Hardware-backed authentication using the WebAuthn / FIDO2 standard. A physical touch of the YubiKey is required for every session โ no password fallback is permitted.
Your YubiKey is a physical hardware security key that generates a cryptographic proof of your identity. Unlike a password, it cannot be phished, guessed, or stolen remotely. The key must be physically present and touched to authenticate.
Navigate to http://your-rpi-ip:8080/realms/secure-os/account and log in as your SNO user. This is a one-time setup.
Select Security Key under Two-Factor Authentication. Click Set Up Authenticator Application then switch to Security Key.
Browser prompts for the key. Insert your YubiKey 5 into USB. Touch the gold contact when the indicator flashes. Registration takes under 5 seconds.
Repeat steps 2โ3 with your backup YubiKey. Store the backup at a different physical location. Without a backup, losing your primary key locks you out permanently.
In Keycloak Admin: Authentication โ Flows โ Browser. Set WebAuthn Authenticator to REQUIRED. This disables password-only logins entirely.
| RESOURCE | URL | NOTES |
|---|---|---|
| Keycloak Admin | localhost:8080 | Your local instance |
| Yubico โ Buy YubiKey 5 | yubico.com | YubiKey 5 NFC or 5C NFC |
| WebAuthn Guide | webauthn.guide | How FIDO2 works |
| Keycloak WebAuthn Docs | keycloak.org/docs | Server-side config |
| FIDO Alliance | fidoalliance.org | Standard specification |