Operator · First Run

First Sign-In

Frame 10 of 107

Your new CA accepts a password that is printed in its own manual. That is not an oversight — a fresh install has to be usable by somebody — but the next few minutes end that state: this is the sign-in where the system stops being anyone's and becomes yours.

Open https://127.0.0.1:8085 and sign in as admin / admin. Do not expect a dashboard yet: before issuing any session, the console shows a TOTP QR code and a manual setup key. This is not optional and cannot be switched off — the MFA floor for the system administrator is compiled in; no policy edit, no exemption, not even a direct database edit removes it. Scan the code with any authenticator app — the factor is plain RFC 6238, fully offline: no IdP, no cloud account, no network needed to generate codes — and confirm with the current six-digit code.

Next the console shows ten one-time recovery codes — once. goca stores only keyed hashes and cannot display them again; you must acknowledge that before entering the console. Store them like the credential they are: any one of them, pasted into the code field, is a sign-in.

Then, first thing inside: change the bootstrap password — Users → your identity, or POST /v1/identities/admin/password. The product does not force this step; it logs a loud warning until you do. Do it now anyway: from here on every sign-in takes password plus code, but the password half should not be a string anyone can look up.

Now the admin account answers to my authenticator and my password — not the manual's.