End User Guide#
Audience: End Users
Prerequisites: Kleidia account, YubiKey device
Outcome: Use Kleidia to manage your YubiKey devices
Getting Started#
First Time Setup#
Install Agent (if not already installed by IT)
- See Agent Installation Guide for detailed instructions
- End users: Follow the “End User Installation” section
- IT administrators: Follow the “Enterprise Deployment” section
- Agent runs automatically in background as system service
Log In
- Navigate to your organization’s Kleidia URL (e.g.,
https://kleidia.example.com) - Enter your username and password
- Click “Log In”
- Navigate to your organization’s Kleidia URL (e.g.,
Verify Agent Connection
- After logging in, check that the agent is connected
- You should see “Agent Connected” status in the dashboard
- If not connected, see Agent Installation Guide
Register Your First YubiKey
- Connect YubiKey to your computer
- Navigate to “Register YubiKey” page
- Follow registration wizard
Managing Your YubiKeys#
View Your YubiKeys#
- Navigate to Dashboard → My YubiKeys
- View list of all your registered YubiKeys
- See device status, serial numbers, and details
Register a New YubiKey#
- Connect YubiKey to your computer
- Navigate to Dashboard → Register YubiKey
- System automatically detects connected YubiKey
- Enter device information:
- Device name (optional)
- PIN (if setting up new device)
- PUK (if setting up new device)
- Click “Register Device”
- Device appears in your YubiKeys list
View YubiKey Details#
- Navigate to My YubiKeys
- Click on a YubiKey device
- View detailed information:
- Serial number
- Device status
- Certificate information
- PIN/PUK status
- Management key status
PIN and PUK Management#
Change PIN#
- Navigate to My YubiKeys
- Select your YubiKey device
- Click “PIN & PUK” tab
- Enter current PIN
- Enter new PIN
- Confirm new PIN
- Click “Change PIN”
- Operation completes automatically
Change PUK#
- Navigate to My YubiKeys
- Select your YubiKey device
- Click “PIN & PUK” tab
- Enter current PUK
- Enter new PUK
- Confirm new PUK
- Click “Change PUK”
- Operation completes automatically
Unblock PIN#
If your PIN is blocked:
- Navigate to My YubiKeys
- Select your YubiKey device
- Click “Advanced” tab
- Enter PUK
- Enter new PIN
- Confirm new PIN
- Click “Unblock PIN”
Certificate Management#
Generate Certificate#
- Navigate to My YubiKeys
- Select your YubiKey device
- Click “Certificate” tab
- Enter your PIN when prompted
- Click “Generate Certificate”
- System automatically generates CSR on YubiKey with subject
yubikey-<serial-number> - System signs certificate via OpenBao PKI
- Certificate imported to YubiKey automatically
- Certificates ready for use
Note: Certificate details (subject, issuer, validity) are automatically generated by the system. Users only need to provide their PIN. The certificate subject is automatically set to yubikey-<serial-number> where <serial-number> is your YubiKey’s serial number.
View Certificates#
- Navigate to My YubiKeys
- Select your YubiKey device
- View certificate information:
- Certificate subject
- Issuer
- Validity period
- Serial number
- PIV slot
Note: Certificate revocation is controlled by administrators. Users cannot revoke certificates.
Device Management#
Check Device Status#
- Navigate to My YubiKeys
- View device status indicators:
- Active: Device is registered and active
- Connected: Device is currently connected
- Disconnected: Device is not connected
Reset Device#
⚠️ WARNING: This will erase all PIV data on the YubiKey.
- Navigate to My YubiKeys
- Select your YubiKey device
- Click “Advanced” tab
- Click “Delete Yubikey”
- Confirm reset
- PIV application reset to factory defaults
- Device removed from system
Troubleshooting#
Agent Not Detected#
Symptom: System cannot detect agent on your workstation.
Solutions:
- Verify agent is installed and running
- Check agent is running on localhost:56123
- Refresh browser page
- Check browser console for errors
- Restart agent if needed
YubiKey Not Detected#
Symptom: System cannot detect your YubiKey.
Solutions:
- Verify YubiKey is connected to computer
- Check YubiKey is inserted properly
- Try different USB port
- Refresh device list
Note: The agent installer includes ykman (YubiKey Manager CLI) - no separate installation required.
Operation Failed#
Symptom: PIN/PUK change or certificate operation fails.
Solutions:
- Verify correct PIN/PUK entered
- Check YubiKey is connected
- Check YubiKey is not locked
- Try operation again
- Contact administrator if issue persists
Best Practices#
- ✅ Keep your PIN and PUK secure
- ✅ Change default PIN/PUK immediately
- ✅ Use strong PINs (6-8 digits)
- ✅ Keep YubiKey firmware updated
- ✅ Backup important certificates
- ✅ Report lost or stolen devices immediately
Getting Help#
- Check this documentation
- Contact your system administrator
- Review troubleshooting section
- Check system status page