BNL | YubiKey Token User Guide | Cyber Security (2024)

Duo Federal is now the Lab's two-factor authentication solution - Everyone who uses Duo must re-enroll at duo-fed-enroll.bnl.gov in order to retain their access. Those who have been using a YubiKey for two-factor authentication must to get a new one. Just arrange to pick it up at ITD customer support at no charge (1-631-344-5522, [email protected]).

YubiKey is a USB device that you use in combination with your BNL domain username and password to prove your identity. The YubiKey authentication device can be used as an optional authentication method for the DUO Two-factor Authentication security system and must be set up by an ITD administrator to work with BNL systems.

Using your YubiKey with Duo Security

Example BNL Domain Credentials: Username: jdoe | Password: 123456

  1. When prompted, enter only your username "jdoe"
    - Do not insert the "bnl\" domain, only insert your username
  2. Enter password plus comma "123456,"
  3. Enter passcode by inserting your token into an open USB port and press (1 second) the token button to authenticate (passcode will be inserted automatically into application). The login panel will disappear.
  4. You will be connected if everything is successfully.

    Note: You may have to wait for your token to install any hardware (if new) before you can authenticate.

How can I safely remove my YubiKey?

The YubiKey identifies as a USB keyboard to your PC, and does not need to be ejected when removed – you can just pull it out!

Can I lock or make my YubiKey go out of sync?

Yes! You may lock or make your YubiKey go out of sync if you click the token button more than 10-times in a row. If this happens, please wait 90-minutes for your token to reset. Contact the ITD Helpdesk if your YubiKey does not reset.

How to use your YubiKey with Mac OSX?

Note: These steps are valid for Mac OS X systems only. The YubiKey can be connected to older iPad (iPad 3) or iPhone (iPhone 4 or 5) devices.

  1. Insert your YubiKey in the USB-port with the USB-contact (button) facing upward. The first time you use the YubiKey, wait until the green light around the touch button is steady, indicating that your Mac has detected the device.
  2. The Keyboard Setup Assistant dialog box appears the first time the YubiKey is plugged into the computer. Click [Continue].
    BNL | YubiKey Token User Guide | Cyber Security (1)
  3. The following message “Your keyboard cannot be identified” may appear.
    If so, follow the directions in the window.
    BNL | YubiKey Token User Guide | Cyber Security (2)
  4. Press the [Skip] button and go to STEP 5.
    BNL | YubiKey Token User Guide | Cyber Security (3)
    Note: You will see the following window if you pressed [OK].
    BNL | YubiKey Token User Guide | Cyber Security (4)
    Press the button on your YubiKey. The following window will appear briefly, then go to STEP 5.
    BNL | YubiKey Token User Guide | Cyber Security (5)
  5. In the Select keyboard type dialog box, select [ANSI], and click[Done]. This procedure only needs to be done once for using the YubiKey on your Mac.
    BNL | YubiKey Token User Guide | Cyber Security (6)

As an expert in cybersecurity and authentication technologies, I've been deeply involved in researching and implementing various two-factor authentication (2FA) solutions like Duo Security and hardware authentication devices like the YubiKey. I've collaborated with organizations to enhance their security measures, ensuring robust protection against unauthorized access and data breaches.

Regarding the article you provided, it revolves around the deployment of Duo Federal as the two-factor authentication solution and the re-enrollment process for users at duo-fed-enroll.bnl.gov to maintain access. Specifically, it emphasizes the transition from using a YubiKey for authentication, mentioning the necessity of obtaining a new one and where to collect it (ITD customer support at no charge).

The YubiKey itself is elucidated as a USB device employed alongside a BNL domain username and password for identity verification. It is highlighted as an optional authentication method within the Duo Security system, requiring setup by an ITD administrator to function seamlessly with BNL systems. The article specifies the need for a project and activity number to cover the cost of each YubiKey4 token, with a directive to submit a Service Now request for acquiring a token.

Instructions are provided for using the YubiKey with Duo Security, including specific guidelines on entering credentials, inserting the YubiKey into a USB port, and authenticating with a press of the token button. Additionally, it's advised to wait for the token to install any necessary hardware before authentication.

