{"id":239573,"date":"2023-02-28T13:42:12","date_gmt":"2023-02-28T11:42:12","guid":{"rendered":"https:\/\/shop.thekernel.ua\/how-to-add-a-spare-yubikey-security-key-and-why-to-do-it"},"modified":"2023-03-20T15:08:55","modified_gmt":"2023-03-20T13:08:55","slug":"how-to-add-a-spare-yubikey-security-key-and-why-to-do-it","status":"publish","type":"post","link":"https:\/\/shop.thekernel.ua\/en\/how-to-add-a-spare-yubikey-security-key-and-why-to-do-it","title":{"rendered":"How to add a spare YubiKey security key and why to do it"},"content":{"rendered":"<p>[et_pb_section fb_built=&#8221;1&#8243; _builder_version=&#8221;4.17.3&#8243; background_image=&#8221;https:\/\/shop.thekernel.ua\/wp-content\/uploads\/2019\/05\/Security-Key-NFC-by-Yubico-Laptop-1030&#215;687.jpg&#8221; parallax=&#8221;on&#8221; min_height=&#8221;610px&#8221; custom_margin=&#8221;-170px||||false|false&#8221; custom_padding=&#8221;60px||22px||false|false&#8221; locked=&#8221;off&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_row custom_padding_last_edited=&#8221;on|phone&#8221; _builder_version=&#8221;4.20.0&#8243; background_size=&#8221;initial&#8221; background_position=&#8221;top_left&#8221; background_repeat=&#8221;repeat&#8221; width_tablet=&#8221;&#8221; width_phone=&#8221;92%&#8221; width_last_edited=&#8221;on|desktop&#8221; custom_margin=&#8221;|auto|0px|auto|false|false&#8221; custom_padding=&#8221;70px||0px||false|false&#8221; custom_padding_tablet=&#8221;0px||||false|false&#8221; custom_padding_phone=&#8221;84px||||false|false&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.16&#8243; custom_padding=&#8221;|||&#8221; global_colors_info=&#8221;{}&#8221; custom_padding__hover=&#8221;|||&#8221;][et_pb_text _builder_version=&#8221;4.20.2&#8243; text_font=&#8221;|900|||||||&#8221; text_text_color=&#8221;#ffffff&#8221; text_font_size=&#8221;65px&#8221; text_letter_spacing=&#8221;2px&#8221; text_line_height=&#8221;1.8em&#8221; header_font=&#8221;|800|||||||&#8221; header_text_color=&#8221;#ffffff&#8221; header_font_size=&#8221;65px&#8221; header_letter_spacing=&#8221;2px&#8221; header_line_height=&#8221;1.8em&#8221; text_orientation=&#8221;center&#8221; custom_margin=&#8221;0px||||false|false&#8221; custom_margin_phone=&#8221;0px||||false|false&#8221; custom_margin_last_edited=&#8221;off|desktop&#8221; text_font_size_tablet=&#8221;49px&#8221; text_font_size_phone=&#8221;38px&#8221; text_font_size_last_edited=&#8221;on|tablet&#8221; text_line_height_tablet=&#8221;1.8em&#8221; text_line_height_phone=&#8221;1.8em&#8221; text_line_height_last_edited=&#8221;on|desktop&#8221; header_font_size_tablet=&#8221;&#8221; header_font_size_phone=&#8221;38px&#8221; header_font_size_last_edited=&#8221;on|desktop&#8221; text_text_shadow_style=&#8221;preset1&#8243; header_text_shadow_style=&#8221;preset1&#8243; text_text_align=&#8221;center&#8221; global_colors_info=&#8221;{}&#8221;]<\/p>\n<h1><span style=\"color: #ffffff;\"><b>How to add a spare YubiKey security key and why to do it<\/b><\/span><\/h1>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section][et_pb_section fb_built=&#8221;1&#8243; _builder_version=&#8221;4.16&#8243; global_colors_info=&#8221;{}&#8221;][et_pb_row _builder_version=&#8221;4.16&#8243; background_size=&#8221;initial&#8221; background_position=&#8221;top_left&#8221; background_repeat=&#8221;repeat&#8221; width_tablet=&#8221;&#8221; width_phone=&#8221;92%&#8221; width_last_edited=&#8221;on|desktop&#8221; custom_margin_tablet=&#8221;&#8221; custom_margin_phone=&#8221;|5.1%||3%|false|false&#8221; custom_margin_last_edited=&#8221;on|desktop&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_column type=&#8221;4_4&#8243; _builder_version=&#8221;4.16&#8243; custom_padding=&#8221;|||&#8221; global_colors_info=&#8221;{}&#8221; custom_padding__hover=&#8221;|||&#8221;][et_pb_text _builder_version=&#8221;4.20.0&#8243; text_text_color=&#8221;#333&#8243; text_font_size=&#8221;16px&#8221; header_text_color=&#8221;#111&#8243; global_colors_info=&#8221;{}&#8221;]<\/p>\n<h1><b><\/b><\/h1>\n<h1><b><\/b><\/h1>\n<h1><b>How to add a spare YubiKey security key and why to do it<\/b><\/h1>\n<p>&nbsp;<\/p>\n<hr>\n<p><b>YubiKey hardware security key<\/b><span style=\"font-weight: 400;\"> very reliable \u2013 it is resistant to wear and tear and does not lose its properties when exposed to water. But it has a small size, so it can get lost by accident. Also, criminals can try to steal it if you often work in crowded places. