Prerequisites
- YubiKey 4 and newer
- Active Directory account
- Windows domain-bound machine (necessary for Step 5)
- Yubikey Manager
- Download direct from Yubico: https://www.yubico.com/support/download/yubikey-manager/#h-downloads
- Windows
- Mac
- Linux
Process
- Run the Yubikey Manager application and insert your key
- Click on Applications and then click on PIV
- Change PIN if Yubikey is fresh out of the box or it's been defaulted
- Click on Configure PINs
- Click Change PIN and then check Use default (if it is default).
Fill in the blanks.
Finish with changing PIN by clicking on Change PIN - Click on Change PUK and then check Use default (if it is default).
Fill in the blanks.
Finish with changing PUK by clicking on Change PUK - Click on Change Management Key and then check Use default (if it is default).
Fill in the blanks.
Finish with changing the key by clicking on Finish- You can check Protect with PIN to not need the Management Key for future
- You can check Protect with PIN to not need the Management Key for future
- Click on Configure PINs
- Go back to Applications and then PIV
- Click on Configure Certificates
- Click on Authentication and then Generate
- Check the radio for Certificate Signing Request and then click Next
- Select RSA2048 and then click on Next
- Input a decent subject text (ala username) and then click on Next
- The next page gives you a summary of what you've done. When you click Generate, it will open a save dialog to save the .csr file.
- Click on Configure Certificates
(This step requires a domain-bound Windows machine)
Open PowerShell and navigate to where you saved the .csr filecd <directory where csr file is saved>
Run the following command to request a certificate from ADCS. You will need to click on RIT AD Signing CA (Kerberos) - itscaad01.ad.rit.edu when the popup appears.
certreq -submit -attrib "CertificateRequest:YubicoSC" <csr file> <crt file>
- Once .crt file is obtained successfully, go back to YubiKey Manager application
- If you closed the application, go to Applications > PIV > Configure Certificates > Authentication
- Click on Import
- A dialog box will pop up to select the .crt file from Step 5.
- Once the certificate is imported, you'll see the details populated in the application