CreaRack-SL

MFA, passkeys and login security

What it is

CreaRack supports multi-factor authentication with three device types:

  • Passkey — the modern, phishing-resistant option: your fingerprint, face or device PIN (Windows Hello, Touch ID, a hardware key). Recommended.
  • TOTP — six-digit codes from an authenticator app (Google Authenticator, Authy, 1Password…).
  • Recovery codes — one-time backup codes for when you lose the other two. Store them somewhere safe.

How to set up MFA

  1. Open User Settings (Configuration → Users → User Settings) and click Set up MFA (or View My Devices if you already have some).
  2. Add a Passkey: your browser walks you through the fingerprint/face/PIN registration. The Sign in with Passkey button on the login page always shows your browser’s account picker (for example Windows Hello) rather than jumping straight to the fingerprint or PIN reader — this way it never gives away whether a given username actually exists.
  3. Or add TOTP: scan the QR with your authenticator app and confirm with a code.
  4. Generate your Recovery codes and keep them offline.

“My Security Devices” lists everything you have registered with the date it was added.

If a user loses their MFA device

An Admin can rescue them: Configuration → Users → User Settings → click MFA next to the user → Remove the lost device (or Remove All). The user logs in with their password and registers a new device.

Login history

Admins can audit sign-ins from User Settings (Configuration → Users → User Settings): under Add New User, click View Login History. It opens in its own window and loads the latest attempts straight away, with columns “Time”, “User”, “Status”, “Method” and “IP”. Use the user filter to see one person’s attempts (the list reloads when you change it), or Load History to refresh. Failed attempts from unexpected addresses are the first thing to look at if you suspect something.

Session timeout

In User Settings (Admins only), the “Timeout (minutes)” field controls automatic logout after inactivity: 0 disables it, the maximum is 120, the default is 10. Click Save Timeout Setting. For shared or kiosk PCs, keep it short.

The timeout is enforced on the server as well as in the browser: if no request reaches CreaRack for that many minutes — the tab was closed, the PC was turned off — the session stops being valid and you have to sign in again, even if nothing in the browser itself ran the countdown.

Monitoring screens stay signed in. Observatory, Wireless, UPS and Digital Signage (including their group and device panels) are built to stay open indefinitely on a control-room display, so they are exempt from the inactivity timeout — neither the browser nor the server signs them out while the tab stays open, even with nobody touching the mouse or keyboard. Every other page still signs out after the configured minutes of no mouse or keyboard activity, as before; while you are working on a page that does not talk to the server on its own, the browser pings it periodically in the background so you are not cut off mid-task. Setting the timeout to 0 disables it everywhere, as before.

Troubleshooting

  • “Passkey not recognized” on a new PC — passkeys can be tied to the device where you created them. Use TOTP or a recovery code to get in, then register a passkey on the new machine.
  • Authenticator codes rejected — the phone’s clock is off. Enable automatic time on the phone; TOTP depends on it.
  • Out of recovery codes — ask an Admin to reset your MFA from Users Management.
  • Signed out of a normal page while still working — that is the inactivity timeout; it now also applies if your PC or network drops out, not just when the browser detects no clicks or keystrokes. Ask an Admin to increase the timeout in User Settings if it is too aggressive for how you work. Observatory, Wireless, UPS and Signage screens are unaffected by this timeout while their tab stays open.
  • [[crearack—settings—user-management]] — managing users and their MFA as an Admin
  • [[crearack—settings—system-logs]] — the audit trail

Véase también

  • [[crearack—settings—user-management]]
  • [[crearack—settings—system-logs]]