FAQs
Frequently Asked Questions | Customer Reference Guide
Contents
Getting Started
Q1. What is FIDO2, and how does the SecureKey or SecurePass work?
FIDO2 is an open authentication standard from the FIDO Alliance that replaces passwords with public-key cryptography. The SecureKey or SecurePass is a hardware device that generates and stores your private keys, letting you sign in with a simple touch, PIN, or NFC tap.
Q2. Why should I use SecureKey or SecurePass instead of a password?
Passwords can be phished, reused, or stolen. SecureKey or SecurePass creates a unique credential for each account using public-key cryptography, so there's no shared secret for an attacker to steal so your private key never leaves the device.
Q3. What is a passkey, and how is it different from a SecureKey or SecurePass?
A passkey is the credential itself a public/private key pair created under the FIDO2/WebAuthn standard. A SecureKey or SecurePass is the physical device that creates and stores passkeys. SecureKey or SecurePass also support PIV and OTP, so “SecureKey” or “SecurePass” describes the device, while “passkey” refers specifically to a FIDO2 credential.
Q4. How do I get started with my new SecureKey or SecurePass?
Register the key directly with the account you want to protect (e.g., Microsoft, Google, your bank) you don't register it with Hirsch first. In the account's security settings, choose “Set up a security key,” insert or tap your key, and follow the prompts. Application-specific guides are available on the Hirsch “Works with SecureKey and SecurePass” page.
Q5. Do I need to configure my SecureKey or SecurePass before using it for FIDO2?
No. For FIDO2, keys work right out of the box, most services simply prompt you to set a PIN the first time you register. Configuration is only needed if you plan to also use the PIV or OTP applets.
Compatibility
Q6. Which devices and operating systems are supported?
SecureKey or SecurePass work with Windows, macOS, Linux, iOS, and Android over USB-A, USB-C, or NFC, depending on the model. Confirm your device has a matching port or NFC support.
Q7. Which browsers support FIDO2 security keys?
Browser | Supported OS | Support Type |
|---|---|---|
Chrome | Windows / Mac / Linux | FIDO2 & U2F |
Firefox | Windows / Mac / Linux | FIDO2 & U2F |
Edge | Windows | FIDO2 |
Opera | Windows / Mac / Linux | FIDO2 & U2F |
Safari | macOS / iOS | FIDO2 & U2F |
Q8. Will this work with my iPhone?
Yes, with any iPhone that supports NFC and most models have been released in the last several years.
Q9. Will this work on my Chromebook?
Yes, as long as ChromeOS is up to date, you're using a supported browser, and your Chromebook has a USB port.
Q10. Can I use SecureKey or SecurePass with my Apple ID?
Yes. SecureKey or SecurePass work with Apple ID over USB-A, USB-C, or NFC, depending on your device.
Q11. Is the SecureKey or SecurePass compatible with Microsoft Entra ID / Azure?
Yes. SecureKey or SecurePass are natively supported by Microsoft Entra ID for passwordless sign-in to Microsoft 365 and other Azure-connected applications.
Q12. On my Mac, I'm prompted to press keys so it can detect my keyboard type is my key still working?
Yes — this is a standard macOS keyboard-detection prompt, unrelated to your key. Close that window and continue; the key will work normally.
Using Your SecureKey or SecurePass
Q13. How many accounts can one SecureKey or SecurePass protect?
SecureKey has
Total resident key (credential slot) capacity: 32
Maximum resident keys supported per Relying Party (RP): 32
SecureKey GOV and SecurePass has
Total resident key (credential slot) capacity: 40
Maximum resident keys supported per Relying Party (RP): 10
Q14. Do I need a separate SecureKey or SecurePass for every application or device?
No. One SecureKey or SecurePass can be registered with multiple FIDO2/U2F-certified applications and used across multiple devices, as long as each device has a compatible port or NFC.
Q15. What happens if I lose my SecureKey or SecurePass am I locked out permanently?
