Multi Factor Authentication (MFA)#
Multi Factor Authentication (MFA) is an augmented level of security. As the name suggests, MFA requires additional steps with human intervention when authenticating.
MFA is mandatory for accessing the Access: Terminal Interface on the following VSC clusters:
Login to Open OnDemand#
Users from all VSC sites can access the Open OnDemand portal at KU Leuven site. For that, proceed to the Open OnDemand portal. If you are affiliated with KU Leuven, click on the KU Leuven logo. Otherwise, click on the VSC logo to choose your institute. You will then be forwarded to the Identity Provider (IdP) of your institute to complete the authentication procedure. Once that succeeds, you will automatically log into the Open OnDemand homepage.
Users from all VSC sites can access the VUB Open OnDemand portal. For that, proceed to the Open OnDemand portal. Select your institute from the dropdown menu. You will then be forwarded to the Identity Provider (IdP) of your institute to complete the authentication procedure. Once that succeeds, you will automatically log into the Open OnDemand homepage.
Obtaining an SSH certificate#
Note
Additional access restrictions (for instance when connecting from abroad or from a non-managed laptop) may apply, which require that you first authorize your connection on the VSC Firewall. See this page for more information.
Using an SSH Agent allows to store so-called SSH certificates which then are made available to any other client program needing to use that same connection. Getting an SSH certificate involves MFA but this only needs to be performed once since a certificate can be used multiple times as long as it remains valid. Agentless options are possible in some cases, see the certificate methods below.
There are two ways to acquire such an SSH certificate:
Works with any SSH client, including PuTTY and MobaXterm.
Uses the step CLI. On Windows, only works from PowerShell or the
Command Prompt, not from GUI clients such as PuTTY and MobaXterm.
VSC clusters that accept these certificates:
Once you have a certificate loaded into your agent, it can be used as long as the agent remains alive and the certificate itself has not expired (they have a lifetime of 16 hours). Do not forget to set up your client so that it contacts your SSH agent when opening new connections (thereby making use of the certificates). For a few common clients the corresponding documentation pages are listed below.