Skip to content

Integrate YubiKey with Securden Password Vault for Enterprises

YubiKey is a physical authentication device from Yubico that can be integrated with Securden Password Vault for Enterprises as a second factor of authentication. Once YubiKey-based two-factor authentication (2FA) is enabled, users must authenticate using their configured YubiKey after successfully completing the first level of authentication.

Prerequisite

Before configuring YubiKey as an authentication method, ensure that the machine hosting the Securden server can communicate with the Yubico OTP validation service.

Allow outbound access from the Securden server to the following URL through your firewall, proxy, or other network security controls:

https://api.yubico.com/wsapi/2.0/verify

Securden uses this endpoint to validate the one-time passwords generated by YubiKey. If the URL is blocked or cannot be reached from the Securden server, YubiKey OTP validation will fail and users will not be able to complete YubiKey-based authentication.

How to Enable YubiKey Authentication in Securden Password Vault

To enable YubiKey as a two-factor authentication method in Securden Password Vault:

  1. Navigate to Admin >> Authentication >> Two-Factor Authentication.
  2. Select YubiKey.
  3. Click Save.

YubiKey is now enabled as a second factor of authentication for the applicable users.

How to Register a YubiKey

When a user signs in for the first time after YubiKey authentication is enabled, the YubiKey must be registered with the user's Securden account.

To register a YubiKey:

  1. Launch the Securden Password Vault for Enterprises web interface.
  2. Enter your Securden credentials and complete the first level of authentication.
  3. After the first level of authentication succeeds, you will be prompted to enter a YubiKey OTP.
  4. Insert the YubiKey into a USB port on your computer.
  5. Before generating the OTP, decide which YubiKey slot you want to use for authentication. A YubiKey provides two slots, Slot 1 and Slot 2. You must continue using the same slot for subsequent authentication attempts.

Using Slot 1 of the YubiKey

Tap the YubiKey once to generate a 44-character OTP.

The first 12 characters uniquely identify the configured slot and remain the same during subsequent authentication attempts. The remaining 32 characters change each time a new OTP is generated.

Using Slot 2 of the YubiKey

Tap and hold the YubiKey for approximately 2–5 seconds to generate a 44-character OTP.

As with Slot 1, the first 12 characters uniquely identify the configured slot and remain the same for subsequent authentication attempts, while the remaining 32 characters change each time a new OTP is generated.

A sample set of OTPs generated from the same YubiKey may appear as follows:

cccjgdwkdjkwjdkjwikjdkhhfgrtnnlgedjlftrbdeut
cccjgjubuebduhubnjkedjkehijeiocjbnublfnrev
cccjgjgkcbejnvchfkfhiiuunbtnvgihdfiktncvlhck

Note

By default, YubiKey generates the Slot 1 passcode when used with NFC-enabled mobile devices. You can configure Slot 2 as the default by changing the configuration from Slot 1 to Slot 2 using the YubiKey Personalization Tool.

  • Submit the generated YubiKey OTP and click Register and Login.

Securden associates the unique 12-character identifier in the YubiKey OTP with your user account. During subsequent login attempts, this identifier is used to associate the YubiKey with your account as part of the second level of authentication.

Sign-In Workflow Using YubiKey

After the YubiKey has been successfully registered:

  1. Launch the Securden Password Vault for Enterprises web interface.
  2. Enter your Securden credentials and complete the first level of authentication.
  3. When prompted for the second factor, generate an OTP using the same YubiKey slot that was used during registration.
  4. Submit the generated YubiKey OTP to complete authentication.

The Securden server sends the generated OTP to the Yubico OTP validation service for verification. Therefore, the Securden server must continue to have access to:

https://api.yubico.com/wsapi/2.0/verify

Once successfully verified, the user will be authenticated into Securden Password Vault for Enterprises.

Securden Help Assistant
What's next?
Request a Demo Get a Price Quote
Thank you message

Thanks for sharing your details.
We will be in touch with you shortly

Thanks for sharing your details.
We will be in touch with you shortly.