It depends on the service, but most offer recovery options such as backup codes or alternate verification. Best practice is to register two SecureKey or SecurePass per account a primary and a backup so a lost SecureKey or SecurePass never locks you out.
Q16. Can I duplicate my SecureKey or SecurePass as a backup?
No, the secure hardware design prevents duplication. Instead, register a second physical key with each account as a backup.
Q17. Once I register a SecureKey or SecurePass with an account, am I locked into using it forever?
No. You can add or remove registered SecureKey or SecurePass from your account at any time.
Q18. Do I need to install drivers?
No. SecureKey or SecurePass work without any driver installation on computers, tablets, or smartphones.
Q19. Is a SecureKey or SecurePass really “multi-factor” if it's just a key?
Yes. When you register the SecureKey and SecurePass, you also set a PIN. The SecureKey or SecurePass is “something you have,” and the PIN is “something you know” and together they satisfy two-factor authentication.
Troubleshooting
Q20. My SecureKey or SecurePass isn't recognized, registration fails, or the request times out so what should I check?
Reinsert the SecureKey or SecurePass, making sure it's right-side-up (USB-A) and fully seated
Try a different port, device, or a supported browser (Chrome, Firefox, Edge, Safari)
Touch or tap the SecureKey or SecurePass promptly when prompted and most timeouts happen when the SecureKey or SecurePass isn't activated quickly enough
If a credential already exists for that account, remove it before re-registering to avoid a “duplicate credential” error
If verification fails, confirm you're entering the correct PIN
Use the Hirsch uTrust Key Manager to confirm the key's model, firmware, and FIDO2 support
Q21. A browser says it's “not compatible with WebAuthn” — what does that mean?
Your browser or its version doesn't support FIDO2. Switch to the current version of Chrome, Firefox, Edge, or Safari (see the Compatibility section).
FIDO2 & Passwordless Authentication
Q22. What's the difference between FIDO U2F and FIDO2?
FIDO U2F (2014) is a second factor used alongside a password. FIDO2 (2019) is newer and enables full passwordless authentication: a PIN or biometric unlocks the key locally, and no secret is ever transmitted to the online service.
Q23. How does FIDO2 keep my accounts safer than a password?
Each account gets its own unique key pair generated on the device. The private key never leaves your key and is never shared with or stored by the service, which eliminates phishing, credential-stuffing, and password-reuse risks. A stolen key alone isn't enough — an attacker would also need your PIN or biometric.
Q24. If I use the same key on multiple websites, can one site tell I use it elsewhere?
No. Each website receives a separate, unique credential, and FIDO2 does not allow sites to correlate your activity across services.
Q25. Does FIDO2 share any of my personal information with websites or the FIDO Alliance?
No. The FIDO Alliance only defines the standard and doesn't collect data. Your credentials stay on your device and are never shared with a provider or service beyond the public key.
Q26. Why can't a phishing site trick my key into authenticating?
FIDO2 credentials are cryptographically bound to the website's origin, so a credential created for one site cannot be used — even by an attacker — on a look-alike phishing site.
Q27. What's the difference between a platform authenticator and a roaming authenticator like my uTrust key?
A platform authenticator (e.g., Windows Hello, Touch ID) is built into your device. A roaming authenticator, like a uTrust key, is an external device you can carry and use across multiple computers.
Q28. What is NFC FIDO, and how do I use it?
NFC-enabled uTrust keys let you authenticate wirelessly — just tap the key against your phone, tablet, or an NFC-enabled reader instead of plugging it in.
Q29. If I register a key on Windows, will it also work on my Mac?
Yes. FIDO2 credentials are tied to your account, not to the operating system, so the same key works across platforms as long as the service supports FIDO2/WebAuthn on both.
Q30. Can I transfer a passkey from one SecureKey or SecurePass to another, or store it in Samsung Vault?
