Otherwise, follow the written and illustrated steps below.
Prerequisite
Warning :
Below, click the icon (“Show steps in list”) to miss none.
Procedure
(If necessary) Install KeepassXC and optionally its extension⚓
If your workstation is managed by DNum : KeepassXC and its extension are pre‑installed on Windows and Linux machines (extension on Firefox). For macOS, contact us if needed.
⚠️ No one will be able to recover this password if you lose it. Don't worry, if you follow our creation recommendations (link above), it should be easy for you to remember ... while being difficult for others to find.
Choose the storage location of your database on your workstation.
⚠️ Make sure to choose a location located in your AD (usually “Desktop” or “Documents”) or synchronized via Seafile, to ensure a regular backup of it.
Select the entry then click on the Entries tab, Time‑based One‑Time Password (TOTP) then Configure TOTP…
On CAS‑MFA, select and copy the string of characters displayed just below the QR code (uppercase letters and numbers).
Back in KeepassXC, in the window that opened, paste the string into the Secret Key field. You can leave the other parameters at their defaults.
Validate the entry recording by clicking OK.
✨ If you want to use the KeepassXC browser extension so that your TOTP codes are automatically entered, your entry must at minimum also contain the URL “https://cas.unistra.fr”. If needed, click on it then Edit Entry… to add it.
Generate your 1st TOTP and validate the method activation⚓
In KeepassXC, right‑click on your TOTP entry and, in the context menu, click on Time‑based One‑Time Password (TOTP) then Copy TOTP.
You can also, as an alternative, select the entry and use the keyboard shortcut Ctrl+T.
Back on the CAS‑MFA page, paste into the right‑hand field requesting a 6‑digit code then click Validate.
Note: The copied code is valid for 10 seconds; if needed, repeat your copy/paste.
If the TOTP method activation succeeded, the CAS‑MFA page changes to show the active slider.
Otherwise, retry the entry or copy‑paste of the 1st TOTP more quickly (which may have expired).
Although optional, the following steps can considerably simplify your daily use.
Tip :
✨ Do you want to use the KeepassXC browser extension so that your TOTP codes are automatically entered? Once the extension is installed in the browser (see previous steps), establish the link between KeepassXC and it:
In KeepassXC, go to the Tools tab then Settings.
In the left column, select the Browser Integration tab.
Check the box Enable browser integration then the boxes for the browsers you use (by default, at least check Firefox). Validate by clicking OK.
Open your browser (e.g., Firefox) and, at the top right of the window, click the icon representing a puzzle piece (the “Extensions” or “Add‑ons”).
Click on the “KeePassXC‑Browser” extension then on Connect.
A window opens and KeepassXC asks to link your vault/database with your browser: give a name to this link (optional) then click Save and allow access.
Close and then restart your Firefox browser to use the extension.
This configuration is to be performed only once, during activation. If the method is already activated, you can use it directly.
Tip : Do you prefer to follow a video tutorial? ✨⚓
If you have never used KeepassXC or have not yet created an entry for your Unistra account, start with this dedicated tutorial: Configure KeepassXC and its browser extension.
Then: Activate and use the TOTP code with KeepassXC.
Otherwise, follow the written and illustrated steps below.
Warning :
Below, click the icon
(“Show steps in list”) to miss none.
If your workstation is managed by DNum : KeepassXC and its extension are pre‑installed on Windows and Linux machines (extension on Firefox). For macOS, contact us if needed.
If you manage your workstation yourself : from the vendor's site, you can download and install KeepassXC (Windows, macOS, Linux), at https://keepassxc.org/download then its browser extension at https://keepassxc.org/download/#browser
Once KeepassXC is installed, if not already done, perform its initial configuration:
Open KeepassXC then click on
Create a database.This is the encrypted file that will store the various usernames and passwords you entrust to it.
Enter a name for this database (optional).
Set the encryption parameters. You can use the default settings (“KBDX”).
Choose a strong password (ideally a good passphrase) to unlock your database, i.e., access all passwords stored in this database. Do not use your Unistra password!
⚠️ No one will be able to recover this password if you lose it. Don't worry, if you follow our creation recommendations (link above), it should be easy for you to remember ... while being difficult for others to find.
Choose the storage location of your database on your workstation.
⚠️ Make sure to choose a location located in your AD (usually “Desktop” or “Documents”) or synchronized via Seafile, to ensure a regular backup of it.
On CAS-MFA, click on the three‑star tile indicating “that a code (TOTP) is generated ...”
Click on the slider to
Activatethe method.A QR code and a string of characters are displayed. This is the secret that will allow the application you have chosen to calculate the TOTP codes.
1. In KeepassXC, create an “entry” to hold the secret⚓
If you already have an entry for your Unistra password, go directly to step 2.
Otherwise, start by creating an entry:
Go to the
Entriestab thenNew entry...Enter the information you need: at minimum a
Title(the name of your entry).Validate by clicking
OK.2. Associate this entry with your TOTP⚓
Select the entry then click on the Entries tab, Time‑based One‑Time Password (TOTP) then Configure TOTP…
On CAS‑MFA, select and copy the string of characters displayed just below the QR code (uppercase letters and numbers).
Back in KeepassXC, in the window that opened, paste the string into the Secret Key field. You can leave the other parameters at their defaults.
Validate the entry recording by clicking OK.
✨ If you want to use the KeepassXC browser extension so that your TOTP codes are automatically entered, your entry must at minimum also contain the
URL“https://cas.unistra.fr”. If needed, click on it thenEdit Entry…to add it.In KeepassXC, right‑click on your TOTP entry and, in the context menu, click on Time‑based One‑Time Password (TOTP) then Copy TOTP.
You can also, as an alternative, select the entry and use the keyboard shortcut Ctrl+T.
Back on the CAS‑MFA page, paste into the right‑hand field requesting a 6‑digit code then click Validate.
Note: The copied code is valid for 10 seconds; if needed, repeat your copy/paste.
If the TOTP method activation succeeded, the CAS‑MFA page changes to show the active slider.
Otherwise, retry the entry or copy‑paste of the 1st TOTP more quickly (which may have expired).
Although optional, the following steps can considerably simplify your daily use.
Tip :
✨ Do you want to use the KeepassXC browser extension so that your TOTP codes are automatically entered? Once the extension is installed in the browser (see previous steps), establish the link between KeepassXC and it:
In KeepassXC, go to the Tools tab then Settings.
In the left column, select the Browser Integration tab.
Check the box Enable browser integration then the boxes for the browsers you use (by default, at least check Firefox). Validate by clicking OK.
Open your browser (e.g., Firefox) and, at the top right of the window, click the icon representing a puzzle piece (the “Extensions” or “Add‑ons”).
Click on the “KeePassXC‑Browser” extension then on Connect.
A window opens and KeepassXC asks to link your vault/database with your browser: give a name to this link (optional) then click Save and allow access.
Close and then restart your Firefox browser to use the extension.