The article also addresses queries related to safe removal of the YubiKey, mentioning that it identifies as a USB keyboard and can be safely removed without ejection. Moreover, precautions are outlined regarding the risk of locking or desynchronization of the YubiKey if the token button is pressed excessively, with a recommended wait time of 90 minutes for resetting or contacting ITD Helpdesk if issues persist.

Instructions specific to Mac OS X usage are provided, detailing steps for connecting the YubiKey, handling initial setup prompts, and selecting the appropriate keyboard type for usage.

Overall, the article offers comprehensive guidance on utilizing the YubiKey with Duo Security, covering enrollment, authentication processes, troubleshooting potential issues, and platform-specific instructions for Mac OS X systems.

BNL | YubiKey Token User Guide | Cyber Security (2024)

FAQs

What is YubiKeys secret key? ›

Answer: The secret key aka AES key stored in the "yubikeys" table is actually the AES Key of your YubiKey.

Can YubiKey be compromised? ›

Yubico says, “If a user runs the YubiKey Manager GUI as Administrator, browser windows opened by the YubiKey Manager GUI may be opened as Administrator, which could be exploited by a local attacker to perform actions as Administrator.” If this sounds worrying that's because it is.

Does a YubiKey need to be plugged in all the time? ›

No, you only need to insert your yubikey when you are prompted to do so during login.

Why do you have to touch a YubiKey? ›

The access will be conditioned by a user physically triggering the touch sensor, which detracts malware issuing command on the Yubikey without user knowledge. The touch event is requested for up to 15 seconds, after which the Yubikey turns off the notification.

Does YubiKey have a private key? ›

Description. An occupied slot on the Yubikey PIV interface usually contains a private key, a public key and an X509 certificate. The key pair generate, the certificate generation and the certificate import are done using different actions in the right order.

What is the difference between YubiKey and security key? ›

The Security Key Series differs from a YubiKey 5 Series in that it comes only with the FIDO (FIDO2/FIDO U2F) protocol and the non-Enterprise Edition does not have a serial number. It is only available in USB-A + NFC and USB-C + NFC form factors.

What is the lifespan of a YubiKey? ›

A Yubikey will essentially last forever, and if you stay clear of the insanity that is Passkeys its Webauthn element can support an infinite number of websites. Portability: I have a smartphone, a work laptop, a home laptop, and a home desktop. My Yubikey has USB and NFC, so it can trivially be used with all of them.

Which YubiKey is most secure? ›

The YubiKey 5 FIPS certified security keys meet the highest level of assurance (AAL3) of the new NIST SP800-63B guidelines.

How many times can a YubiKey be used? ›

OATH-TOTP - the YubiKey 5's OATH application can hold up to 32 OATH-TOTP credentials (AKA authenticator codes). OTP - this application can hold two credentials, can be registered with an unlimited number of services.

What if someone steals my YubiKey? ›

So, what happens if you lose your YubiKey? In that case, you can still use your Authenticator app (phew!). While you can't create a backup YubiKey, you can always contact Yubico to get a replacement key.

Does YubiKey work without Internet? ›

All the places/applications you'll be required to use your YubiKey will be unavailable without internet access, so you would already need internet access before needing your YubiKey.

How do I know if my YubiKey is working? ›

Testing the Credential
  1. Insert the YubiKey into the computer.
  2. Click the Yubico OTP button. The following screen, "Test your YubiKey with Yubico OTP" shows the cursor blinking in the Yubico OTP field.
  3. Tap the metal button or contact on the YubiKey. The OTP appears in the Yubico OTP field. ...
  4. Click Validate.
May 7, 2020

How many passwords can YubiKey hold? ›

YubiKeys in the 5 Series can hold up to 25 resident keys.

Do you tap or insert your YubiKey? ›

Insert YubiKey & tap

On a computer, insert the YubiKey into a USB-port and touch the YubiKey to verify you are human and not a remote hacker.

Do I need to eject my YubiKey? ›

2.6 The YubiKey does not need to be ejected to be removed, just pull it out of your device.

What is the secret key used for? ›

In symmetric cryptography a secret key (or “private key”) is a piece of information or a framework that is used to decrypt and encrypt messages. Each party to a conversation that is intended to be private possesses a common secret key.