No. Each key generates its own unique credential per account, and credentials can't be copied or transferred between hardware keys. For a backup, register a second key separately with the same account — Samsung Vault stores software-based passkeys, not credentials from external hardware keys.
Q31. What's the difference between a device-bound passkey (SecureKey or SecurePass) and a synced passkey (like iCloud Keychain)?
Device-bound passkeys live only on the physical key and never leave it, maximizing security. Synced passkeys are copied across your devices via a cloud service for convenience, which widens the credential's exposure. SecureKey or SecurePass use device-bound passkeys.
Q32. How do I sign in using my FIDO2 key?
Choose “Security key” or “Passkey” at sign-in, insert or tap your key, then complete the prompt — usually a touch and/or PIN entry.
Q33. How do I set or change the PIN on my FIDO2 key?
Most services prompt you to set a PIN the first time verification is required. You can also set or change it using the Hirsch uTrust Key Manager, or via Windows Settings → Accounts → Sign-in options → Security key.
Enterprise & On-Premises Authentication
Q34. What role can a SecureKey GOV play in hybrid (cloud + on-prem) environments?
The GOV key combines FIDO2 for cloud/passwordless login with a PIV/PKI applet for certificate-based, on-prem authentication in one FIPS 140-3 validated, TAA-compliant device — letting a single key serve both cloud and on-prem identity systems.
Q35. When should I use PKI (X.509 certificates) instead of FIDO2?
PKI/PIV is preferred for legacy or infrastructure-based use cases such as Active Directory domain logon, RDP sessions, and thin-client environments where certificate-based trust is already established. FIDO2 is best suited for cloud and web application sign-in.
Q36. How do I enable FIDO2 for on-premises Windows logon?
Use the Hirsch uTrust Windows Logon solution, which provides local middleware so users can sign in to Windows workstations passwordlessly with a FIDO2 key.
Q37. Does the uTrust FIDO2 Login Manager support Active Directory?
The Login Manager handles local machine logon only and does not integrate with Active Directory authentication flows. For AD domain logon, use PIV-based smart card authentication instead.
Q38. How do I use SecureKey or SecurePass for Active Directory domain logon?
Provision a PIV authentication certificate onto the key's PIV applet through your organization's PKI (e.g., AD Certificate Services). The key then functions as a standard PIV smart card for AD logon.
Q39. Is a FIPS 140-3 SecureKey or SecurePass equivalent to a smart card for enterprise use?
Functionally, yes. FIPS 140-3 keys with a PIV applet support certificate-based authentication the same way a smart card does, in a different form factor.
Q40. How does FIDO2 fit into Microsoft Entra ID / Office 365?
FIDO2 is natively supported by Microsoft Entra ID for passwordless sign-in to Microsoft 365 and other Azure-connected applications.
Q41. Do I need to pre-configure SecureKey or SecurePass before issuing them to our users?
Not for FIDO2 — users self-register their own key with each service. PIV certificates, however, can be pre-provisioned in advance if you prefer.
PIV (Smart Card) Authentication
Q42. What is PIV, and how is it used?
PIV (Personal Identity Verification) is a smart-card-based credential, widely used by U.S. federal agencies, that supports certificate-based authentication, digital signing, and encryption for both physical and logical access.
Q43. How do I log in using my PIV key?
Insert your PIV-enabled key into a reader and enter your PIV PIN when prompted. The SecureKey and SecurePass models support PIV.
Q44. How do I change my PIN, PUK, or management key?
Use the Hirsch uTrust Key Manager (SecureKey and SecurePass models) or your organization's PIV management software.
Q45. What are the PIN/PUK retry limits, and what happens if I'm locked out?
You get 6 attempts each for PIN and PUK. Too many incorrect PIN attempts blocks the PIV application until it's unblocked with the PUK; too many incorrect PUK attempts requires reissuance through your badging office.
Q46. What if my PIV certificate has expired?
Visit your issuing office or lifecycle workstation to renew or reissue the certificate.
