Skip to main content

Using YubiKey Bio MPE

Do This First

Security key support for HYPR RP Applications must first be enabled in the Control Center under Workstation Settings.

API Calls

Calls for pairing (registering) a security key/passkey with an RP Application, including updating Recovery PINs, are described under RP Applications > Workstation > Security Keys in the HYPR Passwordless API.

This document describes how to manage security keys for the HYPR Passwordless client.

Definitions

AcronymDefinition
PINA personal identification number (PIN) is a set of characters used to unlock the smart card for use. The PIN is a decentralized secret the user should not share. The PIN is bound and used to unlock an authenticator. In the case of a hardware security key, such as a Yubico YubiKey, the PIN resides on the key and unlocks the authenticator that uses public/private key encryption to perform authentication. See the securityKeyPinCharacters configuration parameter description in Installing Manually.
PUKA PIN unblocking key (PUK) is a code that is used by users or applications to reset a PIN that has been lost, forgotten, or locked because of too many failed attempts. The PUK is part of the PIV standard that the key follows.
PIVPersonal Identity Verification - or frequently associated together as a PIV Card - is commonly the reference to United States Federal smart card or security key that contains the necessary data for the holder to be granted to Federal facilities and information systems and assure appropriate levels of security for all applicable Federal uses. It is also a general means of reference for such devices and associated protocols and standards used for authenticating users securely.

Passwordless for Windows

Registration - Windows

Browser Registration - Windows

  1. Once you have been instructed to follow the prompts to complete pairing, the following dialog will occur:

  2. Click OK on the Continue setup dialog to grant permission to see the make and model of the key.

  3. Type the key's PIN and click OK.


    If you mistype the PIN, try again.


  4. Type the PIN you want to use, then type it again to confirm it.

  5. Touch the contact(s) on the security key.

  6. Your security key is now registered with the app in question, and you are returned to the Device Manager.



Workstation Registration - Windows

  1. Open the HYPR Passwordless client.

  2. Click Start Pairing. You will be given a choice of pairing a Smartphone or pairing with a Security Key.

  3. Select Security Key to continue.



    Connect First

    Make sure you are connected to your secure network, or a warning will appear upon clicking Start Pairing. If this occurs, just connect to your secure network and click Try again.

  4. You will be asked to set a PIN for the key. Type the PIN once, then confirm it by typing it again in the second field. Click Pair.

    PIN Sharing

    YubiKey Bio MPE security keys feature a device PIN that is shared between the PIV and FIDO2 protocols. The PIN you set during the HYPR Passwordless registration will apply for both desktop authentication (PIV) and web access (FIDO2/WebAuthN).


    PIN Requirements
    • The PIN must be between 6 and 8 characters
    • Users are not allowed to choose repeating digits in PINs, such as 111111
    • The PIN may not be left as the default value of 123456

  5. A browser dialog will ask you to touch the fingerprint sensor on your key. If you wish to bypass fingerprint registration, click Skip Fingerprint Registration.

  6. You will have to touch it several times with the same finger to generate a good image.

  7. Name the fingerprint. When you are satisfied with the name, click Set Name. To bypass naming your fingerprint, click Skip Name.

  8. Click Finish. Wait for enrollment to complete. You may be asked to authenticate to the workstation.

  9. The HYPR Passwordless client returns to the main screen. The paired security key now appears here with Edit (pencil icon) and Delete (trash can icon) options.



Authentication - Windows

Browser Authentication - Windows

  1. When the browser prompt appears, enter your security key PIN.

  2. Touch the contacts point(s) on your security key.

  3. You are logged into the application.



Workstation Authentication - Windows

  1. Insert your paired YubiKey Bio MPE into the USB port of the computer. Windows will offer the smart card icon as an additional login option. Click the smart card icon.