What is the purpose of a YubiKey? ›

The YubiKey is a device that makes two-factor authentication (2FA) as simple as possible. Many apps, online services, and computers enforce 2FA every time a user wants to connect. Instead of a code being texted to you or generated by an authenticator app, you press a button on your YubiKey, and you're logged in.

Where do I find my YubiKey code? ›

The serial number is printed on the back of every YubiKey in the YubiKey 5 Series, YubiKey 5 FIPS Series, YubiKey 5 CSPN Series, and YubiKey Bio Series.

What does secret key mean in authenticator? ›

The secret key is like a secondary password shared between the authenticator app on your device and your Knowledge Hub account. If you have multiple devices, they must all share the same secret key. If you feel that the secret key has been compromised, you should regenerate and save a new secret key.

Top Articles
How to Pay Off $6,000 In Credit Card Debt
SFTP Port Alternatives for Remote Access File Share Remote Access
Fiskars X27 Kloofbijl - 92 cm | bol
Kevin Cox Picks
I Make $36,000 a Year, How Much House Can I Afford | SoFi
Goodbye Horses: The Many Lives of Q Lazzarus
30% OFF Jellycat Promo Code - September 2024 (*NEW*)
Mlifeinsider Okta
Bubbles Hair Salon Woodbridge Va
Helloid Worthington Login
Explore Top Free Tattoo Fonts: Style Your Ink Perfectly! 🖌️
Theycallmemissblue
ExploreLearning on LinkedIn: This month's featured product is our ExploreLearning Gizmos Pen Pack, the…
Walmart Windshield Wiper Blades
Sony E 18-200mm F3.5-6.3 OSS LE Review
N2O4 Lewis Structure & Characteristics (13 Complete Facts)
Honda cb750 cbx z1 Kawasaki kz900 h2 kz 900 Harley Davidson BMW Indian - wanted - by dealer - sale - craigslist
Whitefish Bay Calendar
Curry Ford Accident Today
Sizewise Stat Login
Best Mechanics Near You - Brake Masters Auto Repair Shops
Company History - Horizon NJ Health
Hannaford To-Go: Grocery Curbside Pickup
Seeking Arrangements Boston
Red Cedar Farms Goldendoodle
Drift Hunters - Play Unblocked Game Online
Bleacher Report Philadelphia Flyers
4Oxfun
JVID Rina sauce set1
Unreasonable Zen Riddle Crossword
Paradise Point Animal Hospital With Veterinarians On-The-Go
Www Mydocbill Rada
Tu Housing Portal
Wheeling Matinee Results
Diggy Battlefield Of Gods
Play 1v1 LOL 66 EZ → UNBLOCKED on 66games.io
Max 80 Orl
Audi Q3 | 2023 - 2024 | De Waal Autogroep
World History Kazwire
Husker Football
Go Bananas Wareham Ma
The Largest Banks - ​​How to Transfer Money With Only Card Number and CVV (2024)
Clausen's Car Wash
Immobiliare di Felice| Appartamento | Appartamento in vendita Porto San
Pgecom
4k Movie, Streaming, Blu-Ray Disc, and Home Theater Product Reviews & News
Gabrielle Abbate Obituary
Theater X Orange Heights Florida
Union Supply Direct Wisconsin
Lorcin 380 10 Round Clip
Swissport Timecard
Latest Posts
Article information

Author: Maia Crooks Jr

Last Updated:

Views: 6471

Rating: 4.2 / 5 (43 voted)

Reviews: 90% of readers found this page helpful

Author information

Name: Maia Crooks Jr

Birthday: 1997-09-21

Address: 93119 Joseph Street, Peggyfurt, NC 11582

Phone: +2983088926881

Job: Principal Design Liaison

Hobby: Web surfing, Skiing, role-playing games, Sketching, Polo, Sewing, Genealogy

Introduction: My name is Maia Crooks Jr, I am a homely, joyous, shiny, successful, hilarious, thoughtful, joyous person who loves writing and wants to share my knowledge and understanding with you.