Multi-Factor Authentication

The TS4300 has the option to use a one-time password for multi-factor authentication of local users and access through the REST API.

Figure 1. How it works

The TS4300 Tape Library supports multi-factor authentication (MFA) using authenticator apps that comply with RFC 6238 and the SHA-1 algorithm. This includes widely used apps such as:

  • Google Authenticator
  • Microsoft Authenticator
  • 1Password
  • Authenticator browser extensions

The TS4300 supports per-user Multi-Factor Authentication (MFA), allowing each user to register their preferred authenticator app—provided it complies with the RFC 6238 standard and uses the SHA-1 algorithm.

When multi-factor authentication is enabled on the library, a local user first logs into the library with a user name and password. Subsequently, the user is sent a one-time password to enter into a secondary screen. Library administrators can force local users to use multi-factor authentication.

If the user's regular login credentials and the one-time code are valid, the user gains access to the library.

Refer to Setting up Multi-factor authentication.