Duo - YubiKey 5C NFC setup on Windows

Objective

Set up a YubiKey 5C NFC on a Windows machine to allow 2-Factor authentication with Duo.

Users

  • Anyone at the University of Nebraska who needs 2-Factor authentication and who is served by ITS.

Before You Begin

  • Acquire a YubiKey 5C NFC, and an adapter such as EZQuest if you need to plug it into a USB port.
  • Go to the web page and download and install the YubiKey Manager.

Steps

  1. Browse to YubiKey Manager Downloads to download and install YubiKey Manager.Uploaded Image (Thumbnail)Uploaded Image (Thumbnail)Uploaded Image (Thumbnail)
  2. Open YubiKey Manager
    Uploaded Image (Thumbnail)
  3. Plug in the YubiKey.Uploaded Image (Thumbnail)Uploaded Image (Thumbnail)
  4. Click the Applications tab.Uploaded Image (Thumbnail)
  5. Choose OTP.Uploaded Image (Thumbnail)
  6. Under Short Touch, click the Delete button if the slot is already configured.  Then click Configure.Uploaded Image (Thumbnail)
  7. Select Credential Type - Accept the default of Yubico OTP, and click Next>.Uploaded Image (Thumbnail)
  8. Yubico OTP - Click the checkbox to the right of the Public ID field where it says Use serial.  This fills in the public ID, which equates to the serial number.Uploaded Image (Thumbnail)Uploaded Image (Thumbnail)
  9. Click the Generate buttons to the right of the Private ID and Secret Key fields to generate these fields.
  10. Record all three values.  Private ID and Secret Key can be copied and pasted, but Public ID will need to be copied out manually.  It's short.
  11. Leave the Upload checkbox unchecked, and click the Finish button.
  12. Securely share your Public ID, Private ID, and Secret Key with the IAM Team in a service ticket. We recommend using Delinea or Onetime Secret.