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">Of course, after losing the security key, almost all access to accounts can be restored, but correspondence with service administrations can take a lot of time. In order not to lose it, we, as the official distributors of the YubiKey manufacturer in Ukraine, always recommend buying a pair <\/span><b>security keys<\/b><span style=\"font-weight: 400;\">, one of which will be kept in a safe place, such as a safe.<\/span> <\/p>\n<p><span style=\"font-weight: 400;\">The second<\/span> <b>YubiKey hardware key<\/b><span style=\"font-weight: 400;\">, does not necessarily have to be the same form factor or belong to the same series as the main one. But it is important that the keys support the same protocols. These can be OTP passwords, FIDO2, FIDO U2F or the OATH-TOTP protocol.<\/span><\/p>\n<p><b><i>Importantly.<\/i><\/b><i><span style=\"font-weight: 400;\"> Having a spare key will help in emergency situations and save precious time. <\/span><\/i><\/p>\n<h2><b>Registration of the YubiKey security key with OTP or FIDO protocols<\/b><\/h2>\n<p>&nbsp;<\/p>\n<hr>\n<p><span style=\"font-weight: 400;\">To find out which services support the security key protocols of your choice, go to the \u201c<\/span><a href=\"https:\/\/shop.thekernel.ua\/en\/compatible-with-yubikey\"><span style=\"font-weight: 400;\">Services Compatible<\/span> <b>with YubiKey Security<\/b> <span style=\"font-weight: 400;\">Keys<\/span><\/a><span style=\"font-weight: 400;\">\u201d.<\/span> <\/p>\n<p><span style=\"font-weight: 400;\">If your security key supports <\/span><b>OTP<\/b><sup>1<\/sup><b> \u0430\u0431\u043e FIDO<\/b><sup>2<\/sup><span style=\"font-weight: 400;\">protocols, the second key will need to be registered<\/span><sup style=\"font-weight: 400;\">3<\/sup><span style=\"font-weight: 400;\"> just like the first one. But keep in mind that the keys are not related to each other in any way, because they are created in such a way that the information contained on them cannot be transferred or copied. Therefore, each key must be registered separately so that any of them can be used for authentication in the future. <\/span><\/p>\n<p><sup style=\"font-weight: 400;\">1<\/sup> <i><span style=\"font-weight: 400;\">OTP (<\/span><\/i><i><span style=\"font-weight: 400;\">One Time Password<\/span><\/i><i><span style=\"font-weight: 400;\">) is a password that is valid only for one authentication session.<\/span><\/i><\/p>\n<p><sup style=\"font-weight: 400;\">2 <\/sup><span style=\"font-weight: 400;\"> <\/span><i><span style=\"font-weight: 400;\">FIDO (<\/span><\/i><i><span style=\"font-weight: 400;\">Fast Identity Online<\/span><\/i><i><span style=\"font-weight: 400;\">) is a protocol for passwordless or two-factor authentication. <\/span><\/i> <\/p>\n<p><sup style=\"font-weight: 400;\">3<\/sup> <i><span style=\"font-weight: 400;\">To register <\/span><\/i><b><i>the security key<\/i><\/b><i><span style=\"font-weight: 400;\">, you can use the instructions in <\/span><\/i><a href=\"https:\/\/shop.thekernel.ua\/en\/compatible-with-yubikey\"><i><span style=\"font-weight: 400;\">the catalog<\/span><\/i><\/a><i><span style=\"font-weight: 400;\">. <\/span><\/i> <\/p>\n<h2><b>Registration of YubiKey security key with OATH-TOTP protocol<\/b><\/h2>\n<p>&nbsp;<\/p>\n<hr>\n<p><span style=\"font-weight: 400;\">If your chosen service or service uses the <\/span><b>OATH-TOTP<\/b><sup>4<\/sup><span style=\"font-weight: 400;\">protocol, then you need to register the second security key differently. <\/span> <\/p>\n<p><sup style=\"font-weight: 400;\">4 <\/sup><i><span style=\"font-weight: 400;\">OATH-TOTP (<\/span><\/i><i><span style=\"font-weight: 400;\">Time-based One-Time Password Algorithm<\/span><\/i><i><span style=\"font-weight: 400;\">) is a secure authentication algorithm using a one-time password.<\/span><\/i><\/p>\n<p><span style=\"font-weight: 400;\">When you register the first key, you will receive a secret in the form of a QR code. You will need to scan it and save it in a safe place. This code will be needed when registering the second key. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">To do this, you will first need to use the Yubico Authenticator app to scan the QR code that was issued to the first security key by the service. Then get the QR code for the second security key. Scan it with the same app and link them that way. After that, you can use any of these keys for authentication. