2020-02-29 07:43:59 +07:00
|
|
|
---
|
2022-06-15 14:51:47 +07:00
|
|
|
title: "Security Key"
|
|
|
|
description: "Authelia utilizes WebAuthn security keys as one of it's second factor authentication methods."
|
|
|
|
lead: "Authelia utilizes WebAuthn security keys as one of it's second factor authentication methods."
|
2022-06-28 12:27:14 +07:00
|
|
|
date: 2020-02-29T01:43:59+01:00
|
2022-06-15 14:51:47 +07:00
|
|
|
draft: false
|
|
|
|
images: []
|
|
|
|
menu:
|
|
|
|
overview:
|
|
|
|
parent: "authentication"
|
|
|
|
weight: 240
|
|
|
|
toc: true
|
|
|
|
aliases:
|
|
|
|
- /docs/features/2fa/security-key
|
2020-02-29 07:43:59 +07:00
|
|
|
---
|
|
|
|
|
2022-06-15 14:51:47 +07:00
|
|
|
__Authelia__ supports hardware-based second factors leveraging [FIDO2] [WebAuthn] compatible security keys like
|
2021-07-15 10:21:47 +07:00
|
|
|
[YubiKey]'s.
|
2020-02-29 07:43:59 +07:00
|
|
|
|
2022-06-15 14:51:47 +07:00
|
|
|
Security keys are among the most secure second factor. This method is already supported by many major applications and
|
2022-03-03 18:20:43 +07:00
|
|
|
platforms like Google, Facebook, GitHub, some banks, and much more.
|
2020-02-29 07:43:59 +07:00
|
|
|
|
2022-06-15 14:51:47 +07:00
|
|
|
{{< figure src="yubikey.jpg" caption="A YubiKey Security Key" alt="A YubiKey Security Key" width=150 >}}
|
2020-02-29 07:43:59 +07:00
|
|
|
|
2022-06-15 14:51:47 +07:00
|
|
|
Normally, the protocol requires your security key to be enrolled on each site before being able to authenticate with it.
|
2022-03-03 18:20:43 +07:00
|
|
|
Since Authelia provides Single Sign-On, your users will need to enroll their device only once to get access to all your
|
|
|
|
applications.
|
2020-02-29 07:43:59 +07:00
|
|
|
|
2022-06-15 14:51:47 +07:00
|
|
|
{{< figure src="REGISTER-U2F.png" caption="The WebAuthn Registration View" alt="2FA WebAuthn Registration View" width=400 >}}
|
2020-02-29 07:43:59 +07:00
|
|
|
|
2022-03-03 18:20:43 +07:00
|
|
|
After having successfully passed the first factor, select *Security Key* method and click on *Register device* link.
|
|
|
|
This will send you an email to verify your identity.
|
2020-02-29 07:43:59 +07:00
|
|
|
|
|
|
|
*NOTE: This e-mail has likely been sent to the mailbox at https://mail.example.com:8080/ if you're testing Authelia.*
|
|
|
|
|
2022-06-15 14:51:47 +07:00
|
|
|
Confirm your identity by clicking on __Register__ and you'll be asked to touch the token of your security key to
|
2022-03-03 18:20:43 +07:00
|
|
|
complete the enrollment.
|
2020-02-29 07:43:59 +07:00
|
|
|
|
2022-03-03 18:20:43 +07:00
|
|
|
Upon successful enrollment, you can authenticate using your security key by simply touching the token again when
|
|
|
|
requested:
|
2020-02-29 07:43:59 +07:00
|
|
|
|
2022-06-15 14:51:47 +07:00
|
|
|
{{< figure src="2FA-U2F.png" caption="The WebAuthn Authentication View" alt="2FA WebAuthn Authentication View" width=400 >}}
|
2020-02-29 07:43:59 +07:00
|
|
|
|
|
|
|
Easy, right?!
|
|
|
|
|
2022-03-03 18:20:43 +07:00
|
|
|
## FAQ
|
2021-02-12 12:59:42 +07:00
|
|
|
|
2022-06-15 14:51:47 +07:00
|
|
|
### Can I register multiple FIDO2 WebAuthn devices?
|
2021-02-12 12:59:42 +07:00
|
|
|
|
2022-03-03 18:20:43 +07:00
|
|
|
At present this is not possible in the frontend. However the backend technically supports it. We plan to add this to the
|
|
|
|
frontend in the near future. Subscribe to [this issue](https://github.com/authelia/authelia/issues/275) for updates.
|
2021-02-12 12:59:42 +07:00
|
|
|
|
2022-03-03 18:20:43 +07:00
|
|
|
### Can I perform a passwordless login?
|
2021-02-12 12:59:42 +07:00
|
|
|
|
2022-03-03 18:20:43 +07:00
|
|
|
Not at this time. We will tackle this at a later date.
|
2020-02-29 07:43:59 +07:00
|
|
|
|
|
|
|
### Why don't I have access to the *Security Key* option?
|
|
|
|
|
2022-06-15 14:51:47 +07:00
|
|
|
The [WebAuthn] protocol is a new protocol that is only supported by modern browsers. Please ensure your browser is up to
|
|
|
|
date, supports [WebAuthn], and that the feature is not disabled if the option is not available to you in __Authelia__.
|
2022-03-03 18:20:43 +07:00
|
|
|
|
|
|
|
### Can my FIDO U2F device operate with Authelia?
|
|
|
|
|
|
|
|
At the present time there is no plan to support [FIDO U2F] within Authelia. We do implement a backwards compatible appid
|
2022-06-15 14:51:47 +07:00
|
|
|
extension within __Authelia__ however this only works for devices registered before the upgrade to the [FIDO2]
|
|
|
|
[WebAuthn] protocol.
|
2022-03-03 18:20:43 +07:00
|
|
|
|
2022-06-15 14:51:47 +07:00
|
|
|
If there was sufficient interest in supporting registration of old U2F / FIDO devices in __Authelia__ we would consider
|
2022-03-03 18:20:43 +07:00
|
|
|
adding support for this after or at the same time of the multi-device enhancements.
|
2020-02-29 07:43:59 +07:00
|
|
|
|
2022-03-03 18:20:43 +07:00
|
|
|
[FIDO U2F]: https://www.yubico.com/authentication-standards/fido-u2f/
|
|
|
|
[FIDO2]: https://www.yubico.com/authentication-standards/fido2/
|
2022-06-15 14:51:47 +07:00
|
|
|
[WebAuthn]: https://www.yubico.com/authentication-standards/webauthn/
|
2021-07-15 10:21:47 +07:00
|
|
|
[YubiKey]: https://www.yubico.com/products/yubikey-5-overview/
|