Using the YubiKey Manager GUI¶
The YubiKey Manager’s (ykman’s) graphical user interface (GUI) is a quick, convenient way to find out what firmware your YubiKey has and/or to reset it - unless you prefer to use ykman’s CLI. Note that the CLI has more options, so if you do not find what you want in the GUI, check to see if the CLI has it.
Checking Firmware Version¶
Launch the YubiKey Manager App and connect your YubiKey if it is not already connected. Note that the tool will only read a single YubiKey at a time, so if you have multiple keys connected, it might not be evident which one the tool is identifying.
The YubiKey Manager opens the Home tab by default, displaying the following:
- YubiKey series (e.g., YubiKey 5)
- Firmware (e.g., 5.4.X)
- Images of the various form factors within that series.
YubiKey Manager GUI, Home tab
The YubiKey Manager can be used to check which applications are enabled on which interface and to enable or disable each application on each physical interface.
To find out which applications are enabled, select the Interfaces tab. A checkbox with a tick is shown next to each enabled applications. To change which applications are enabled, use the checkboxes to select the ones you want enabled and click Save Interfaces.
For the YubiKey 5Ci, any modifications made to the applications over the USB interface will also apply to the applications over Lightning®.
Once the desired applications have been selected, a lock code can be set to prevent changes to the set of enabled applications. This is done using the YubiKey Manager command line interface command
ykman config set-lock-code. The lock code is 16 bytes presented as 32 hex characters. For more information, see ykman config set-lock-code [OPTIONS].
The Interfaces tab displays your key’s form factor (e.g., USB), and the interfaces it has. Use the Interfaces tab to configure what is available on that key. For example, you can disable the interfaces by deselecting the respective checkboxes.
Resetting FIDO2 Function¶
Resetting the key is not the same as unblocking it. Because resetting the FIDO2 function returns the key to its beginning state when it has no PIN, you must set a new PIN and enroll the key again after resetting it.