Follow

Keep Up to Date with the Most Important News

By pressing the Subscribe button, you confirm that you have read and are agreeing to our Privacy Policy and Terms of Use
Contact

How can I reset the fido PIN on a yubikey using ykman?

In order to test something, I need to set a PIN on a yubikey. I found that I can do that using ykman fido access change-pin. However, I did not find any option to remove that PIN afterwards. I only want to set the PIN for a short test, so how can I remove it again?

I do not want a factory reset. I only want to reset the fido PIN.

MEDevel.com: Open-source for Healthcare and Education

Collecting and validating open-source software for healthcare, education, enterprise, development, medical imaging, medical records, and digital pathology.

Visit Medevel

>Solution :

As far as I’m aware, the CTAP protocol which governs FIDO behavior does not define such behavior, so you have to do a complete reset of the FIDO applications to reset the PIN.

ykman fido reset

CTAP 2.1 does specify a set minimum PIN length feature which allows you to set a flag requiring the PIN to be changed on the next use, but I have not yet encountered a Yubikey with that feature present.

Add a comment

Leave a Reply

Keep Up to Date with the Most Important News

By pressing the Subscribe button, you confirm that you have read and are agreeing to our Privacy Policy and Terms of Use

Discover more from Dev solutions

Subscribe now to keep reading and get access to the full archive.

Continue reading