and password. You will not be able to finish logging in yet. Instead, the system sends a password reset email to the institutional email address associated with your NMRhub account.
[[File:Email check.png|thumb|300px|center|NMRhub confirms that the reset email has been sent.]]
The email comes from '''support@nmrhub.org''' and looks like this:
<blockquote>
''Dear <user>,''


''We received a request to reset your password for NMRhub username: <username>''
''We received a request to reset your password for NMRhub username: <username>''
Line 15: Line 25:
''If you did not request a password reset, please contact us at: support@nmrhub.org''
''If you did not request a password reset, please contact us at: support@nmrhub.org''


''Thank you,''
''NMRhub Support Team''
''UConn Health''
</blockquote>
The link in this email expires after 24 hours. If the link expires, return to the login page and start again to receive a new one.
=== If the email does not arrive ===
* Allow a few minutes for delivery, then check your spam or junk folder.
* If you no longer have access to the institutional email address on your NMRhub account, head to [https://nmrhub.org/forgot-password NMRhub Forgot Password page] and login with your ORCID iD to follow the same recovery/upgrade workflow.
== Step 2: Reset your password and set security questions ==


''Thank you,''
Click the link in the email. You will be guided through two screens.
 
'''Reset your password.''' Enter a new password that meets the NMRhub password complexity rules. Note: If you have reset your password recently, this screen is skipped and you go straight to the security questions.


'''Set your security questions.''' Create and answer the security questions. These are used to verify your identity if you are locked out, so create questions and answers that you will not forget and which are secure.


''NMRhub Support Team''
[[File:Questions.png|thumb|300px|center|The security question screen.]]


''UConn Health''</blockquote>
Record your answers somewhere safe, such as your password manager. Answers are case insensitive.


== Step 2: Reset Password and Create Security Questions ==
== Step 3: Add NMRhub to your authenticator app ==
Click on the link in the email. You will be guided through the following steps to complete the 2FA setup:


# Reset password. You may skip this step if you've recently reset your password. The new password must meet the current password complexity rules.
You will be shown a QR code. Open your authenticator app, choose the option to add a new account, and scan the code.
# Create security questions and the answers to them:


=== Security questions ===
[[File:Qrcode.png|thumb|300px|center|Scan this QR code with your authenticator app.]]
After setting your password (if required), complete security questions:


[[File:Questions.png|frameless|600x600px]]
Most TOTP authenticators work, including Google Authenticator, Authy, Duo Mobile, Okta Verify, Microsoft Authenticator, and FreeOTP. You do not need a phone: desktop authenticators and password managers such as 1Password also work, and can either capture the QR code from your screen or accept the setup key shown with it, which you can type in by hand.


== Step 3: Add NMRhub account to your authenticator application ==
Once added, your app will display a six digit code for NMRhub that changes every 30 seconds.
Scan the QR code and add NMRhub to the authenticator app of your choosing.  


[[File:Qrcode.png|frameless|600x600px]]
<div style="border: 1px solid #a2a9b1; border-left: 8px solid #36c; background-color: #eaf3ff; padding: 0.75em 1em; margin: 1em 0;">
'''If the QR code setup goes wrong,''' click the link in your email again. It is valid for 24 hours, and if it has expired you can start the login process again to get a new one. You will not be asked to reset your password a second time, only to confirm your security questions, and then you can scan a new QR code. You can also add additional authenticators later.
</div>


== Step 4: Log in ==
== Step 4: Log in ==
After you finish setting up the 2FA authenticator, log into NMRhub - You will be required to enter a One-Time-Password (OTP) generated in your phone authenticator app.


While you may save your password in a password manager, the OTP will be generated in real time and need to be entered after the previous 2FA authentication expires.  
Return to the NMRhub login page and sign in with your username and new password. You will then be prompted for a one-time password (OTP). Open your authenticator app, read the current six digit code for NMRhub, and enter it. Note that codes expire every 30 seconds and most apps show a countdown. If close to the end of the countdown, wait till the code refreshes so you have longer to enter the code.
 
[[File:Keycloak.png|thumb|300px|center|The one-time password prompt.]]
 
You will also be prompted for a one-time password when you connect to NMRbox over RealVNC or SSH, transfer files with [[FileZilla]], and access the NMRbox and NAN websites. Each prompt needs a fresh code from your app. You will be asked again if you switch devices or locations, or after a set amount of time.
 
RealVNC works the same way as the websites: enter the six digit code from your authenticator app when prompted.
 
