Zextras Auth Zimlet overview

The Zextras Auth Zimlet can be accessed from the "Zimlets" section of the Zimbra Web Client. Users do not need any CLI access to use the Zextras Auth.

The creation of a new credential allows to give access to the account, possibly including the Zextras Mobile Apps, to other persons without having to share the personal credentials.

zextras auth overview

From the zimlet, the user can:

  • Add new credentials by clicking on either Authentication Type (for text codes and QR codes) or One Time Password

  • Check the status and other information for every Authentication Type created. Each entry of the list displays the label of the password, its status, the service it is valid for, and its creation date.

  • Check the status and other information for every One Time Password. Here, each entry shows a description, its status, the failed attempts, and its creation date.

  • Manage the 2FA access. Each user can decide whether to enforce access using 2FA, unless its use has been enabled or disabled at COS, domain, or global level. In this case, only a greyed-out checkbox is shown.

  • Delete any credential created, by simply selecting it and clicking on the DELETE button

Users can in no case modify their assigned credentials, change the password of credentials they generate, or modify any property of the credential. Limited editing of a credential is strictly limited to the administrators.

In the remainder of this section, we give an overview of the various possibilities.

Create New Credentials: Text Code

To create a new Mobile Password (for EAS service), open the Zextras Auth Zimlet and click on Authentication type, then on NEW AUTHENTICATION.

  • Here, enter an easy to remember identifier for the password in the Authentication description field and select Text code as the Authentication mode:

zextras_auth_mobilepass1.png

  • Click Next. The new Mobile Password will be displayed:

zextras_auth_mobilepass2.png

  • Click on the small blue icon on the right-hand side of the password to copy it to the clipboard.

Mobile Passwords are randomly generated and cannot be displayed again after the creation is complete.
  • Click on DONE to close the Zextras Auth window. An entry for the new Mobile Password is now visible in the Active Passwords list of the Zextras Auth Zimlet.

zextras_auth_mobilepass3.png

Create New Credentials: QR Code

Zextras Auth can speed up and manage Zextras Application logins, such as those for the Team App and Drive App.

This is achieved through the creation of a QR Code, which the user can then scan from the App’s login page to log in. The procedure is very similar to the one described in the previous section.

QR Codes are a one-time credential only, meaning that once generated it will grant access to the app until the relevant credential itself is deleted from the account. Once generated, the QR Code can only be viewed once.

In order to create a new QR Code for Mobile Application, open the Zextras Auth Zimlet and click on Authentication type, then on NEW AUTHENTICATION.

  • Here, enter an easy to remember identifier for the password in the Authentication description field and select QR code as the Authentication mode:

zextras_auth_qrcode1.png

  • Click Next. The QR code for Mobile Application will be displayed:

zextras_auth_qrcode2.png

Use the Zextras mobile app to frame the code and grant access to the app.

QR Codes are randomly generated and cannot be displayed again after the creation is complete.
  • Click on DONE to close the Zextras Auth window. An entry for the new Mobile Application is now visible in the Active Passwords list of the Zextras Auth Zimlet.

zextras_auth_qrcode3.png

Create New Credentials: OTP

In order to create a new QR Code for One Time Password access, open the Zextras Auth Zimlet and click on One Time Password, then on NEW OTP.

zextras_auth_otp1.png

  • No additional step is required, you will be presented with the QR code and a list of PIN codes to be used for authentication.

zextras_auth_otp2.png

  • Click on the small blue icon on the right-hand side of the PIN list to print the codes on paper or to a file.

QR codes and its associated PINs are randomly generated and cannot be displayed again after the creation is complete.
  • Click on DONE to close the Zextras Auth window. An entry for the new OTP entry will be shown in the list.

The Description is automatically created using the email address to which it is associated.

zextras_auth_otp3.png

Delete Credentials

In order to delete a credential, simply select it from the list of Active passwords or OTPs, and click on the DELETE button:

zextras_auth_delete_credential.png

Click on YES to confirm the removal of the credential.