Enrollment
- Ensure YubiKey is plugged in.
- Ensure Yubikey has default MGMT pin, if not run the following command:
ykman piv access change-management-key -m <MGMKEY> -n 01020304050607080102030405060708010203040506070
- Ensure Yubikey has default MGMT pin, if not run the following command:
- Remote desktop to enroll02.ad.rit.edu
- Enter enroll02.ad.rit.edu
- into the Computer:
- Select Show Options dropdown in the bottom left.
- Select the Advanced tab.
- Select Settings... from the Connect from anywhere.
- Select Use these RD Gateway server settings: and enter "rdgateway.rit.edu" as the Server name.
- Select OK.
- Select Connect.
- Enter TCH Credentials with username MAIN\xxxtch where "xxx" is your initials.
- Enter Credentials again.
Multi-factor with DUO (will do so automatically)
- Double-click on the Autoenroll.bat
- Enter PIN 123456 when prompted. When complete, the command prompt window will go away.
- Note: 123456 is the default Yubikey PIN.
Change PIN (if default)
- Note: 123456 is the default Yubikey PIN.
- Send Ctrl-Alt-Del through RDP (Ctrl-Alt-End) and click on Change a password
- Click on Sign-in options and then Smart card
- Enter the default PIN and your new PIN