VaultTub: Difference between revisions
Update to be more accurate to the current system |
No edit summary |
||
| Line 1: | Line 1: | ||
VaultTub is | VaultTub is a password manager managed by [[Bath Open Source Society]] which allows societies to store and share passwords securely. It can be accessed at [https://vault.bathcs.com vault.bathcs.com]. | ||
For more detailed instructions, see [https://bitwarden.com/help/ BitWarden’s documentation]. | |||
For | |||
== Quick setup == | == Quick setup == | ||
You should be messaged or told by the previous committee that you need to sign up so they can invite you. All Bath students can freely make an account (though we ask you not to store your personal passwords on there). | |||
You should be | |||
<ol style="list-style-type: decimal;"> | <ol style="list-style-type: decimal;"> | ||
<li><p>Go to [https://vault.bathcs.com vault.bathcs.com]</p></li> | <li><p>Go to [https://vault.bathcs.com vault.bathcs.com].</p></li> | ||
<li><p>Enter your uni email and click "Use single sign-on"</p></li> | <li><p>Enter your uni email and click "Use single sign-on".</p></li> | ||
<li><p>Once redirected to our authentication site, enter your | <li><p>Once redirected to our authentication site (Authelia), enter your University username and password.</p></li> | ||
<li><p>You will be redirected back and asked to create a master password</p>{{Note|text=If you lose the password you will | <li><p>You will be redirected back to VaultTub and asked to create a master password. Use a brand new password that you will not forget.</p>{{Note|text=If you lose the master password you will lose all access to VaultTub.|type=warn}}</li> | ||
<li><p>You may also receive emails during this process, if the email is in '''junk''', there should be a dropdown at the top of the email with the option to make “vault@bathcs.com” never go to your junk folder. Please select this as you will get a lot more emails after this point.</p></li> | <li><p>You may also receive emails during this process, if the email is in '''junk''', there should be a dropdown at the top of the email with the option to make “vault@bathcs.com” never go to your junk folder. Please select this as you will get a lot more emails after this point.</p></li> | ||
<li><p>''' | <li><p>'''Required''': [[#Two-step login|Set up 2FA]]</p></li> | ||
<li><p>''' | <li><p>'''Required''' '''for [[VaultTub#Organisation owners|Owners of organisations]]''': set up [[#Emergency Access|emergency access]]</p></li></ol> | ||
Outgoing committees/initiatives will add you to the relevant organisation as described in the handover procedure. Please ensure that they do this, otherwise you will lose all access to the society's passwords. | |||
Please | |||
== Recommended Settings == | == Recommended Settings == | ||
| Line 37: | Line 26: | ||
=== Two-step login === | === Two-step login === | ||
{{Note|type= | {{Note|type=info|text= | ||
Two-factor authentication is '''mandatory''' for everyone. | |||
}} | }} | ||
Go to [https://vault.bathcs.com/#/settings/security/two-factor Two-step login settings] and choose a provider. For the best security we recommend Authenticator app or Passkey. | |||
=== Emergency | === Emergency access === | ||
{{Note|text= | {{Note|text= | ||
Emergency access is '''mandatory''' for all [[#Organisation owners|Owners of organisations]]. | |||
|type= | |type=info}} | ||
We recommend setting up emergency access with at least 1 other person, this is for safety if you lose access to your account. | We recommend setting up emergency access with at least 1 other person, this is for safety if you lose access to your account. | ||
First, ask your trusted contact to create a VaultTub account. Once they have done that, head to [https://vault.bathcs.com/#/settings/emergency-access Emergency access settings] and click “Add emergency contact”. Enter the user's email and ask them to follow the instructions they receive via email. Once all the steps are complete, go back to the Emergency access tab and verify that they show up as expected. | |||
{{Note|type=warn|text=Make sure you verify that the user was added completely. It is easy to accidentally forget a step.}} | |||
Emergency access is required for users with a significant amount of power due to the risk of losing everything (we cannot recover your passwords). | |||
=== Using the extension/app === | === Using the extension/app === | ||
Bitwarden has a [https://bitwarden.com/download/#downloads-web-browser browser extension] and an [https://bitwarden.com/download/#downloads-mobile app] which | Bitwarden has a [https://bitwarden.com/download/#downloads-web-browser browser extension] and an [https://bitwarden.com/download/#downloads-mobile app] which support self-hosted instances (and multiple accounts). | ||
