1.14 TOTP

TOTP is a time-based one-time password. This method uses a predefined time step, which is equal to 30 seconds by default and hence for every 30 seconds a new one-time password is generated.

To enroll the TOTP authenticator, follow the recommendations of your system administrator.

TOTP method supports the following types of usage:

  • Advanced Authentication smartphone app (Apple iOS ap, Google Android app).

  • Google Authenticator app.

  • OATH TOTP compliant hardware token.

  • OATH TOTP compliant software token.

WARNING:The format of the QR codes for Advanced Authentication and Google Authenticator apps are different. Contact your system administrator to know which apps you must use.

To enroll a TOTP authenticator, perform the following steps:

  1. Click the TOTP icon.

    Then perform the following tasks based on the required preferences:

    A. Using Advanced Authentication smartphone app

  2. Specify a comment in Comment. For example, my iPhone.

  3. Select the required category from Category.

  4. Move the cursor out of the QR code and open the Advanced Authentication smartphone app.

  5. Tap Offline authentication in the app.

  6. Tap + to add a new authenticator in the app.

  7. Use the camera of your smartphone to scan the QR code.

  8. Click Save.

    A message Authenticator "TOTP" added is displayed.

  9. Specify your username and an optional comment in the smartphone app.

  10. Save the authenticator on your smartphone.

HINT:If you are not able to scan the QR code with the Advanced Authentication app, do the following:

  1. Scan the zoomed QR code by zooming the page to 125-150%.

  2. Ensure that nothing overlaps the QR code (mouse cursor, text).

  3. Try to scan the QR code using the Google Authenticator app.

If you are unable to scan the QR code, contact your system administrator.

B. Using Google Authenticator app

  1. Specify a comment in Comment. For example, my iPhone.

  2. Select the required category from Category.

  3. Move the cursor out of the QR code and open the Google Authenticator app.

  4. Tap BEGIN SETUP in the app.

  5. Tap Scan barcode to add a new authenticator in the app.

  6. Use the camera of your smartphone to scan the QR code.

  7. Click Save.

    A message Authenticator "TOTP" added is displayed.

HINT:If an error Invalid barcode is displayed, then it could be that the QR code is compatible with Advanced Authentication app.

C. Using OATH TOTP compliant hardware token

  1. Specify a comment in Comment. For example, HID token.

  2. Select the required category from Category.

  3. Specify your token's serial number in OATH Token Serial. The token’s serial number is displayed on the back of your token.

  4. Press the token's button and specify the OTP in OTP.

  5. Click Save.

    A message Authenticator "TOTP" added is displayed.

D. Using OATH TOTP compliant software token

  1. Specify a comment in Comment. For example, A phone app.

  2. Select the required category from Category.

  3. Specify the Enter TOTP secret manually.

  4. Specify the 40 hexadecimal characters in Secret.

  5. Select the Google Authenticator format of secret (Base32) option if you are using the Google Authenticator app.

  6. Change the value of Period value if required (30 seconds by default).

  7. Click Save.

    A message Authenticator "TOTP" added is displayed.

To test the enrolled authenticator, perform the following steps:

  1. Click the TOTP icon in the Enrolled methods section.

  2. Click Test.

    Then perform the following tasks based on the required preferences:

    A. Using Advanced Authentication smartphone app

  3. Open the NetIQ Auth app.

  4. Open the Enrolled Authenticators section to view Time Based One-Time Password.

  5. Specify the TOTP in Password.

  6. Click Next.

    B. Using Google Authenticator app

  7. Open the Google Authenticator app.

  8. Specify the One-time password in Password.

  9. Click Next.

    C. Using Google Authenticator app

  10. Specify the One-time password shown on your hardware token in Password.

  11. Click Next.

    D. Using Google Authenticator app

  12. Specify the One-time password shown on your hardware token in Password.

  13. Click Next.