  2. The YubiKey Bio Login dialog appears. Depending on your environment and configuration, you will be prompted to type your security key PIN or, on the key, touch the fingerprint sensor. To switch between methods, click Use [YubiKey Bio PIN/Fingerprint] instead.



  3. Provided you have entered a correct PIN and/or used a registered fingerprint, HYPR Passwordless logs you in.



Deregistration - Windows

When unpairing a method from HYPR Passwordless, make sure you have another means of logging in. If you do not, we recommend pairing another method, such as the HYPR Mobile App, before unpairing your last method.



Browser Deregistration - Windows

HYPR handles unpairing the YubiKey Bio MPE from the RP application; no browser dialogs appear when this action is taken.



Workstation Deregistration - Windows

Partial Reset

Because the PIN on a YubiKey Bio MPE is shared, a PIN reset will also remove the FIDO2 credentials in the security key.

As a result HYPR does not fully reset the key during de-registration of a YubiKey Bio MPE and instead just removes the certificate and its corresponding private key.

  1. Open the HYPR Passwordless client.

  2. Click the trash can icon under the key you wish to remove.

  3. Confirm the deregistration request.

  4. Enter the security key PIN to confirm unpairing, then click Unpair.

  5. HYPR informs you when unpairing is complete, then returns to the Device Manager.



Changing the Fingerprint and PIN - Windows

  1. Open the HYPR Passwordless client.

  2. Click the pencil icon under the key you wish to update. The Update Biometric Key dialog opens.

  3. Choose the value you wish to update.

    • Change PIN: You will be prompted to enter the PIN and confirm with with a second entry. When you are finished, click Finish to save the values.

    • Manage Fingerprints: You may be asked to enter the PIN to access Fingerprint Management. A list of registered prints displays, including the name entered earlier (this will be blank if that part was skipped) and buttons to Save changes to the key, Cancel making changes, and Delete the key. Here you may also Delete All fingerprints or Add Fingerprint (repeats the pairing process described in Workstation Registration).

  4. When you are finished making updates, click Go Back to return to the Update Biometric Key dialog; then click Cancel to return to the HYPR Passwordless Device Manager.

Resetting a YubiKey Bio MPE Security Key at Login - Windows

If a user cannot recall the key's PIN, they will have the option to reset the YubiKey Bio MPE; this will cause some of the credentials to return to factory defaults.

Partial Reset

Because the PIN on a YubiKey Bio MPE is shared, a PIN reset will also remove the FIDO2 credentials in the security key.

  1. If the PIN is entered incorrectly too many times, the following message displays. Click Reset Device to initiate a factory reset.

  2. A confirmation dialog displays. Click Reset to continue.

  3. Once the key has been reset, a confirmation dialog appears. Since the PIN has been reset, the key must be paired again with HYPR. Click Pair Again to open the HYPR Passwordless Start Pairing dialog; see the Workstation Registration section in this article.

Passwordless for macOS

YubiKey Bio MPE is only supported for use on macOS via Web channel RP applications.

Browser Registration - macOS

Prompts given by a browser (Chrome) in this case to register a YubiKey Bio MPE key.

  1. Choose how to manage your passkeys. Click Open 'Password Options".

  2. Choose a location to save the passkey; in this instance, choose Use a phone, tablet, or security key.

  3. Enter the PIN for the key, then click Next.

  4. Repeatedly touch your finger to the Touch ID until your fingerprint has been successfully captured.



  5. Touch your key once more.

  6. Allow the site to see your key.

You are returned to the Device Manager.



Browser Authentication - macOS

The Browser dialogs that occur after choosing to login with a Passkey at a HYPR web login.

Place your finger on the Touch ID scanner.

That's it.



Browser Deregistration - macOS

When unpairing a method from HYPR Passwordless, make sure you have another means of logging in. If you do not, we recommend pairing another method, such as the HYPR Mobile App, before unpairing your last method.

HYPR handles unpairing the YubiKey Bio MPE from the RP application; no browser dialogs appear when this action is taken.