Table of Contents
Hardware Tokens like Yubikey
What exactly is this?
A YubiKey is a hardware token used for secure authentication. It is a small device, usually in USB or NFC format, that serves as a second layer of security (2-factor authentication, or 2FA). It generates one-time codes or confirms identities through physical touch.
A YubiKey allows the use of various MFA methods. It can be used for:
- OTP (One-Time Password) methods such as TOTP, HOTP, Yubikey OTP, etc.
- FIDO2 Tokens
- Certificate-based logins like Smartcard applications
- and much more.
The GWDG offers YubiKeys for purchase. Procurement is managed through the respective institutions. If your institution is interested in procuring YubiKeys or has questions about their use and application, please contact: sso-support@gwdg.de
Prerequisites:
Owning a hardware token, such as a YubiKey, is required.
When procuring, please note that hardware tokens (including YubiKeys) come in different versions. Depending on your needs, YubiKeys with USB-A or USB-C can be acquired.
Setup:
As mentioned, there are multiple ways to use the YubiKey.
Unfortunately, there is currently no self-service available in our account portal that allows you to use the YubiKey in AES mode. If you are interested in using this method for your entire institution and configuring it for accounts, please contact: sso-support@gwdg.de
However, setting up the YubiKey as a FIDO2 token is possible via self-service as follows:
Open your account portal as described here under the heading “How do I set up an additional factor?”
1. After pressing the “Secure my account” button under “Passkeys and Security Keys,” you can assign a label to the security key (e.g., “YubiKey”).
2. The next two steps depend on your operating system and any authentication methods already configured on your device. Here are two common options:
2.1 In the window that opens (the appearance depends on the operating system), click on “More options.”
2.2 In the following window, click “OK.”
3. If such a window appears, select “Security Key.” If not, skip this step.
4. Activate your YubiKey by, for example, placing your finger on it.
5. After confirming the YubiKey once again, the security key is set up and ready for use.