Skip to main content

Set Up a SecurID PIN (Software Fob)

Hardware or software key fobs are available for people who need to log into servers in the Extra Tier and for some high-security applications.

This article applies to: Managed Servers


On this page:

For Non-Cornell Employees Only

If you are not a Cornell employee, follow these steps before setting up your software token.

  1. Activate your Cornell NetID.
  2. Install and connect to the Cornell VPN. Use the following credentials to log onto the VPN.
    For more information, see the VPN pages
    • Group: CornellVPN
    • Username: netid@cit.roc
    • Password: your Cornell NetID password
  3. Confirm that your IP address is 10.17.29.x

Using the Cornell VPN and your cit.roc credentials ensures that you connect to a server farm network that is protected by our firewalls.


Download the App and Receive a Setup Password

Complete this procedure only once during initial setup.

Your unit or area manager will request a soft token from System Support for you. Before starting this procedure, be sure you have received an email from Systems Support that includes both a soft token and a link to your RSA SecurID phone app password at DropBox.

  1. Download the RSA SecurID app.
    From the app store for your device, download the RSA SecurID app.
  2. Retrieve the password.
    Systems Support sends the password to you via DropBox. You'll need to retrieve this password from DropBox on your device during the setup of your RSA SecurID app. It is used only once during the initial setup.

Create Your PIN

Complete this procedure only once during initial setup.

  1. Open the RSA SecurID app on your device and tap Import Token.
  2. Enter the soft token you received in an email from Systems Support.
    It looks like a URL and starts with http://127.0.0.1/securid.
    Depending on the type of device you're using, you may be able to click the link in the email or copy and paste the soft token.
  3. When prompted to enter a password, enter the password that was sent to you through Dropbox (https://dropbox.cornell.edu/).
  4. When prompted to enter a PIN, enter 0000. The app generates a code. You'll need this code in step 7.
  5. Use Remote Desktop to connect to this server: hopperrdp.cit.cornell.edu.
    You must be on a campus network or the Cornell VPN.


     
  6. You'll be prompted to enter your NetID and password.
    Note: If you don't see the Cornell domain, your username is cornell\netid. The password is your Cornell NetID password.


     
  7. Click the RSA SecurID logo.


     
  8. In Username, enter your NetID.
    In Passcode, enter the code that was generated when you entered 0000 in the RSA SecurID app.
    Note: This is a temporary passcode used only when you're creating your PIN.


     
  9. You will be prompted to set a PIN. Enter a numeric PIN from 4-8 digits, and then click Finish.
    This is the PIN you will enter in the RSA SecurID app on your phone in the future.


     
  10. In the RSA SecurID app on your device, press Back until you are prompted for the PIN, and then enter the PIN you just created. The RSA SecurID app will display a passcode.
  11. On your computer, you should see the login prompt again.
    In User name, enter your NetID.
    In Passcode, enter the passcode from the RSA Secure ID app.
    Note: You can only use the number that the SecurID app displays once.


     
  12. The first time you log in, you will be prompted to enter your Windows password. Click OK.


     
  13. In Password, enter your password from the Cornell domain. (For most people, this is your NetID password.)
    Note: You should only see this prompt the first time you log into a SecurID system.


     

It may take a minute or two for the system to create your new profile. When it finishes, you'll be logged in and ready to RDP to your servers. To RDP to a server, click Start, then Accessories, then Remote Desktop Connections. You can drag and drop to make this a shortcut on your remote desktop as shown in the following image.

Important! If you downloaded the file containing your password from DropBox, be sure to securely delete the file.


Use Two-Factor Authorization to Log In to Your Servers

If you have not already done so, first download the RSA SecurID app and then create a PIN.

  1. Open the RSA SecurID app on your device, and when prompted enter your PIN. The app generates a code. You'll need this code in step 5.
  2. Connect to this server: hopperrdp.cit.cornell.edu.
    You must be on a campus network or the Cornell VPN.


     
  3. You'll be prompted to enter your NetID and password.
    Note: If you don't see the Cornell domain, your username is cornell\netid. The password is your Cornell NetID password.


     
  4. Click the RSA SecurID logo.


     
  5. In User name, enter your NetID.
    In Passcode, enter the code that was generated in the RSA SecurID app.


     
  6. If prompted, enter your Windows password, and then click OK.


     
  7. You're now logged in and can RDP to your servers. To RDP to a server, click Start, then Accessories, then Remote Desktop Connections. You can drag and drop to make this a shortcut on your remote desktop as shown in the following image.

Was this page helpful?

Your feedback helps improve the site.

Comments?