- Depending on your distribution, install YubiKey Manager.
- Arch Linux
sudo pacman -S yubikey-manager sudo systemctl enable pcscd.socket- Debian / Ubuntu
sudo apt-add-repository ppa:yubico/stable sudo apt update sudo apt install yubikey-manager- Fedora
sudo dnf install yubikey-manager
After installation and connecting the YubiKey to the computer, verify that the device is detected.
ykman infoExample of successful detection:
Device type: YubiKey 5 NFC Serial number: 4200689 Firmware version: 5.7.1 Form factor: Keychain (USB-A) Enabled USB interfaces: OTP, FIDO, CCID NFC transport is enabled Applications USB NFC Yubico OTP Enabled Enabled FIDO U2F Enabled Enabled FIDO2 Enabled Enabled OATH Enabled Enabled PIV Enabled Enabled OpenPGP Enabled Enabled YubiHSM Auth Enabled EnabledConfigure the PIN code.
ykman fido access change-pin
FIDO2 – Security Key
Setup
We recommend using either a YubiKey 5C NFC or a GoTrust IdemKey security key.
Warning:
To configure a security key, the user must already have an MFA method activated via Microsoft Authenticator, TOTP, or possess a Temporary Access Pass (TAP). A Temporary Access Pass can be requested using the ICT Helpdesk form.
Windows
To configure a PIN on the security key, open Accounts › Sign-in options, select Security Key, click Manage, and set your PIN code.
- Continue below with the steps common to all systems.
Linux
Configure a PIN on your security key.
YubiKey
Console
GoTrust IdemKey
Common Steps
- On your computer, open https://mysignins.microsoft.com/security-info and sign in using your university account
username@cvut.czand your CTU password. Click Add sign-in method.
Select Security key.
Select USB device.
Prepare your security key and click Next.
Insert the security key into the computer and wait until you are redirected to the next page.
After redirection, enter the PIN code created in PIN setup.
Touch the security key.
Click Allow.
Give your security key a name and click Next.
The security key has been successfully added.
Warning:
If adding the FIDO2 security key fails with an unknown error, verify that a PIN has been configured on the key. A security key without a PIN cannot be registered for MFA.

















