


{"id":4781,"date":"2017-02-08T08:50:27","date_gmt":"2017-02-08T15:50:27","guid":{"rendered":"https:\/\/xmission.com\/blog\/?p=4781"},"modified":"2017-11-06T09:44:57","modified_gmt":"2017-11-06T16:44:57","slug":"6-steps-to-zimbra-two-factor-authentication-with-yubikey","status":"publish","type":"post","link":"https:\/\/xmission.com\/blog\/2017\/02\/08\/6-steps-to-zimbra-two-factor-authentication-with-yubikey","title":{"rendered":"6 steps to Zimbra two-factor authentication with YubiKey"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"alignright size-medium wp-image-4799\" src=\"https:\/\/xmission.com\/blog\/wp-content\/uploads\/2017\/02\/2fa_XM_Yubikey_Zimbra-300x225.jpg\" alt=\"\" width=\"300\" height=\"225\" srcset=\"https:\/\/xmission.com\/blog\/wp-content\/uploads\/2017\/02\/2fa_XM_Yubikey_Zimbra-300x225.jpg 300w, https:\/\/xmission.com\/blog\/wp-content\/uploads\/2017\/02\/2fa_XM_Yubikey_Zimbra.jpg 384w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/>We are proud to announce that XMission Zimbra\u00a0<a href=\"https:\/\/xmission.com\/zimbra\" target=\"_blank\" rel=\"noopener\">Email and Collaboration<\/a> now features two-factor authentication (2FA). Two-factor authentication is a technology that provides identification of users utilizing\u00a0two different components. Typically something\u00a0that you\u00a0know (like a password, UserID, etc) and something you have\u00a0(a smartphone, USB-key, etc.). Using 2FA protects you against phishing and other sophisticated attacks.<\/p>\n<p>In this post we&#8217;re working with the YubiKey NEO and an Android smartphone. The\u00a0<a href=\"https:\/\/www.amazon.com\/gp\/product\/B00LX8KZZ8\/ref=as_li_tl?ie=UTF8&amp;camp=1789&amp;creative=9325&amp;creativeASIN=B00LX8KZZ8&amp;linkCode=as2&amp;tag=xmis-20&amp;linkId=a99f347bb39e3f146eb25ce2568eb5c2\" target=\"_blank\" rel=\"noopener\">YubiKey NEO<\/a><img loading=\"lazy\" decoding=\"async\" style=\"border: none !important; margin: 0px !important;\" src=\"\/\/ir-na.amazon-adsystem.com\/e\/ir?t=xmis-20&amp;l=am2&amp;o=1&amp;a=B00LX8KZZ8\" alt=\"\" width=\"1\" height=\"1\" border=\"0\" \/>\u00a0USB and NFC security key offers an easy and secure way to log in to your services such as <a href=\"https:\/\/blog.zimbra.com\/2016\/02\/zimbra-collaboration-8-7-two-factor-authentication-2fa-technical-preview\/\" target=\"_blank\" rel=\"noopener\">Zimbra<\/a>, <a href=\"https:\/\/www.cnet.com\/news\/facebook-passwords-login-with-key-token-two-factor-authentication\/\" target=\"_blank\" rel=\"noopener\">Facebook<\/a>, Salesforce, GitHub and many more. YubiKeys are also supported by leading password managers, including <a href=\"https:\/\/lastpass.com\/yubico\" target=\"_blank\" rel=\"noopener\">LastPass<\/a>, <a href=\"http:\/\/keepass.info\/help\/kb\/yubikey.html\" target=\"_blank\" rel=\"noopener\">KeePass<\/a>, and others. We like the super convenient NFC feature in the Neo. (NFC is use by services like ApplePay and Google Wallet and is what allows you to tap your mobile devices to payment kiosks as well as this two-factor authentication method where you simply touch your USB key to your phone.)<\/p>\n<p>Purchase your own\u00a0<a href=\"https:\/\/www.amazon.com\/gp\/product\/B00LX8KZZ8\/ref=as_li_tl?ie=UTF8&amp;camp=1789&amp;creative=9325&amp;creativeASIN=B00LX8KZZ8&amp;linkCode=as2&amp;tag=xmis-20&amp;linkId=a99f347bb39e3f146eb25ce2568eb5c2\" target=\"_blank\" rel=\"noopener\">YubiKey NEO<\/a>\u00a0<img loading=\"lazy\" decoding=\"async\" src=\"\/\/ir-na.amazon-adsystem.com\/e\/ir?t=xmis-20&amp;l=am2&amp;o=1&amp;a=B00LX8KZZ8\" alt=\"\" width=\"1\" height=\"1\" border=\"0\" \/>on Amazon.<\/p>\n<p>Here is how to configure:<\/p>\n<p><strong>Step 1:<\/strong> Download the\u00a0<a href=\"https:\/\/www.yubico.com\/support\/knowledge-base\/categories\/downloads\/\" target=\"_blank\" rel=\"noopener\">Yubico Authenticator<\/a> app for Android or Desktop.