Skip to content

Setting Up and Using Duo

Note

The information here only pertains to using Duo with Holland Computing Center accounts.

For help with your general University (i.e. TrueYou) account and Duo, contact the Huskertech Help Center via email at support@nebraska.edu.

Use of Duo two-factor authentication (https://www.duosecurity.com) is required for access to HCC resources.

Users will connect via SSH and enter their username/passwords as usual. One additional authentication step through Duo is then needed before the login is completed. This second authentication can be in several different forms (cell phone, YubiKey hardware token), and is user-selectable at each login. A brief description of each is provided below. See the Duo Authentication Methods page for more details.

Initial Setup

Most HCC account holders use the Duo Mobile application on their smartphone or purchase a YubiKey USB device.

Smartphone

If you are not currently using Duo with your TrueYou account:

  1. Install the free Duo Mobile application from the Google Play Store, Apple App Store, or Microsoft Store

    Join one of HCC's Remote Open Office hours sessions every Tuesday and Thursday from 2-3 PM central to activate Duo. Contact hcc-support@unl.edu for alternate times if you are not able to attend.

    Faculty/staff members with a verified NU telephone number can enroll by phone. If you would like an HCC staff member to call your NU telephone number to enroll, please email hcc-support@unl.edu with a time you will be available.

If you are currently using Duo with your TrueYou account:

  1. You can request to use the same phone for HCC's Duo as you are using for TrueYou. Please contact hcc-support@unl.edu with the request using the email address associated with your TrueYou account. In the email, include the last 4 digits of the phone number for verification.

YubiKeys

YubiKey devices are currently a one-time cost of around $25 from HCC, or can be purchased from Yubico and added in-person at either HCC location. Purchasing a YubiKey from HCC must be done via a University cost object transfer (HCC cannot accept cash or credit cards). Please bring the cost object number with you if possible. YubiKeys are also available from the Husker Tech store in the UNL City Union. Note that YubiKeys are configured for HCC's Duo, and not for general YubiCloud or U2F use.

Required Yubikey Feature

If you are purchasing a Yubikey on your own or through Huskertech, the Yubikey must support the "OTP" protocol. On Yubico's website, this will be listed as "Yubico OTP".

Example login using Duo Push

This demonstrates an example login to Swan using the Duo Push method. Using another method (SMS, phone call, etc.) proceeds in the same way.  (Click on any image for a larger version.)

First, a user connects via SSH using their normal HCC username/password, exactly as before.

ubuntu@laptop:~$ ssh hccdemo@swan.unl.edu
Password:
Duo two-factor login for hccdemo

Enter a passcode or select one of the following options:

1. Duo Push to XXX-XXX-9368
2. Phone call to XXX-XXX-9368
3. SMS passcodes to XXX-XXX-9368 (next code starts with: 1)

Passcode or option (1-3):

login with Duo 2FA prompting to choose a login option

Account lockout

After 10 failed authentication attempts, the user's account is

disabled. If this is the case, then the user needs to send an email to hcc-support@unl.edu including his/her username and the reason why multiple failed authentication attempts occurred.

After entering the password, instead of completing the login, the user will be presented with the Duo prompt. This gives the choice to use any authentication method that the particular account is setup to use. In this example, the choices are Duo Push notification, SMS message, or phone call. Choosing option 1 for Duo Push, a request to verify the login will be sent to the user's smartphone.

Duo 2FA prompting if you're logging into swan

Simply tap Approve to verify the login.

approved window

Warning

If you receive a verification request you didn't initiate, deny the request and contact HCC immediately via email athcc-support@unl.edu

In the terminal, the login will now complete and the user will logged in as usual.

Swan terminal

2. Phone call to XXX-XXX-9368
3. SMS passcodes to XXX-XXX-9368 (next code starts with: 1)

Passcode or option (1-3): 1
Success. Logging you in...
Last login: Wed Jun 21 16:34:28 2023 from 10.71.104.42

Have questions? See the documentation!
https://hcc.unl.edu/docs/

For SLURM docs, see https://hcc.unl.edu/docs/submitting_jobs/

HCC currently has no storage that is suitable for HIPAA, PHI, PID, classified
or other data sets for which access is legally restricted. Users are not
permitted to store such data on HCC machines.