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">Please note: If you did not save the QR code that was provided to you by the service or service the first time, you must first delete the key from your account and start registering security keys again. <\/span><\/p>\n<h2><b>Registration of YubiKey security key with Challenge-Response protocol<\/b><\/h2>\n<p>&nbsp;<\/p>\n<hr>\n<p><span style=\"font-weight: 400;\">For services that use Challenge-Response (or \u201crequest-response\u201d) protocols or a static password function, the second key registration instructions will be similar to the previous one. Only for the Challenge-Response protocol, instead of the QR code, you will need a backup copy of the secret encrypted in the first key of the YubiKey. With its help, you will encrypt your data in a spare key. <\/span><\/p>\n<p>&nbsp;<\/p>\n<p><span style=\"font-weight: 400;\">To perform these actions, you will need the YubiKey-manager application, which can be downloaded from the links:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"https:\/\/support.yubico.com\/support\/solutions\/articles\/15000010964-enabling-the-yubico-ppa-on-ubuntu\"><span style=\"font-weight: 400;\">Linux \u2013 Ubuntu Download<\/span><\/a><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"https:\/\/developers.yubico.com\/yubikey-manager-qt\/Releases\/yubikey-manager-qt-latest-linux.AppImage\"><span style=\"font-weight: 400;\">Linux \u2013 Download AppImage<\/span><\/a> <span style=\"font-weight: 400;\"> (may need to install pcscd package)<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"https:\/\/developers.yubico.com\/yubikey-manager-qt\/Releases\/yubikey-manager-qt-latest.tar.gz\"><span style=\"font-weight: 400;\">Linux \u2013 Download source code<\/span><\/a><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"https:\/\/developers.yubico.com\/yubikey-manager-qt\/Releases\/yubikey-manager-qt-latest-mac.pkg\"><span style=\"font-weight: 400;\">Download macOS<\/span><\/a><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"https:\/\/developers.yubico.com\/yubikey-manager-qt\/Releases\/yubikey-manager-qt-latest-win64.exe\"><span style=\"font-weight: 400;\">Windows (x64) Download<\/span><\/a><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"https:\/\/developers.yubico.com\/yubikey-manager-qt\/Releases\/yubikey-manager-qt-latest-win32.exe\"><span style=\"font-weight: 400;\">Windows (x86) Download<\/span><\/a><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">In the application, go to the menu <strong>program -&gt; OTP<\/strong> and make settings<\/span><\/p>\n<hr>\n<p><span style=\"font-weight: 400;\"><\/span><\/p>\n<p><span style=\"font-weight: 400;\">You will not need a copy of your credentials to register a spare key with the static password feature enabled. But only if your password does not exceed 38 characters. Otherwise, you will need to use a copy of the parameters stored in the credentials: public ID, private ID, and secret key. <\/span><\/p>\n<p><span style=\"font-weight: 400;\">You will need the YubiKey Personalization Tool to set it up. It works with all keys (except the Security Key series). You can download them from the links below.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Download YubiKey Personalization Tool v3.1.25:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"https:\/\/developers.yubico.com\/yubikey-personalization-gui\/Releases\/yubikey-personalization-gui-3.1.25.tar.gz\"><span style=\"font-weight: 400;\">Download Linux<\/span><\/a><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"https:\/\/developers.yubico.com\/yubikey-personalization-gui\/Releases\/yubikey-personalization-gui-3.1.25.pkg\"><span style=\"font-weight: 400;\">Download for Mac (.pkg file)<\/span><\/a><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"https:\/\/developers.yubico.com\/yubikey-personalization-gui\/Releases\/yubikey-personalization-gui-3.1.25.exe\"><span style=\"font-weight: 400;\">Download Microsoft Windows<\/span><\/a><\/li>\n<\/ul>\n<hr>\n<p><span style=\"font-weight: 400;\">Download YubiKey Personalization Tool v1.19.0:<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"https:\/\/developers.yubico.com\/yubikey-personalization\/Releases\/ykpers-1.19.0.tar.gz\"><span style=\"font-weight: 400;\">Download Linux<\/span><\/a><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"https:\/\/developers.yubico.com\/yubikey-personalization\/Releases\/ykpers-1.19.0-mac.zip\"><span style=\"font-weight: 400;\">Download