FED-LOGIN Overview
What is FED-LOGIN?
FED-LOGIN is primarily a so-called Identity Provider (IdP) for the authentication of electronic identities in the enterprise context of the Federal Administration. It enables login with identities of persons who access eIAM-integrated applications as part of their employment or contractual relationship.The term FED-LOGIN covers all login methods that enable the use of the SG-PKI-based electronic identity. An SG-PKI-based electronic identity is issued to persons who have been onboarded through the employer processes of the HR services of the Federal Administration or by certain partners of the Federal Administration, such as cantonal administrations.
A characteristic feature is that these persons receive a smartcard and/or Mobile VDI access from the Federal Administration. The SG-PKI-based electronic identity can be used from all networks (including the Internet) by means of a smartcard and, within the Federal Administration network, additionally via Kerberos.
This SG-PKI-based electronic identity can now also be used through alternative authentication methods, in particular via the FED-LOGIN Access App as well as via security keys. This enables high-quality authentication that works independently of location and end device – including over the Internet.
The registration and management of these login methods are carried out by the user in self-service at www.myaccount.eiam.admin.ch. Activation requires an existing identification, usually by means of a smartcard or – if no smartcard is available – via video identification.
Which FED-LOGIN login method can you use?
FED-LOGIN with smartcard Quality of authentication: High+ (QoA60)The best method for you if you are equipped with a standard workstation system of the Federal Administration and a smartcard and use it to access eIAM-integrated applications. Using the smartcard login method on FED-LOGIN allows a login whose quality meets the requirements of all eIAM-integrated applications of the Federal Administration.
FED-LOGIN with Access App Quality of authentication: High (QoA50)
The FED-LOGIN Access App is the simplest and at the same time the most secure method for you if you are equipped with a smartcard of the Federal Administration and want to log in to FED-LOGIN with a device that does not support the use of your smartcard (for example smartphones, tablets, PCs without a smartcard reader, Mobile VDI). The FED-LOGIN Access App method enables a login whose quality meets the requirements of most eIAM-integrated applications of the Federal Administration. Link to the instructions: FED-LOGIN - Register the Access App
FED-LOGIN with security key (FIDO2) Quality of authentication: High (QoA50)
FED-LOGIN supports security keys (FIDO2) as an alternative login method if you are equipped with a smartcard of the Federal Administration and want to log in to FED-LOGIN with a device that does not support the use of your smartcard (for example smartphones, tablets, PCs without a smartcard reader, Mobile VDI). This login method is also suitable in situations where the use of smartphones is not allowed or not desired. The FED-LOGIN security key login method enables a login whose quality meets the requirements of most eIAM-integrated applications of the Federal Administration and it is completely passwordless. Link to the instructions: FED-LOGIN - Register a security key (FIDO2)
FED-LOGIN with Active Directory Single Sign-On (Kerberos) Quality of authentication Medium (QoA40)
Login with Active Directory Single Sign-On is the right method for you if you are equipped with a standard workstation system of the Federal Administration or Mobile VDI of the Federal Administration and work with this device in the Federal Administration network. In this case, the login takes place automatically in the background without any user interaction. FED-LOGIN recognizes the quality requirement of the application you access and performs the login automatically if that requirement can be met with this login method.
FED-LOGIN with software certificate Quality of authentication Medium (QoA30)
Login with a software certificate is the right method if a system/process requires access to eIAM-integrated resources. Examples of use are end-to-end monitoring or test automation of eIAM-integrated applications. Please note that a technical identity (Managed Techuser) must be registered in eIAM. The software certificate serves as proof-of-identity means for this technical identity. Further information about «Managed Techuser» can be found at: Suppor