{{Note|text= | {{Note|text= | ||
| Line 93: | Line 72: | ||
==== Adding a Login ==== | ==== Adding a Login ==== | ||
You can easily add a login by clicking the "New" button within the app, and filling out the details, along with the "website". Please make sure the owner is set to the | You can easily add a login by clicking the "New" button within the app, and filling out the details, along with the "website". Please make sure the owner is set to the society this login should live under, as well as a collection set. | ||
From this interface you can also generate a password to fill in. The recommneded settings are: | From this interface you can also generate a password to fill in. The recommneded settings are: | ||
* >= 25 characters | * >= 25 characters | ||
* include special characters | |||
* min numbers: 2 | |||
* min special characters: 2 | |||
== Organisation owners == | |||
Make sure you have at least two owners to an organisation. This is to make sure we don’t lose access to the data. | |||
For societies we recommend roles equivalent to chair and secretary. For other initiatives, we recommend you choose two people to act as the Owner. | |||
For societies we recommend roles equivalent to chair and secretary. For other initiatives, we recommend you choose | |||
{{Note|text= | {{Note|text= | ||
| Line 116: | Line 93: | ||
Owners also require [[#Emergency Access|emergency access]] to be set up with someone who is not another owner of their organisation. | Owners also require [[#Emergency Access|emergency access]] to be set up with someone who is not another owner of their organisation. | ||
== Organisations == | |||
To create an organisation, you can go to your “vaults” and click the “New organization” button on the side panel. | To create an organisation, you can go to your “vaults” and click the “New organization” button on the side panel. | ||
| Line 139: | Line 105: | ||
== Handover procedures == | == Handover procedures == | ||
{{Stub}} | |||
We need some instructions here on how to do handover. See the [https://boss.bathcs.com/handover/permissions/ old instructions] in the meantime. | |||
=== Rotating passwords === | === Rotating passwords === | ||
| Line 169: | Line 135: | ||
== How to deal with the worst case scenarios == | == How to deal with the worst case scenarios == | ||
If it is relating to the website being down, please contact [mailto:su-boss@bath.ac.uk su-boss@bath.ac.uk]. Note that | If it is relating to the website being down, please contact [mailto:su-boss@bath.ac.uk su-boss@bath.ac.uk]. Note that BOSS do not have any access to any of the data stored as it is all encrypted. | ||
=== I lost my password and don’t have Emergency Access === | === I lost my password and don’t have Emergency Access === | ||
In that case, there is nothing | In that case, there is nothing you can do. Your account must be deleted and you will need to be re-invited (this means you WILL lose access to any passwords you have stored outside of organisations). Organisations passwords can be recovered by other members of the organisation. | ||
This is why you MUST either know your password by hand or store your password in your own password manager which also has a proper recovery procedure | This is why you MUST either know your password by hand or store your password in your own password manager which also has a proper recovery procedure. | ||
=== The owner of the organisation is not responding === | === The owner of the organisation is not responding === | ||
| Line 185: | Line 151: | ||
You want to then either export the vault data or copy every single password into a new organisation. | You want to then either export the vault data or copy every single password into a new organisation. | ||
== | == Creating new organisations == | ||
All | All student groups (including non-SU groups) are welcome to have organisations to share passwords as we believe in good password policies. However, only BOSS committee can create a new organisation for you, and so please submit a request by emailing [mailto:su-boss@bath.ac.uk su-boss@bath.ac.uk]. | ||
They can do this through the [https://vault.bathcs.com/admin/users/overview admin interface] in the "Organisation" tab (however this interface is normally turned off and so has to be activated through a redeployment). | They can do this through the [https://vault.bathcs.com/admin/users/overview admin interface] in the "Organisation" tab (however this interface is normally turned off and so has to be activated through a redeployment). | ||