Blocks [      /home      ] [       /work       ] [      /common     ]
U:hccdemo=> [13.6% (2.7GiB/20GiB)] [0.0% (738.4MiB/50TiB)] [0.0% (263.8KiB/30TiB)]
G:demo----> [0.7% (3.3GiB/500GiB)] [0.0% (972.9MiB/50TiB)] [0.0% (14.3GiB/30TiB)]
E:--------> [17.9% (1.5TiB/8.4TiB)] [12.5% (678.2TiB/5.3PiB)] [55.1% (1PiB/1.9PiB)]

key: (Blocks) storage space
key: (U)ser, (G)roup, (E)ntire system
above output generated by 'hcc-du' command, type 'hcc-du -h' for more options

Purge policy on /work, see https://hcc.unl.edu/docs/handling_data/data_storage/#purge-policy

[hccdemo@login1.swan ~]$

Duo Authentication Methods

Duo Push

[Watch the Duo Push Demo]

Phone showing that the Login is approved

For smartphone or tablet users (iPhone, Android, Blackberry, Windows Phone), the Duo Mobile app is available for free. A push notification will be sent to the device, and users can simply confirm the login with one tap.

Duo Mobile Passcodes

Duo app with codes shown

The Duo Mobile app can also be used to generate numeric passcodes, even when internet and cell service is unavailable.  Press the key icon to generate a passcode.  The passcode is then entered manually at the login prompt to complete authentication.

SMS Passcodes

Duo Mobile with text messages for login codes

For non-smartphone users, Duo can send passcodes via normal text messages which are entered manually to complete login. Please note since this is an SMS message it may not be free, depending on the details of the particular cell phone plan.

Phone Callback

For users with cell phones who prefer not to use any of the above methods and for those with landline phones, Duo will call the phone and provide a passcode via automatic voice message. The passcode is then entered manually to complete the login.

YubiKey

[Yubico]

Yubikey shown

YubiKeys are USB hardware tokens that generate passcodes when pressed. With HCC clusters, there is no prompt to press on the YubiKey. When the DUO prompt appears in the terminal, press the YubiKey and it will output a string to the terminal to authenticate you. They appear as a USB keyboard to the computer they are connected to, and so require no driver software with almost all modern operating systems. YubiKeys are available from the Husker Tech store at UNL. Users may also purchase them directly from Yubico if desired; this does require stopping by either HCC location in person to have the YubiKey added to the user's account. For your convenience, HCC often carries some YubiKeys as well; these may only be purchased via a Cost Object transfer.

Setting up a Yubikey for DUO

If you are bringing a YubiKey for your account, it will need to be configured specifically for HCC's DUO.

Self-Provided YubiKeys must support the Yubico OTP protocol

HCC Setup

The YubiKey can be brought into either of HCC's offices by appointment to be setup. Appointments can be setup by emailing HCC support at hcc-support@unl.edu

There must be one free slot. Yubikeys will typically have two slots, the short tap and long press.

Self Setup

You can also set up the YubiKey remotely with HCC either by email at hcc-support@unl.edu or in the Open Office Hours every Tuesday and Thursday from 2-3 PM central.

There must be one free slot. Yubikeys will typically have two slots, the short tap and long press.

You will also need to install the YubiKey Manager on your computer.

Instructions
  1. Open YubiKey Manager.
  2. Insert the YubiKey into a USB port.
  3. Wait for the YubiKey Manager app to recognize the YubiKey.
  4. Once the YubiKey has been recognized, the app will display the device's serial number and name.
  5. Note the Serial Number.
  6. From the Applications menu at the top, select OTP.
  7. Select an empty configuration slot using the Configure button under the respective slot.
  8. Select Yubico OTP as the credential type.
  9. Click Next.
  10. Check Use serial for Public ID.
  11. Click Generate for both Private ID and Secret Key.
  12. Copy the following values into a text document:
    • Serial Number - 6-8 digit numeric
    • Private ID - 12 character alphanumeric
    • Secret Key(s) - 32 character alphanumeric
  13. Leave the box for upload un-checked and select Finish.
  14. This will save the settings to your YubiKey.
  15. Exit the YubiKey Manager.
  16. Email hcc-support@unl.edu and provide the Serial Number, Private ID and Secret Key(s) noted in Step 12 into the appropriate fields.