<\/p>\n<p><strong>Step 2:<\/strong> Insert YubiKey into your computer&#8217;s USB port or tap YubiKey to phone for NFC.<\/p>\n<p><strong>Step 3:<\/strong>\u00a0On the Android phone, in the Yubico Authenticator app, tap the menu button in the top right corner of your screen and tap &#8220;Add account manually.&#8221; Here you will be asked for a name, code, and protocol. You can name it whatever you want, and the protocol should be set to TOTP.<\/p>\n<p><strong>Step 4:<\/strong> Log in to <a href=\"https:\/\/zimbra.xmission.com\" target=\"_blank\" rel=\"noopener\">Zimbra<\/a>, go to the Preferences tab along the top, then select Accounts in left column. Under Account Security, click on &#8220;Setup two-factor authentication&#8230;&#8221; Click &#8220;Begin Setup&#8221;\u00a0on the window that appears.<\/p>\n<p><a href=\"https:\/\/xmission.com\/blog\/2017\/02\/08\/6-steps-to-zimbra-two-factor-authentication-with-yubikey\/2fa_xm_zimbra_accountsecurity\" rel=\"attachment wp-att-4782\"><img loading=\"lazy\" decoding=\"async\" class=\"alignright size-full wp-image-4782\" src=\"https:\/\/xmission.com\/blog\/wp-content\/uploads\/2017\/02\/2fa_XM_Zimbra_AccountSecurity.png\" alt=\"\" width=\"579\" height=\"64\" srcset=\"https:\/\/xmission.com\/blog\/wp-content\/uploads\/2017\/02\/2fa_XM_Zimbra_AccountSecurity.png 579w, https:\/\/xmission.com\/blog\/wp-content\/uploads\/2017\/02\/2fa_XM_Zimbra_AccountSecurity-300x33.png 300w\" sizes=\"auto, (max-width: 579px) 100vw, 579px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>&nbsp;<\/p>\n<p>Now confirm your Zimbra password and click &#8220;Next&#8221; to proceed.<\/p>\n<p>The next\u00a0screen instructs you to install an authentication application on\u00a0your phone and has a Zimbra.com wiki link to other <a href=\"https:\/\/wiki.zimbra.com\/wiki\/TOTPApps\" target=\"_blank\" rel=\"noopener\">TOTP authentication apps<\/a> for Android, iOS, and Windows. In Step 1 above, we installed the Yubico App on your phone so click\u00a0&#8220;Next&#8221; to get\u00a0your authentication code.<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"https:\/\/xmission.com\/blog\/2017\/02\/08\/6-steps-to-zimbra-two-factor-authentication-with-yubikey\/2fa_xm_zimbra_code_example\" rel=\"attachment wp-att-4784\"><img loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-4784\" src=\"https:\/\/xmission.com\/blog\/wp-content\/uploads\/2017\/02\/2fa_XM_Zimbra_code_example-300x175.png\" alt=\"\" width=\"212\" height=\"124\" srcset=\"https:\/\/xmission.com\/blog\/wp-content\/uploads\/2017\/02\/2fa_XM_Zimbra_code_example-300x175.png 300w, https:\/\/xmission.com\/blog\/wp-content\/uploads\/2017\/02\/2fa_XM_Zimbra_code_example.png 507w\" sizes=\"auto, (max-width: 212px) 100vw, 212px\" \/><\/a><strong><br \/>\nStep 5:<\/strong> Enter code generated by Zimbra into the &#8220;Secret key&#8221; field in the Yubico Authenticator app and click &#8220;Add&#8221;<\/p>\n<p><strong>Step 6:<\/strong>\u00a0Tap or plug in YubiKey\u00a0again to save settings.<\/p>\n<p>Now that you have this configured, your YubiKey will work with your phone and desktop.\u00a0<em>\u00a0<\/em><\/p>\n<p><em>NOTES: <\/em><\/p>\n<ul>\n<li><em>All YubiKeys, and many other brands of security USB keys, will work with Zimbra two-factor authentication and your desktop or laptop.<\/em><\/li>\n<li><em>iPhones and iPads have very limited support with YubiKey devices but still work with Zimbra 2FA.<\/em><\/li>\n<li><em>Paid editions\u00a0of Zimbra Collaboration 8.7.X \u00a0supports two-factor authentication. Open source edition does not support 2FA.<\/em><\/li>\n<\/ul>\n<p>Don&#8217;t forget, Zimbra makes it simple\u00a0to further secure sensitive\u00a0email messages. See our post on how to easily use\u00a0<a href=\"https:\/\/xmission.com\/blog\/2016\/11\/09\/easily-encrypt-sign-email-with-zimbra-and-openpgp\" target=\"_blank\" rel=\"noopener\">PGP encryption.