== | == Technical details == | ||
=== Backups === | === Backups === | ||
Backups are handled by [[Bath Open Source Society|BOSS]] and is one of the few systems that get | Backups are handled by [[Bath Open Source Society|BOSS]] and is one of the few systems that get a complete off-site backup on a third-party service along with the typical whole cluster backups. | ||
But the basic idea: | But the basic idea: | ||
| Line 200: | Line 166: | ||
* VaultTub get's backed up every 4 hours to our backup server. | * VaultTub get's backed up every 4 hours to our backup server. | ||
* The whole cluster get's backed up every day to our backup server | * The whole cluster get's backed up every day to our backup server | ||
* The specific VaultTub data (including passwords), | * The specific VaultTub data (including passwords), gets backed up to [https://www.scaleway.com/en/ Scaleway] every day | ||
Contact [mailto:su-boss@bath.ac.uk su-boss@bath.ac.uk] if you have any questions. You can also see [https://gitlab.bath.ac.uk/cs/int/terraform/ our configuration within terraform]. | Contact [mailto:su-boss@bath.ac.uk su-boss@bath.ac.uk] if you have any questions. You can also see [https://gitlab.bath.ac.uk/cs/int/terraform/ our configuration within terraform]. | ||
| Line 206: | Line 172: | ||
=== Emails === | === Emails === | ||
Emails are sent through | Emails are sent through the BOSS SMTP server. If you find they are going to junk, please contact [mailto:su-boss@bath.ac.uk su-boss@bath.ac.uk]. | ||
Revision as of 17:50, 11 June 2026
VaultTub is a password manager managed by Bath Open Source Society which allows societies to store and share passwords securely. It can be accessed at vault.bathcs.com.
For more detailed instructions, see BitWarden’s documentation.
Quick setup
You should be messaged or told by the previous committee that you need to sign up so they can invite you. All Bath students can freely make an account (though we ask you not to store your personal passwords on there).
Go to vault.bathcs.com.
Enter your uni email and click "Use single sign-on".
Once redirected to our authentication site (Authelia), enter your University username and password.
You will be redirected back to VaultTub and asked to create a master password. Use a brand new password that you will not forget.
If you lose the master password you will lose all access to VaultTub.You may also receive emails during this process, if the email is in junk, there should be a dropdown at the top of the email with the option to make “vault@bathcs.com” never go to your junk folder. Please select this as you will get a lot more emails after this point.
Required: Set up 2FA
Required for Owners of organisations: set up emergency access
Outgoing committees/initiatives will add you to the relevant organisation as described in the handover procedure. Please ensure that they do this, otherwise you will lose all access to the society's passwords.
Recommended Settings
Once you have signed up with a password you can remember (but don’t use anywhere else), we recommend updating the following settings:
Settings can be found: “Profile Icon in top right > account settings”.
Two-step login
Go to Two-step login settings and choose a provider. For the best security we recommend Authenticator app or Passkey.
Emergency access
We recommend setting up emergency access with at least 1 other person, this is for safety if you lose access to your account.
First, ask your trusted contact to create a VaultTub account. Once they have done that, head to Emergency access settings and click “Add emergency contact”. Enter the user's email and ask them to follow the instructions they receive via email. Once all the steps are complete, go back to the Emergency access tab and verify that they show up as expected.
Emergency access is required for users with a significant amount of power due to the risk of losing everything (we cannot recover your passwords).
Using the extension/app
Bitwarden has a browser extension and an app which support self-hosted instances (and multiple accounts).
To install the app or the extension:
- Download the extension, from Bitwarden’s download page
- Open it up
- if you already have an account you can click the profile icon and then click “Add account”.
- Under the input for the email address (set to “bitwarden” by default), you can select “self-hosted”.
- Input “https://vault.bathcs.com” for the server field and hit “Save” in the top right.
- Enter your login details for VaultTub.
