Overview
Three YubiKeys have been purchased to provide secure authentication and disaster recovery.
Each key has a defined purpose and responsibility.
YubiKey Inventory
YK-01
Testing
Model
YubiKey 5C NFC
Purpose
Primary test key.
Planned Location
Key ring.
YK-02
Unconfigured
Model
YubiKey 5C NFC
Purpose
Backup authentication key.
Planned Location
Secure backup location.
YK-03
Unconfigured
Model
YubiKey 5C Nano
Purpose
Primary laptop authentication key.
Planned Location
Laptop.
Current Standard
Only one YubiKey will be configured initially.
The remaining keys will stay unconfigured until the authentication workflow has been fully validated.
Once testing has been completed successfully, all three keys will be configured identically and registered with every supported service.
A common FIDO2 PIN is used across all three keys. The PIN is not recorded here. It is stored encrypted in the secrets vault as YUBIKEY_FIDO2_PIN and can be retrieved with /secrets get.
Implementation Log
🚧
No entries yet. The log will be updated as each key is configured, tested and commissioned.