Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

...

  • These docs are not the only way to accomplish the goal nor are YubiKeys required however the further you deviate from these docs the less knowledge ITS has to assist you.
  • The OS requires a lock on the YubiKey. If using multiple computers, even if a computer is virtual, multiple devices will be needed – one device per instance of the OS.
    • A YubiKey can be passed through RDP session(s) (Windows only)
  • Each device will have a different certificate. A certificate can, however, be used for access to both Linux and Windows servers.
  • Expert mode: While a YubiKey (i.e. a Yubico device) is not required, the docs and process are built assuming a Yubikey is being used. Any device that can securely generate and store keys in a way that can be cryptographically verified will work.

...

If you plan on utilizing your Yubikey to login into Windows machines, please follow the process below:Windows workstations or Windows servers via RDP you need a Windows CA-issued certificated. Otherwise a self-signed certificate is sufficient.


Expand
titleWindows CA-issued Certificate

Include Page
Yubikey Smartcard Setup via Windows CA-issued Certificate (Yubikey Manager)
Yubikey Smartcard Setup via Windows CA-issued Certificate (Yubikey Manager)

...


Expand
titleSelf-Signed Certificate

Include Page
Yubikey Smartcard Setup via Self-Signed Certificate (Yubikey Manager)
Yubikey Smartcard Setup via Self-Signed Certificate (Yubikey Manager)

...