Primary device: smartphone – secondary device: PC/laptop

1. Setting up a KeePassXC database

KeePassXC is already pre-installed on most university computers. If not, please install KeePassXC on your PC or laptop.

  1. Launch KeePassXC.
  2. Click on “Create Database” or, via the menu, select “Database” and then “New Database…”.
  3. Enter a name for the database.
  4. Leave the encryption settings as they are and confirm by clicking the “Next” button.
  5. Choose a secure password for the database. If KeePassXC flags your password as insecure, it is too short. (You can also specify a key file.)
  6. Click “Finish” and then select a save location in the “Save database as” dialogue box.

The KeePassXC database has now been created. You can now use it to manage multiple passwords and TOTP database entries.

Note

If you are working exclusively on the university network, it is advisable to save the database in your home directory on the central file server (usually drive H:). In this case, no further backup is required.

In all other cases, the database file should be backed up – just like all other data.

2. Set up a database entry using TOTP

Once the database you have just created or an existing one has been opened in KeePassXC, you can now configure an entry for TOTP. It is advisable to change the time settings in KeePassXC first.

Change time settings

  1. Click on the cog icon or select ‘Tools’ and ‘Settings’ from the menu.
  2. Go to the ‘Security’ category.
  3. Change the ‘Clear clipboard’ value to ‘30’ seconds.
  4. Click the ‘OK’ button to save the change.

Set up a database entry

  1. Click on the plus icon or, in the menu, select “Entries” and “New entry …”.
  2. Enter the title “2FA University of Greifswald” and enter your username for the database entry.
  3. Click “OK” to save the database entry.
  4. Right-click on the database entry or select “Entries” from the menu.
  5. Under “TOTP”, select the menu option “Set up TOTP…”.
  6. Open a web browser and log in to the account management portal using your username and password.
  7. Navigate to My Account / Two-factor authentication.
  8. You will now see a page with a QR code.
  9. Under Option B: Manual Setup, click the “Show details” link.
  10. Copy the TOTP secret using the “Copy” link.
  11. Return to the KeePassXC programme.
  12. In KeePassXC, paste the TOTP secret from the account management section into the “Secret key” field (STRG + V).
    This helps you avoid unnecessary errors when copying, such as extra spaces.
  13. Click “OK” to save the TOTP secret (secret key) in KeePassXC.

KeePassXC is now set up on your secondary device and configured to generate TOTP codes.