=== Connecting with SSH and FileZilla ===
 
Separate guides cover connecting to NMRbox with SSH and transferring files with FileZilla.
 
=== If you lose access to your authenticator app ===


[[File:Keycloak.png|frameless|600x600px]]
If you replace your phone, lose it, or delete the app, return to [[#Step 1: Start the login process|Step 1]] and begin logging in as usual. You will receive a new email link, confirm your security questions, and then scan a new QR code for your new device.

Latest revision as of 21:03, 14 September 2026

Starting Tuesday, September 22, 2026, all NMRhub users will be required to use two-factor authentication (2FA) to log in to NMRhub services. This includes the NMRhub, NMRbox, and NAN websites, SSH and RealVNC connections to NMRbox servers, and FileZilla file transfers to and from NMRbox servers.

As part of this change, NMRhub accounts are being migrated to a new account management system. Every account requires a one-time password reset, so all users must complete the setup below.

Before you start, set up an authenticator app. Most people use a phone app, but a desktop app or certain password managers works too. The process takes just a few minutes and has three parts: resetting your password, setting security questions, and adding NMRhub to your authenticator app.

A note on phishing: this process starts with you. You will only receive a password reset email from support@nmrhub.org after you begin logging in at NMRhub. If you receive a reset email you did not request, do not click the link. Forward it to support@nmrhub.org instead.

Step 1: Start the login process

Go to the NMRhub User Dashboard and begin logging in with your current NMRhub username and password. You will not be able to finish logging in yet. Instead, the system sends a password reset email to the institutional email address associated with your NMRhub account.

NMRhub confirms that the reset email has been sent.

The email comes from support@nmrhub.org and looks like this:

Dear <user>,

We received a request to reset your password for NMRhub username: <username>

Please click here and follow the prompts to update your password.

If you did not request a password reset, please contact us at: support@nmrhub.org

Thank you,

NMRhub Support Team

UConn Health

The link in this email expires after 24 hours. If the link expires, return to the login page and start again to receive a new one.

If the email does not arrive

  • Allow a few minutes for delivery, then check your spam or junk folder.
  • If you no longer have access to the institutional email address on your NMRhub account, head to NMRhub Forgot Password page and login with your ORCID iD to follow the same recovery/upgrade workflow.

Step 2: Reset your password and set security questions

Click the link in the email. You will be guided through two screens.

Reset your password. Enter a new password that meets the NMRhub password complexity rules. Note: If you have reset your password recently, this screen is skipped and you go straight to the security questions.

Set your security questions. Create and answer the security questions. These are used to verify your identity if you are locked out, so create questions and answers that you will not forget and which are secure.

The security question screen.

Record your answers somewhere safe, such as your password manager. Answers are case insensitive.

Step 3: Add NMRhub to your authenticator app

You will be shown a QR code. Open your authenticator app, choose the option to add a new account, and scan the code.

Scan this QR code with your authenticator app.

Most TOTP authenticators work, including Google Authenticator, Authy, Duo Mobile, Okta Verify, Microsoft Authenticator, and FreeOTP. You do not need a phone: desktop authenticators and password managers such as 1Password also work, and can either capture the QR code from your screen or accept the setup key shown with it, which you can type in by hand.

Once added, your app will display a six digit code for NMRhub that changes every 30 seconds.

If the QR code setup goes wrong, click the link in your email again. It is valid for 24 hours, and if it has expired you can start the login process again to get a new one. You will not be asked to reset your password a second time, only to confirm your security questions, and then you can scan a new QR code. You can also add additional authenticators later.

Step 4: Log in

Return to the NMRhub login page and sign in with your username and new password. You will then be prompted for a one-time password (OTP). Open your authenticator app, read the current six digit code for NMRhub, and enter it. Note that codes expire every 30 seconds and most apps show a countdown. If close to the end of the countdown, wait till the code refreshes so you have longer to enter the code.

The one-time password prompt.

You will also be prompted for a one-time password when you connect to NMRbox over RealVNC or SSH, transfer files with FileZilla, and access the NMRbox and NAN websites. Each prompt needs a fresh code from your app. You will be asked again if you switch devices or locations, or after a set amount of time.

RealVNC works the same way as the websites: enter the six digit code from your authenticator app when prompted.

Connecting with SSH and FileZilla

Separate guides cover connecting to NMRbox with SSH and transferring files with FileZilla.

If you lose access to your authenticator app

If you replace your phone, lose it, or delete the app, return to Step 1 and begin logging in as usual. You will receive a new email link, confirm your security questions, and then scan a new QR code for your new device.