Go to navigation

FIDO2 – Security Key

Setup

We recommend using either a YubiKey 5C NFC or a GoTrust IdemKey security key.

Warning:

To configure a security key, the user must already have an MFA method activated via Microsoft Authenticator, TOTP, or possess a Temporary Access Pass (TAP). A Temporary Access Pass can be requested using the ICT Helpdesk form.

Windows

  1. To configure a PIN on the security key, open Accounts  Sign-in options, select Security Key, click Manage, and set your PIN code.

    fido windows cs
  2. Continue below with the steps common to all systems.

Linux

Configure a PIN on your security key.

  • YubiKey

    Console
    1. Depending on your distribution, install YubiKey Manager.
      Arch Linux
      sudo pacman -S yubikey-manager
      sudo systemctl enable pcscd.socket
      Debian / Ubuntu
      sudo apt-add-repository ppa:yubico/stable
      sudo apt update
      sudo apt install yubikey-manager
      Fedora
      sudo dnf install yubikey-manager
    2. After installation and connecting the YubiKey to the computer, verify that the device is detected.

      ykman info
    3. Example of successful detection:

      Device type: YubiKey 5 NFC
      Serial number: 4200689
      Firmware version: 5.7.1
      Form factor: Keychain (USB-A)
      Enabled USB interfaces: OTP, FIDO, CCID
      NFC transport is enabled
      Applications    USB        NFC
      Yubico OTP      Enabled    Enabled
      FIDO U2F        Enabled    Enabled
      FIDO2           Enabled    Enabled
      OATH            Enabled    Enabled
      PIV             Enabled    Enabled
      OpenPGP         Enabled    Enabled
      YubiHSM Auth    Enabled    Enabled
    4. Configure the PIN code.

      ykman fido access change-pin
  • GoTrust IdemKey

    Web Browser
    1. In Google Chrome/Chromium, open chrome://settings/securityKeys.

      go trust 1 cs
    2. Open the Create PIN tab.

      go trust 2 cs
    3. Connect the security key to the device.

      go trust 3 en
    4. After inserting the security key, create a PIN code and click Save.

      go trust 4 en

Common Steps

  1. On your computer, open https://mysignins.microsoft.com/security-info and sign in using your university account username@cvut.cz and your CTU password.
  2. Click Add sign-in method.

    fido web 1 en
  3. Select Security key.

    fido web 2 en
  4. Select USB device.

    fido web 3 en
  5. Prepare your security key and click Next.

    fido web 4 en
  6. Insert the security key into the computer and wait until you are redirected to the next page.

    fido web 5 en
  7. After redirection, enter the PIN code created in PIN setup.

    fido web 6 en
  8. Touch the security key.

    fido web 7 en
  9. Click Allow.

    fido web 8 en
  10. Give your security key a name and click Next.

    fido web 9 en
  11. The security key has been successfully added.

    fido web 10 en
Warning:

If adding the FIDO2 security key fails with an unknown error, verify that a PIN has been configured on the key. A security key without a PIN cannot be registered for MFA.

Sign-In

  1. On the sign-in screen, select Sign-in options:

    login entra ooptions.cs
  2. Select Face recognition, fingerprint, PIN, or security key:

    login entra options fido.cs
  3. Select Security key.

    fido login 1 cs
  4. Enter your PIN.
  5. When the security key starts flashing, touch the gold contact area.
  6. Done, you are signed in.