See below for enforcing two-factor authentication in Vault for PKCS#11.

Enforcing two-factor authentication for the current user

See below for enforcing two-factor authentication for the current user.

To enforce two-factor authentication for the current user

  1. Log in to the Cryptographic Security Platform Vault for PKCS#11 webGUI.
  2. In the top menu bar, click Settings.
  3. In the Two-Factor Authentication field, click Set up Two-Factor Authentication.
  4. In the Enable Two-Factor dialog box, select the HOTP or TOTP radio button.

  5. Scan the generated barcode with your authorization app.
  6. Enter the six-digit verification code from your app in the dialog box.
  7. Click Continue. Cryptographic Security Platform Vault verifies the code and displays a message indicating success or failure. If the code is not correct, re-enter it.
  8. After the code has been accepted, click Done.
  9. When you log into the Vault web GUI:

    • Enter a valid OTP along with your standard account password on the login page. Do not add any characters or spaces between your account password and the one-time password generated by your authorization app. For example, if your password is XyZ123$, and your OTP is 32325, you enter XyZ123$32325 in the password field.

    • If you use TOTP, make sure your password doesn't expire before you submit the login request. 

Enforcing two-factor authentication for all users

See below for enforcing two-factor authentication for all Vault users

To enforce two-factor authentication for all users

  1. Log into the Vault web GUI using an account with Security Admin privileges.
  2. In the top menu bar, click Settings.
  3. In the System Settings section, click Two-Factor Authentication Settings.
  4. On the Two-Factor Authentication Settings page, select ENFORCED.
  5. Click Apply.