Q47. My PIV key or card isn't recognized — what should I do?
Reinsert it and check orientation, try a different reader, and confirm PIV drivers/middleware are installed on Windows. If the issue persists, contact your issuing office or IT help desk.
Q48. What do “Smart Card is blocked” or “System cannot log you on” errors mean?
“Smart Card is blocked” means too many incorrect PIN attempts were entered — visit your badging office to reset it. “System cannot log you on” usually means the system can't validate your PIV certificate — contact IT support.
Q49. What should I do if I lose my PIV badge?
Report it immediately so your access and certificates can be deactivated; a temporary badge is typically issued.
Q50. How do I handle a re-issued PIV or CAC card?
Start the re-registration process through your service portal, which typically requires verifying your identity with a one-time code or email.
Q51. Does the uTrust Key Manager Tool support loading PIV certificates?
Not currently. To test PIV certificate loading, use the Hirsch uTrust Mini Driver.
OTP (HOTP) Authentication
Q52. Does my SecureKey or SecurePass support one-time passcodes (OTP)?
Yes — SecureKey and SecurePass support HOTP (HMAC-based One-Time Password) out of the box, configured by default to generate a 6-digit code.
Q53. How do I program my SecureKey or SecurePass for OATH-HOTP?
In the Hirsch uTrust Key Manager, go to Applications → OTP, enter your OTP secret key, and click Finish. From then on, each touch of the key generates a new 6-digit code.
Q54. Where do I get my HOTP seed/secret key?
Your HOTP seed must come from the service enabling HOTP authentication — it can't be generated by you. If you purchased your key through Hirsch, contact Sales and we can provide a seed.
Q55. Should I use HOTP or TOTP?
HOTP doesn't rely on time synchronization, making it more reliable for cases like SMS or email where delays are unpredictable. TOTP codes instead expire on a fixed interval (e.g., every 30 seconds).
Q56. Are there security considerations I should know about with HOTP?
An HOTP code doesn't expire until it's used, so exposure risk is somewhat higher than TOTP. Missed validations can also desynchronize the counter between the key and the server.
PGP Encryption (SecureKey GOV or SecurePass)
Q57. Which SecureKey GOV or SecurePass supports PGP?
PGP is supported by SecureKey GOV.
Q58. What's the difference between PGP and PIV on a SecureKey GOV?
PGP is used for email encryption and signing; PIV is used primarily for authentication.
Q59. How do I set up PGP on my SecureKey GOV?
Generate your key pair using GnuPG (or GPG Suite on macOS), then transfer the subkeys to your GOV key's OpenPGP applet for secure storage.
Q60. Does Hirsch provide a tool for managing PGP keys?
No — the Hirsch uTrust Key Manager Tool supports FIDO, PIV, and OTP only. Use the GnuPG tool suite for PGP.
Q61. Is it safe to store my PGP private key on the device?
Yes. The private key is generated and stored in the secure element and never leaves it, making it resistant to extraction.
Q62. What's the difference between my public and private PGP key?
Your public key encrypts messages and verifies signatures; your private key decrypts messages and creates signatures.
Q63. How do I back up my PGP keys?
Generate the master private key externally (not on the device) and transfer only the subkeys to your GOV key — this preserves a recoverable backup.
Q64. How do I export my public PGP key?
Export it using your PGP tool or email client so you can share it with others.
Q65. How do I revoke a PGP key?
Generate a revocation certificate and publish it, then notify anyone who has your public key that it's no longer valid.
Q66. What's the retry limit for the PGP PIN and Admin PIN, and what happens if I'm locked out?
Each has 3 attempts. If the PIN is blocked, you won't be able to sign or decrypt until it's reset with the Admin PIN.
Q67. How do I configure PGP on macOS or Linux?
On macOS, use GPG Suite. On Linux, standard GnuPG tooling works — see the Linux Foundation's GPG guide for step-by-step setup.