Mac<\/span><\/a><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"https:\/\/developers.yubico.com\/yubikey-personalization\/Releases\/ykpers-1.19.0-win64.zip\"><span style=\"font-weight: 400;\">Download the 64-bit version of Microsoft Windows<\/span><\/a><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"https:\/\/developers.yubico.com\/yubikey-personalization\/Releases\/ykpers-1.19.0-win32.zip\"><span style=\"font-weight: 400;\">Download the 32-bit version of Microsoft Windows<\/span><\/a><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">In the application menu, find sections <\/span><b>Static password &gt; Additionally<\/b><span style=\"font-weight: 400;\"> and make the necessary settings. As in the previous cases, if you have not previously saved your public ID, private ID and secret key, you will need to delete the first key from your account and register again.<\/span><\/p>\n<p><span style=\"font-weight: 400;\"><\/span><\/p>\n<p><span style=\"font-weight: 400;\"><\/span><\/p>\n<p><span style=\"font-weight: 400;\"><\/span><\/p>\n<p><span style=\"font-weight: 400;\"><\/span><\/p>\n<p><span style=\"font-weight: 400;\"><\/span><\/p>\n<p><span style=\"font-weight: 400;\"><\/span><\/p>\n<p><span style=\"font-weight: 400;\"><\/span><\/p>\n<p><span style=\"font-weight: 400;\"><\/span><\/p>\n<p><span style=\"font-weight: 400;\"><\/span><\/p>\n<hr>\n<p style=\"text-align: center;\"><span style=\"font-size: x-large;\"><strong>If you have not yet purchased a second key, you can choose it in <a href=\"https:\/\/shop.thekernel.ua\/shop\">our online store<\/a>. <\/strong><\/span><\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section][et_pb_section fb_built=&#8221;1&#8243; fullwidth=&#8221;on&#8221; _builder_version=&#8221;4.17.1&#8243; _module_preset=&#8221;default&#8221; global_colors_info=&#8221;{}&#8221;][et_pb_fullwidth_post_slider include_categories=&#8221;current&#8221; _builder_version=&#8221;4.17.1&#8243; _module_preset=&#8221;default&#8221; background_enable_color=&#8221;off&#8221; background_image=&#8221;https:\/\/shop.thekernel.ua\/wp-content\/uploads\/2022\/04\/090f3141-scaled.jpg&#8221; custom_margin=&#8221;||-85px||false|false&#8221; global_colors_info=&#8221;{}&#8221;][\/et_pb_fullwidth_post_slider][\/et_pb_section]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>How to add a spare YubiKey security key and why to do it How to add a spare YubiKey security key and why to do it &nbsp; YubiKey hardware security key very reliable \u2013 it is resistant to wear and tear and does not lose its properties when exposed to water. But it has a [&hellip;]<\/p>\n","protected":false},"author":55,"featured_media":239586,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_seopress_robots_primary_cat":"none","_seopress_titles_title":"How to add a spare YubiKey security key ","_seopress_titles_desc":"The hardware security key YubiKey is very reliable \u2013 it is resistant to wear and tear and does not lose its properties when it gets into water. But he can get lost. A spare key solves this problem.","_seopress_robots_index":"","_et_pb_use_builder":"on","_et_pb_old_content":"","_et_gb_content_width":"","footnotes":""},"categories":[402],"tags":[],"class_list":["post-239573","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-settings"],"acf":[],"_links":{"self":[{"href":"https:\/\/shop.thekernel.ua\/en\/wp-json\/wp\/v2\/posts\/239573","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/shop.thekernel.ua\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/shop.thekernel.ua\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/shop.thekernel.ua\/en\/wp-json\/wp\/v2\/users\/55"}],"replies":[{"embeddable":true,"href":"https:\/\/shop.thekernel.ua\/en\/wp-json\/wp\/v2\/comments?post=239573"}],"version-history":[{"count":13,"href":"https:\/\/shop.thekernel.ua\/en\/wp-json\/wp\/v2\/posts\/239573\/revisions"}],"predecessor-version":[{"id":240537,"href":"https:\/\/shop.thekernel.ua\/en\/wp-json\/wp\/v2\/posts\/239573\/revisions\/240537"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/shop.thekernel.ua\/en\/wp-json\/wp\/v2\/media\/239586"}],"wp:attachment":[{"href":"https:\/\/shop.thekernel.ua\/en\/wp-json\/wp\/v2\/media?parent=239573"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/shop.thekernel.ua\/en\/wp-json\/wp\/v2\/categories?post=239573"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/shop.thekernel.ua\/en\/wp-json\/wp\/v2\/tags?post=239573"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}