<\/a><\/p>\n<p>Using encryption is easy and a great practice to use in your day to day communications. To sign up for\u00a0<a href=\"https:\/\/xmission.com\/zimbra\" target=\"_blank\" rel=\"noopener\">Email and Collaboration <\/a> or <a href=\"https:\/\/xmission.com\/licensing\" target=\"_blank\" rel=\"noopener\">buy licensing<\/a> for your own on-premise Zimbra mail server, please <a href=\"mailto:zimbrasales@xmission.com\">contact John<\/a>.<\/p>\n<p>Please comment or ask questions below. We would love to hear from you. Remember, sharing is easy as clicking on of the social buttons below.<\/p>\n<p><em><a title=\"Connect with me on LinkedIn, john801\" href=\"mailto:john@xmission.com\" target=\"_blank\" rel=\"noopener\">John Webster<\/a>, \u00a0XMission Email Product Manager and Zimbra evangelist, has worked at <a title=\"Go, XMission!\" href=\"https:\/\/xmission.com\/\" target=\"_blank\" rel=\"noopener\">XMission<\/a> for over 20 years doing his favorite thing: helping companies securely communicate with\u00a0customers\u00a0through\u00a0technology to grow their\u00a0business. When he\u2019s not uncovering <a title=\"More Zimbra tips from John\" href=\"http:\/\/xmission.com\/blog\/?s=zimbra&amp;searchsubmit=Search\" target=\"_blank\" rel=\"noopener\">Zimbra\u2019s secrets<\/a>\u00a0you might find him in our beautiful Utah mountains. \u00a0<a title=\"Connect with me on LinkedIn, john801\" href=\"https:\/\/www.linkedin.com\/in\/john801\" target=\"_blank\" rel=\"noopener\">Connect with him on LinkedIn today!<\/a><\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>We are proud to announce that XMission Zimbra\u00a0Email and Collaboration now features two-factor authentication (2FA). Two-factor authentication is a technology that provides identification of users utilizing\u00a0two different components. Typically something\u00a0that you\u00a0know (like a password, UserID, etc) and something you have\u00a0(a smartphone, USB-key, etc.). Using 2FA protects you against phishing and other sophisticated attacks. In this [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[179,449,253,255,397,396,610,310,468,139,3,123,399,398,39],"tags":[578,608,577,216,611,579,576,580],"class_list":["post-4781","post","type-post","status-publish","format-standard","hentry","category-cloud","category-collaboration","category-email-2","category-exchange-replacement","category-licensing","category-mail-server","category-multi-factor-authentication","category-open-source","category-open-source-edition","category-privacy","category-security-safety","category-stuff-we-like","category-value-added-reseller","category-var","category-zimbra","tag-2fa","tag-advanced-protection","tag-authentication","tag-encryption","tag-multi-factor-authentication","tag-two-factor-authentication","tag-yubikey","tag-yubikey-neo"],"_links":{"self":[{"href":"https:\/\/xmission.com\/blog\/wp-json\/wp\/v2\/posts\/4781","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/xmission.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/xmission.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/xmission.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/xmission.com\/blog\/wp-json\/wp\/v2\/comments?post=4781"}],"version-history":[{"count":28,"href":"https:\/\/xmission.com\/blog\/wp-json\/wp\/v2\/posts\/4781\/revisions"}],"predecessor-version":[{"id":5077,"href":"https:\/\/xmission.com\/blog\/wp-json\/wp\/v2\/posts\/4781\/revisions\/5077"}],"wp:attachment":[{"href":"https:\/\/xmission.com\/blog\/wp-json\/wp\/v2\/media?parent=4781"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/xmission.com\/blog\/wp-json\/wp\/v2\/categories?post=4781"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/xmission.com\/blog\/wp-json\/wp\/v2\/tags?post=4781"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}