Public Yubikey Initialization Script

Warnings

  • This should only be done if you purchased the token independently or token’s PUK has been locked
  • If you have previously purchased the token from us, you should check your old order for the PIN, PUK, and management key. You can contact support for assistance on this.
  • On Yubikey 5 FIPS, if there are multiple options for algorithms on the management key, you should select aes-256.

Process to Re-Initialize (Restore Defaults on) the YubiKey FIPS Token

Requirements:

Steps:

  1. Download and install the YubiKey Manager. (note: Modern Windows computers will use x64; x86 is for older, 32-bit computers.
  2. Open the YubiKey Manager and insert the Token.
  3. Navigate to Applications > PIV > Reset PIV, when prompted confirm the action by clicking “yes”. This will remove ALL certificates stored on the Yubikey.
   

4. After a brief processing time, the YubiKey Manager will display a notice that the action was successful and the token is now reset to defaults.  You may now configure your PIN.

Process to Configure PINs on Yubico YubiKey FIPS Token

Requirements:

  • Download Yubico Yubikey Manager
  • Yubico YubiKey FIPS Token

Steps:

  1. Open YubiKey Manager and insert the Token into a USB slot on the computer.
  2. Navigate to Applications > PIV > Configure PINs.
  3. Select “Change PIN” and then check the “use default” checkbox.
  4. Generate a new PIN of at least 6 characters.
  5. Record the PIN in a secure location.
    Take note that you will need the PIN to use the token with signing documents or code. Also, you will have a sole record of the PIN and SSL.com will not be able to help you recover it if it gets lost.
  6. Enter the PIN into the New PIN field of the YubiKey Manager and then re-enter the PIN into the Confirm New PIN field. Select Change PIN to lock-in the changes.
  7. You will then be redirected back to the PIV menu. From Applications > PIV > Configure PINs, select Change PUK.
  8. Check the box for Use Default.
  9. Generate your PUK of at least 6 characters
  10. Record the PUK in a secure location.
    Take note that you will need the PUK to reset it if it ever becomes lost or you forget it. Take note also that this is the only record of the PUK and SSL.com will not be able to help you recover it if you lose it.
  11. Enter the PUK into the New PUK field of the YubiKey Manager and then re-enter the PUK into the Confirm New PUK field. Finally, select Change PUK to lock-in the changes.
  12. Provided that there are no error messages you will be redirected back to the PIV menu. Next, perform the following operation to change the Management Key:
    From Applications > PIV > Configure PINs, select Change Management Key.
  13. Check the box for Use Default.
  14. Click the Generate button to generate a new 48 character Management Key. Highlight the key and press Ctrl-C to copy it.
  15. Record the Management Key in a secure location.
    Take note that you will need the Management Key for all certificate activity on the token, such as generation of a CSR or installing an S/MIME certificate. Take note also that you have the sole record of the Management Key and ssl.com will not be able to help you recover it if you lose it.
  16. Once the Management Key has been recorded in the proper location, press Finish to save the changes and update the token. You have now reset the PIN/PUK/Management Key on the Yubico YubiKey FIPS Token.

If you are interested in learning how to generate a key pair and attestation certificate on your Yubikey, check out this article.

Thank you for choosing SSL.com! If you have any questions, please contact us by email at Support@SSL.com, call 1-877-SSL-SECURE, or just click the chat link at the bottom right of this page. You can also find answers to many common support questions in our knowledgebase.
   
Twitter
Facebook
LinkedIn
Reddit
Email

Stay Informed and Secure

SSL.com is a global leader in cybersecurity, PKI and digital certificates. Sign up to receive the latest industry news, tips, and product announcements from SSL.com.

We’d love your feedback

Take our survey and let us know your thoughts on your recent purchase.