IT organizations that want to leverage PIV and store their certificates on YubiKeys need key security components to make deployments easier. SecureW2 bundles together turnkey PKI services, onboarding software for end users to enroll for certificates, and authentication services.
In the SecureW2 Management Portal, everything that is needed to enroll a YubiKey for a certificate
can be done using the Getting Started Wizard, which is available under Device Onboarding > Getting Started.
Configure the Wizard with the following settings:
- Choose your Identity Provider:Β SecureW2 supports Google, Active Directory, Okta, LDAP and every other major Identity Provider to authenticate users for certificate enrollment. Specify your IDP here.
- PIN/PUK Requirements:Β Ensuring YubiKeys are not using default PIN and PUKs are extremely important. Configure your organizationβs security policies regarding PIN/PUK here.
- Certificate Template:Β The SecureW2 PKI services empower organizations to generate custom certificates for Desktop Login, VPN, Wi-Fi, and more. Specify the application of your certificate here.
- Run the Wizard:Β After configure the settings above, run the Wizard and it will configure everything required to configure your YubiKeys for certificates.
1.1 Configuring YubiKey Certificate Enrollment Settings
There are a number of Certificate Enrollment settings available for configuration with SecureW2, for an incredibly easy and customizable end-user experience.
To configure these settings:
- Navigate toΒ Network Profiles.
- Click EditΒ on the Network Profile you created in the Getting Started Wizard.
- Click EditΒ on Network Settings.
- Under the Client Certificate section, configure the following settings:
- Select theΒ Enforce Smart CardΒ checkbox.
- SelectΒ YubiKeyΒ from the Smart Card drop-down list.
- SelectΒ EnabledΒ from theΒ Require TouchΒ drop-down list, if you want the users to touch their YubiKeys.
- Optionally, configureΒ PIN Management.
- Select theΒ Prevent Default PINΒ if you want to prevent YubiKeys with default PINs from
enrolling for certificates. - Minimum PINΒ Length allows you to require a minimum PIN length.
- Enforce PIN ComplexityΒ enforces the following PIN complexity conditions. Contain characters from the following categories:
- English uppercase characters (A through Z).
- English lowercase characters (a through z).
- Base 10 digits (0 through 9).
- Select theΒ Prevent Default PINΒ if you want to prevent YubiKeys with default PINs from
- Optionally, configureΒ PUKΒ Management.
- PUK Policy:
- SelectΒ Disable PUKΒ to prompt only for resetting YubiKey PIN.
- SelectΒ User EnabledΒ to prompt for resetting both YubiKey PIN and PUK.
- PUK Policy:
- ClickΒ Update.
- ClickΒ Update.
1.2 Key Attestation Settings
SecureW2 offers the ability for YubiKeys to perform Key Attestation, attesting that the private key was generated on the YubiKey itself. This allows administrators to create high security clearance access policies specifically for YubiKeys.
YubiKeys come by default with an attestation certificate signed by the standard Yubico PIV CA. Some YubiKeys, when ordered as a large custom batch, come with attestation certificates issued via a custom Root CA. If your YubiKeys have a custom attestation Root CA, you can also upload that here.
- Navigate toΒ Identity Management > Key Attestation Providers.
- Click AddΒ Key Attestation Provider.
- Create aΒ Name.
- Select Type asΒ YUBIKEY.
- ClickΒ Save.
- Navigate to theΒ ConfigurationΒ tab. To upload your custom Key Attestation Root CA:
- SelectΒ Choose File.
- Upload your CA. Allowed certificate file extensions are .cer, .crt, and .pem.
- ClickΒ Upload.
- ClickΒ Update.
- Now, your Key Attestation Provider will be a configurable setting when creating Device Policies.
1.3 Generate the Onboarding Page for YubiKey Self-Enrollment
After the Getting Started Wizard has finished, a landing page will be generated. This is where you will instruct your end-users to navigate to, so they can self-service their YubiKeys for certificates.
Every aspect of this page is completely customizable. Contact us for more information.
To get your landing page:
- Navigate toΒ Network ProfilesΒ and clickΒ View. You will be taken to the JoinNow Landing Page, which automatically detects the deviceβs Operating System and deploys the appropriate client to configure their YubiKey
- Copy this URL and instruct end-users to navigate to the page.
There are many other features you can configure in SecureW2, but the steps above outline the minimum setup required to start configuring YubiKeys for Certificates.
2. YubiKey Certificate Enrollment End User Flow
The following steps outline how the end-users can self-enroll themselves for unique certificates for their YubiKeys, using a macOS or a Windows device.
2.1 macOS
- Download the YubiKey Manager from https://www.yubico.com/products/servicessoftware/download/yubikey-manager.
- After you download and install the YubiKey Manager, reboot your computer.
- OpenΒ YubiKey Manager,Β and then insert your YubiKey.
- Go to theΒ JoinNow MultiOSΒ landing page.
- ClickΒ JoinNowΒ and the JoinNow client will download.
- Click theΒ SecureW2 JoinNowΒ app and clickΒ OpenΒ in the window that appears and the JoinNow client will begin configuration.
2.1.1 Enter or Reset PIN/PUK
Ensuring YubiKeys are not using default PIN and PUKs are extremely important. The JoinNow client can enforce any PIN/PUK complexity rules, detect if the user is using a default PIN/PUK, and prevent certificate enrollment until they have configured a secure and unique PIN/PUK.
