// VERIFICATION FACTOR 1 OF 7

๐Ÿ”‘ YubiKey FIDO2

Hardware-backed authentication using the WebAuthn / FIDO2 standard. A physical touch of the YubiKey is required for every session โ€” no password fallback is permitted.

โœ“
AUTHENTICATED
YubiKey 5 Series ยท FIDO2 session active ยท Touch not required until next login
WHAT IS THIS FACTOR?

Your YubiKey is a physical hardware security key that generates a cryptographic proof of your identity. Unlike a password, it cannot be phished, guessed, or stolen remotely. The key must be physically present and touched to authenticate.

Why hardware keys? Software 2FA (TOTP apps, SMS) can be intercepted. A hardware FIDO2 key binds authentication to a physical object. Without the key in your hand, nobody can log in โ€” including you.
REGISTRATION
Register your YubiKey with Keycloak once. All SNO services then require it for access.
1

Open Keycloak Admin

Navigate to http://your-rpi-ip:8080/realms/secure-os/account and log in as your SNO user. This is a one-time setup.

2

Go to Security โ†’ Signing In

Select Security Key under Two-Factor Authentication. Click Set Up Authenticator Application then switch to Security Key.

3

Insert YubiKey and touch

Browser prompts for the key. Insert your YubiKey 5 into USB. Touch the gold contact when the indicator flashes. Registration takes under 5 seconds.

4

Register backup key

Repeat steps 2โ€“3 with your backup YubiKey. Store the backup at a different physical location. Without a backup, losing your primary key locks you out permanently.

5

Set as Required

In Keycloak Admin: Authentication โ†’ Flows โ†’ Browser. Set WebAuthn Authenticator to REQUIRED. This disables password-only logins entirely.

BROWSER TEST
Test WebAuthn availability in this browser. Full registration requires Keycloak on HTTPS or localhost.
โณ Not yet tested
SETUP LINKS
TROUBLESHOOTING
YubiKey not recognised? Ensure your browser supports WebAuthn (Chrome, Firefox, Edge, Safari โ€” all do). If using a USB-C YubiKey, try a USB-A adapter. The key must be inserted before clicking authenticate.
Lost your key? Physical access to the RPi is required. SSH in with a known IP, access the Keycloak admin console directly, remove the old key registration, and register your backup key.
No backup key? If you lose your only YubiKey with no backup registered, recovery requires physical console access to the Raspberry Pi and manual Keycloak database intervention. Register a backup key NOW.