This article demonstrates how to activate and use YubiKey and Feitian OTP hardware tokens.
Add a Feitian OTP c100
A Feitian Hardware Token is a small, battery-powered device, often on a keychain, that displays a numeric code. This code changes automatically every 30-60 seconds. You must read the code from the token's screen and type it into the 2FA prompt to log in.
Note: These steps are only for the Feitian c100 token. No other Feitian tokens, including the c200, are approved as compatible with UA systems.
____________________
Instructions
-
- Navigate to the 2FA Portal.
- Select Manage Your Account and log in with your NetID and password.
- Scroll down and select the Hardware Token drop-down panel.
- Select Add an HOTP Token.
_______________
The HOTP Secret & Serial Number
Enter the Serial Number that is found on the back of the Feitian hardware token.
Follow the instructions that match where you got your token for the HOTP Secret.
-
- If you purchased your token from the UA Bookstore:
- Leave the HOTP Secret field blank.
- If you purchased your device from the Feitian website, you must enter the HOTP Secret from the.txt file attachment you received in an email from Feitian.
- Open the attachment. You will see two long values separated by a space.
- Copy the second value and paste it into the HOTP Secret field.
- Click Continue.
Use a Feitian OTP c100
Follow the steps below to log in with your Feitian c100 OTP hardware token.
Note: These steps are only for the Feitian c100 token. No other Feitian tokens, including the c200, are compatible with UA systems.
_______________
Instructions
-
- Log in to a UA service with your NetID and password as usual. You will be directed to the 2FA authentication page.
- The 2FA page may default to your last-used login method (e.g., a Duo Push). If your hardware token is not the default, select Other Options and then select your Feitian token.
- When prompted for a passcode:
- Press the refresh button on your Feitian token (it looks like a power button) to generate a new six-digit passcode.
- Type this passcode into the field on your screen.
- Select Verify.
- The prompt "Is this your device?" refers to remembering you for future logins.
- Select "Yes, this is my device" ONLY if you are on a private, secure computer.
- Select "No, other people use this device" if you are on a shared or public computer (e.g., in a library, lab, or classroom).
- If you see the prompt in the screenshot below, click the checkbox to Trust this browser for 30 days.
Note: Check this box only if you are on a private, secure computer. Never use this option on a shared or public computer (e.g., in a library, lab, or classroom). Please be aware that some high-security services may still require 2FA, even after you have trusted the browser.
- Select Continue to application.
Add a Yubikey 5 NFC
A YubiKey Hardware Token is a physical device that you connect to your computer or phone (via USB).
The Yubikey 5 NFC now requires the use of the Yubico Authenticator software and the instructions previously shared in this article are no longer valid.
For now, we recommend that you review Duo's documentation on Using Yubikeys with Duo.
____________________
Note: The instructions for adding a device to the portal have been left in the article but may be incomplete. Please share your feedback on this article about your experience.
Add a Device in the 2FA Portal
Instructions
-
- Navigate to the 2FA Portal.
- Select Manage Your Account and log in with your NetID and password.
- Scroll down and select Hardware Token.
- Select Add a Yubikey Token.
- A new window will open. Keep this 2FA Portal window open as you will need to copy the Public ID, Private ID, and Secret key values from the Yubico Authenticator tool.
____________________
You may also want to review the following support site from the vendor, especially if you need to verify compatibality of your Yubikey with the Yubikey Authenticator software: Using your YubiKey with authenticator codes
Use a Yubikey 5 NFC
Follow the steps below to log in with your Yubikey hardware token.
Note: Any Yubikey model except the FIDO U2F Security Key will work with 2FA, however these instructions are for the Yubikey 5 NFC.
____________________
Instructions
-
- Log in to a UA service with your NetID and password as usual. You will be directed to the 2FA authentication page.
- The 2FA page may default to your last-used login method (e.g., a Duo Push). If your hardware token is not the default, select Other Options and then select your Yubikey token.
- When prompted for a passcode, insert the Yubikey into a USB port on the computer..
- With the cursor in the Passcode field, press the touch-sensitive circle (some models may have a button) on the Yubikey to 'type' a one-time password (OTP) into the field.
Note: If your USB port is old or dirty, you may get this error: "This passcode has already been used, try again with a new passcode."
- The prompt "Is this your device?" refers to remembering you for future logins.
- Select "Yes, this is my device" ONLY if you are on a private, secure computer.
- Select "No, other people use this device" if you are on a shared or public computer (e.g., in a library, lab, or classroom).
- If you see the prompt in the screenshot below, click the checkbox to Trust this browser for 30 days.
Note: Check this box only if you are on a private, secure computer. Never use this option on a shared or public computer (e.g., in a library, lab, or classroom). Please be aware that some high-security services may still require 2FA, even after you have trusted the browser.
- Select Continue to application.