Note:Β For security reasons, you can disable PUK reset YubiKeys from enrolling for certificates. To do this, navigate to step 4.e in the βConfiguring YubiKey Certificate Enrollment Settingsβ section.
If you have forgotten or need to reset your PIN, follow these steps:
- In the SecureW2 client, clickΒ Forgot PIN?
- You are prompted toΒ Use my (default) PUKΒ orΒ Reset your Yubikey.
- If you choose use my (default) PUK:
- Enter yourΒ PUK.
- Upon successful authentication, a new screen appears. This screen notifies you that resetting your YubiKey will erase all existing information stored on the YubiKey.
- Enter your newΒ PINΒ andΒ PUK,Β and then clickΒ Next.Β A screen confirming you have set a new PIN and PUK appears.
- Certificate enrollment resumes per the instructions in the next section.
- If you chooseΒ Reset your YubiKey:
- A new screen appears. This screen notifies you that resetting your YubiKey will erase all existing information stored on the YubiKey.
- Enter your newΒ PINΒ andΒ PUK,Β and then clickΒ Next.
- A screen appears confirming you have set a new PIN and PUK.
- Certificate enrollment resumes per the instructions in the next section.
- If you choose use my (default) PUK:
Note:Β If you enter your default PIN/PUK, you will be prompted to reset your YubiKey.
2.1.2 Certificate Enrollment and Installation
After the client has ensured the YubiKey has a secure PIN, users can begin the certificate enrollment and installation process.
- Click Next and the login page opens in a new tab.This login page can be configured for use with any LDAP (Active Directory) or SAML (Google Apps, Okta, OneLogin, and other major vendors) Identity Provider.
- Enter your organizationβs credentials. After the credentials are validated, you are returned to the JoinNow client.
- Enter your device credentials to allow JoinNow to configure your device.
- The JoinNow client now enrolls and configures the YubiKey for a certificate. When it finishes, clickΒ Done.
- Open theΒ Yubikey ManagerΒ and clickΒ Applications > PIV > Configure CertificatesΒ to verify the SecureW2 certificate successfully installed on your YubiKey.
2.1.3 Desktop Logon
Not only are YubiKeys enrolled for certificates with SecureW2, they are also configured for certificate applications such as desktop logon. After running the client, users can immediately start using their YubiKey for desktop logon.
In order to unlock the keychain in macOS, which is necessary for desktop logon, a self-signed certificate must be configured in Slot 9d. The client automatically does this, which can be seen by opening up the YubiKey Manager client.
2.2 Windows
- Download the YubiKey Smartcard Mini Driver for Windows: https://www.yubico.com/products/services-software/download/smart-card-drivers-tools.
- Click here for Yubicoβs documentation on installing the Mini Driver.
- After you download and install the driver, reboot your computer.
- Navigate to your organizationβsΒ JoinNowΒ landing page, and clickΒ JoinNowΒ to download the client.
- Open the .exe file that is downloaded to begin the configuration process.
2.2.1 Enter or Reset PIN/PUK
Ensuring YubiKeys are not using default PIN and PUKs are extremely important. The JoinNow client can enforce any PIN/PUK complexity rules, detect if the user is using a default PIN/PUK, and prevent certificate enrollment until they have configured a secure and unique PIN/PUK.
Note:Β For security reasons, you can disable PUK reset YubiKeys from enrolling for certificates. To do this, navigate to step 4.e in the βConfiguring YubiKey Certificate Enrollment Settingsβ section.
If you have forgotten, or need to reset your PIN, follow these steps:
- In the SecureW2 client, clickΒ Setup YubiKey/Forgot PIN.
- You are prompted toΒ Use PUKΒ or ResetΒ YubiKey.
- If you chooseΒ Use PUK:
- Enter yourΒ PUK.
- Upon successful authentication, a new screen appears prompting you to enter your new PIN and PUK.
- Enter your newΒ PINΒ andΒ PUK,Β and then clickΒ Next.Β A screen appears confirming you have set a new PIN and PUK.
- Certificate enrollment resumes per the instructions in the next section.
- If you choose Reset YubiKey
- A new screen appears. This screen notifies you that resetting your YubiKey will erase all existing information stored on the YubiKey.
- Enter your new PIN and PUK, and then click Next. A screen appears confirming youβve set a new PIN and PUK.
- Certificate enrollment resumes per the instructions in the following section.
- If you chooseΒ Use PUK:
Note:Β If you enter your default PIN/PUK, you will be prompted to reset your YubiKey.
2.2.2 Certificate Enrollment and Installation
After the client has ensured the YubiKey has a secure PIN, users can begin the certificate enrollment and installation process.
- ClickΒ NextΒ and a login page will open in a new tab. This login page can be configured for use with any LDAP (Active Directory) or SAML (Google Apps, Okta, OneLogin, and other major vendors) Identity Provider.
- Enter your organizationβs credentials. Once the credentials are validated, you are returned to the JoinNow client.
- The JoinNow client now enrolls and configures the YubiKey for a certificate. When it indicates you have joined the network, clickΒ Done.
- Open the Yubikey Manager and clickΒ Applications > PIV > Configure CertificatesΒ to verify the SecureW2 certificate successfully installed on your YubiKey.




