# Website management

*[Versão em português](https://kb.deec.uc.pt/books/servicos-comuns/page/gestao-de-sites)*

Websites hosted by the IT services of **DEEC, ISR, IT and INESC Coimbra** are now updated in a single place, **[sites.deec.uc.pt](https://sites.deec.uc.pt)**. You sign in with your institutional account and, for security, with two-step verification. It replaces FTP access and the shared accounts each website used to have.

## Who it is for

Faculty, researchers, projects and student groups who have a website hosted by us and need to update its files (pages, images, documents).

To get access to a website, or to give access to someone else, write to **[suporte@deec.uc.pt](mailto:suporte@deec.uc.pt)** with the website address and each person's username. Access is personal: everyone signs in with their own account, and no passwords are shared.

## Signing in

1. Open **https://sites.deec.uc.pt**.
2. In **Utilizador** (username), type only your **username**, **without @domain**. For example `jsilva`, not `jsilva@deec.uc.pt`.
3. In **Password**, use your institutional e-mail password.
4. Click **Iniciar sessão** (sign in).

If you do not remember your password, contact support.

## Turning on two-step verification (first time only)

Two-step verification (2FA) is mandatory on your first sign-in. You only do it once, and it takes about two minutes. You need a phone with an authenticator app, such as **Microsoft Authenticator** or **Google Authenticator**, both free on the App Store and Google Play.

1. After signing in, you see the page **"Two-factor authentication using Authenticator apps"**, saying your account requires 2FA.
   **Do not change** **"Configuration"** (leave it as *Default*) or **"Require 2FA for"** (leave it as *HTTP*). Click **"Enable"**.
2. The **"Set up two-factor authentication"** window opens with a **QR code**. On your phone, open the authenticator app and add an account:
   - **Microsoft Authenticator:** **"+" → "Other account (Google, Facebook, etc.)"**;
   - **Google Authenticator:** **"+" → "Scan a QR code"**.

   Point the camera at the QR code. The app now shows a **Sites DEEC** entry with a 6-digit code that changes every 30 seconds.

   *If the camera does not work, choose "enter a setup key" in the app and type the letters and numbers shown below the QR code.*
3. Type the **6-digit code the app is showing at that moment** in the field below the QR code and confirm.
   If you see *"Failed to validate the provided authentication code"*, wait for the next code and try again.
4. Two-step verification is now on. On the same page, in **"Recovery codes"**, click **"Generate new recovery codes"** and **keep those codes somewhere safe**, for example printed or in a password manager. Each one lets you sign in once if you lose or replace your phone.

From then on, every sign-in asks for your password and then for the app's **6-digit code**.

## Managing your website files

After signing in, you see one folder for each website you have access to. Inside it you can **upload, replace, rename, create folders and delete** files. To upload, drag the files onto the window or use the upload button.

**Changes go live immediately** on the website. Before deleting or replacing anything, keep a copy of important files: changes cannot be undone from the interface.

## Connecting with WinSCP or another program

Programs such as **WinSCP** or **Cyberduck** connect over **WebDAV**, which does not support two-step verification. For that reason this kind of connection **only works from the internal networks of DEEC, ISR, IT and INESC Coimbra**, or with the **[VPN](https://kb.deec.uc.pt/books/deec/chapter/vpn-jAV)** connected.

| Field | Value |
|---|---|
| Protocol | **WebDAV** |
| Encryption | **TLS/SSL Implicit encryption** |
| Host | `sites.deec.uc.pt` |
| Port | `443` |
| User / password | your username (without @domain) and your e-mail password |
| Remote directory (WinSCP: *Advanced → Directories*) | `/dav` |

This kind of connection does not ask for the 6-digit code.

**FTP** has been discontinued and is not available.

## Limitations

- For security, **executable files cannot be uploaded**, such as `.php`, `.phtml`, `.phar`, `.htaccess` or `.user.ini`, and files cannot be renamed to those extensions.
- **WordPress** sites, or sites with other server-side code, are handled case by case. Please contact support.
- The [WordPress website hosting Terms and Conditions](https://kb.deec.uc.pt/books/servicos-comuns/page/termos-e-condicoes-de-alojamento-de-site-wordpress) apply where relevant.

## Common problems

| Situation | What to do |
|---|---|
| Your password is not accepted | Make sure you typed your **username without @domain**. |
| The 6-digit code is rejected | Make sure your phone's clock is set automatically, and use the next code. |
| You replaced or lost your phone | Sign in with one of your recovery codes. If you do not have them, contact support to reset two-step verification. |
| You cannot see your website's folder | Access has not been granted yet. Contact support. |
| WinSCP will not connect | You are outside the internal networks: connect the [VPN](https://kb.deec.uc.pt/books/deec/chapter/vpn-jAV) or use the browser. |

Support: **[suporte@deec.uc.pt](mailto:suporte@deec.uc.pt)**