Recommended settings
You may wish to change the default lockout period or add a pin, which can be done in the “Settings tab”. These are handled on a per account basis.
You can click “unlock with pin” and enter a pin (unchecking “unlock with master on browser restart” if you don’t want that).
You can also change the “Vault timeout”, however this is not recommended.
Adding a Login
You can easily add a login by clicking the "New" button within the app, and filling out the details, along with the "website". Please make sure the owner is set to the society this login should live under, as well as a collection set.
From this interface you can also generate a password to fill in. The recommneded settings are:
- >= 25 characters
- include special characters
- min numbers: 2
- min special characters: 2
Organisation owners
Make sure you have at least two owners to an organisation. This is to make sure we don’t lose access to the data.
For societies we recommend roles equivalent to chair and secretary. For other initiatives, we recommend you choose two people to act as the Owner.
Owners also require emergency access to be set up with someone who is not another owner of their organisation.
Organisations
To create an organisation, you can go to your “vaults” and click the “New organization” button on the side panel.
Once created you can go to the “Organizations” tab in the top right and choose the organisation to manage, where you can invite new members (via “Members > Invite Member”) or create a new collection (basically a folder which you can choose who has access to it).
For each member you can choose the role and what collections they have permission to access, the rest is up to you on how you organise everything.
Handover procedures
Please help improve it by adding more detail, providing tips, and linking to other relevant pages.
We need some instructions here on how to do handover. See the old instructions in the meantime.
Rotating passwords
As part of the handover procedures, it is recommended that each initiative rotates all the passwords stored in the organisation.
To do this, please follow this rough instruction list:
Open the item on VaultTub (either by the extension or website)
Copy the password and temporarily store it somewhere (e.g. in the notes section)
Visit the website
Navigate to the change password section (it’s different for every website)
On the extension, click “edit” on the item and click the “Generate Password” button and confirm that it will override the current password stored then
Password recommendations:
- >= 25 characters
- include special characters
- min numbers: 2
- min special characters: 2
- uncheck “avoid ambiguous characters”
Click “Save” on the item to save the new password
Paste the new password in the change password fields + change the password
Log out and log in again to make sure the new password has saved correctly
Delete the temporary storage of the old password
Add a line to the notes saying it was updated on the current date and include your name
How to deal with the worst case scenarios
If it is relating to the website being down, please contact su-boss@bath.ac.uk. Note that BOSS do not have any access to any of the data stored as it is all encrypted.
I lost my password and don’t have Emergency Access
In that case, there is nothing you can do. Your account must be deleted and you will need to be re-invited (this means you WILL lose access to any passwords you have stored outside of organisations). Organisations passwords can be recovered by other members of the organisation.
This is why you MUST either know your password by hand or store your password in your own password manager which also has a proper recovery procedure.
The owner of the organisation is not responding
If all owners of the organisation are not responding or have lost access to their account, this is slightly more of an issue so make sure to have multiple owners.
The organisation will have to be deleted and recreated. To save as many passwords as possible, get all other members to see what Collections they have access to and if they have permission to export the vault (found in the settings for the organisation).
You want to then either export the vault data or copy every single password into a new organisation.
Creating new organisations
All student groups (including non-SU groups) are welcome to have organisations to share passwords as we believe in good password policies. However, only BOSS committee can create a new organisation for you, and so please submit a request by emailing su-boss@bath.ac.uk.
They can do this through the admin interface in the "Organisation" tab (however this interface is normally turned off and so has to be activated through a redeployment).
Technical details
Backups
Backups are handled by BOSS and is one of the few systems that get a complete off-site backup on a third-party service along with the typical whole cluster backups.
But the basic idea:
- VaultTub get's backed up every 4 hours to our backup server.
- The whole cluster get's backed up every day to our backup server
- The specific VaultTub data (including passwords), gets backed up to Scaleway every day
Contact su-boss@bath.ac.uk if you have any questions. You can also see our configuration within terraform.
Emails
Emails are sent through the BOSS SMTP server. If you find they are going to junk, please contact su-boss@bath.ac.uk.