2-factor authentication
See also:
See also https://uol.de/2fa/zwei-faktor-login for an overview of two-factor authentication (2FA) in general.
See also https://uol.de/itdienste/services/zugang-zum-campusnetz for access to the campus network via VPN (GlobalProtect).
During login with hardware token, the hardware token is queried in addition to the username and password previously used, e.g. at a USB port. This a) exchanges some secrets/challenges in the background and b) checks whether the user is "on site".
The hardware token (Yubikey) must be registered once at https://2fa.uol.de before use.
When logging in with One Time Password, an on-time password is requested in addition to the user name and password as previously known. This is only generated offline, e.g. in a mobile app, depending on the time and is only valid for a few seconds.
The mobile app must be registered once on the university website https://2fa.uol.de before use.