How Can We Help?

Yubikey Hardware Instructions – Linux

You are here:
< All Topics

Overview

This guide will walk users and technical staff through the setup, configuration, and other methods of manipulating a hardware key used in Multi-Factor Authentication on (most) Linux distributions.

Technical note: These instructions work for the Yubikeys supplied by the university for those who traded in their Duo token. If you purchase your own key, these instructions work with the newer Yubikey FIDO 2 keys, including the Security Key (C) (NFC), YubiKey 5(C) (NFC), and YubiKey 5(C) (NFC) FIPS. They may generally work for most FIDO 2 devices.

Please contact SalukiTech if you have any questions on purchasing your own Yubikey if you do not have a Duo token to exchange.

Creating a PIN on Linux for a Yubikey / FIDO2 Device

ATTENTION: If you are setting up a new Yubikey / FIDO2 Device for the first time on a Linux device, you must configure it with a security key PIN first. To do this you need to download the Yubikey Manager from Yubico.

  1. Open a browser go to the Yubico Manager website: https://www.yubico.com/support/download/yubikey-manager/
  2. Download the Appimage file, or another file appropriate for your distribution.
    A screenshot of a computer

Description automatically generated
  3. After the Yubikey Manager download is complete it will be in your ‘Downloads’ folder, or otherwise on your system where downloaded files go. Double click to run and install.
  4. After installation is complete, open it and go to Applications -> FIDO2
    A screenshot of a computer

Description automatically generated
  5. Click ‘Set PIN’
    A screenshot of a computer

Description automatically generated
  6. Enter the new PIN twice.
    A screenshot of a computer

Description automatically generated

Adding a Hardware Token to your SIU / Microsoft Account

  1. Logon to office.siu.edu, click your profile and go to ‘My Account’ then ‘Security Info’. You can also head there directly at https://mysignins.microsoft.com/security-info
    A screenshot of a computer

Description automatically generated
  2. Click ‘Add sign-in method’ select ‘Security Key’ and click ‘Add’.
    A screenshot of a computer

Description automatically generated
  3. Select USB, or NFC if you are operating your NFC-capable hardware token via a mobile device.
    A screenshot of a computer

Description automatically generated
  4. You will now be advised to have you key ready and click ‘Next’.
    A screenshot of a computer error message

Description automatically generated
  5. The browser will alert you that Microsoft (login.microsoft.com) is requesting information to complete the setup, this includes items like the serial number of the device. Click ‘Proceed’.
    A screenshot of a computer error

Description automatically generated
  6. You will see your e-mail address listed as logging into login.microsoft.com. If your e-mail address is correct click ‘OK’.
  7. You will be prompted to enter your PIN from the hardware token, if used previously, or set one up now.
    SIU recommends a 6-character password for your Yubikey. This doesn’t have to be overly complex, and should be something you can/will remember. Entering this wrong 8 or more times will reset the device.
  8. You will be asked to Touch the security key and/or enter your PIN to confirm.
    A white background with black text

Description automatically generated
  9. You will be asked to enter a name for this key. This is for your reference only and mostly used for those individuals who have multiple hardware tokens. Click ‘Next’ when done.A screenshot of a computer

Description automatically generated
Was this article helpful?
0 out Of 5 Stars
5 Stars 0%
4 Stars 0%
3 Stars 0%
2 Stars 0%
1 Stars 0%
5
How can we improve this article?
How Can We Improve This Article?

Leave a Reply

Table of Contents