Yubico YubiKey 4/4 Nano/4C/4C Nano

vSEC:CMS will change your views on how to manage the lifecycle of Yubico YubiKeys. The vSEC:CMS S-Series for YubiKey is an innovative, easily integrated and cost-effective Smart Card Management System or Credential Management System (SCMS or CMS) that are helping organizations deploy YubiKeys.

vSEC:CMS Overview

  • Fast implementation that takes minutes, rather than weeks or months
  • Intuitive user interface that improves operational efficiency
  • No hidden costs and low total cost of ownership
  • Consistently high security level without exception
  • Large scale capabilities, available from day one

vSEC:CMS Connectors (see figure above)

1. Smart card printer for batch operations
2. User directory for looking up users
3. File and database servers
4. Secure transport of PIN codes
5. Event & log management
6. User photo capture
7. Certificate/PKI services
8. Physical access control systems
9. Hardware security module
10. Secondary/out-of-band communication
11. Key archival & key recovery
12. Credential provider -login screen interface
13. Remote security device management
14. User self-service application
15. Physical & virtual smart cards/tokens
16. Administrative operator console

This section shows what user directories, certificate authorities (CAs), Hardware Security Modules (HSMs) and other internal and external software and hardware that vSEC:CMS can work with to provide the ideal identity and access management system for our customers.

Technical Specifications

Operating Systems Windows 7
Windows 8
Windows 10
Windows Server 2008/R2
Windows Server 2012/R2
Windows Server 2016
Smart Card Readers All smart card readers compliant with PC/SC and certified by the Microsoft WHQL
Security Features Secure key storage
Secure backup and synchronization of databases
Disaster recovery for stolen/lost tokens
Encrypted audit log
Granular access control
Approval work flows
Connects logical and physical access control
Key archival and key restore processes
Support for fingerprint template management
Smart card stock/inventory management
Performance The system is tested and is functional with 300,000 registered user smart cards and 100 parallel operators interacting with the system
User Directory LDAP V2/V3
IBM LDAP
OpenLDAP
Microsoft Active Directory
Microsoft SQL Server Using LDAP to SQL gateway
Flexible Directory-PKI connector using alternative IDs
Certification Authority Microsoft Certificate Authority from 2008 R2 and above
Primekey EJBCA 4.0.12 Community and 6.3.2.3 Enterprise
Entrust version 8.1
Symantec version 8.15
Symantec MPKI 7.5 (for Kuwait Government PKI, PACI)
Nexus Certificate Manager version 7.9
Verizon UniCERT version 5.3.8
GlobalSign
Digicert
IDnomic (formely known as OpenTrust) PKI version 4.8.1
Database Card Repository
SQL Support (Native Client: 9.0, 10.0 and 11.0)
Backup / Restore
Multi-forest & Multi-domain
HSM Gemalto Safenet Luna
Gemalto Safenet ProtectServer
Utimaco SafeGuard CryptoServer
Thales nShield
Engage Black Vault
Card Printer Evolis Primacy
HID Fargo HDP5000
DataCard SR300
Magicard Prima 4
Matica 8300
Advanced Batch Mode
Card Layout Definition
Two-Factor Authentication Service (SMS) Telesign
Clickatell
Certificall
Tyntec
Dolphin
PACS and Other Connectors Mail Server (SMTP)
Photo Camera, webcam or Scanner
Data Export (SQL & CSV) to synchronize with other systems: Time attendance, HR, Printing etc.
Physical Access (PAMS)
Logging Option to log events to the Windows Event Log
Other CMS Upgrade path from vSEC:CMS K-Series and T-Series
Migration path from competing CMS products (inquire for more details)

The vSEC:CMS S-Series for YubiKey is fully functional with the YubiKey PIV and it streamlines all aspects of a management system by connecting to enterprise directories, certificate authorities, physical access control systems, email servers, log servers, biometric fingerprint readers, PIN mailers etc. With vSEC:CMS S-Series for YubiKey organizations can issue YubiKeys to employees, personalize the YubiKey with authentication credentials and manage the lifecycle of the YubiKey – directly from the off-the-shelf product.

We Manage Our YubiKeys Manually – Why Change?

Managing YubiKeys manually results in additional work and increases the possibilities of security breaches. For example, the administration key of the YubiKey will need to be stored in a file that references the user to whom it is issued. This file could be used maliciously by someone to ascertain the key value; consequently, the YubiKey could easily be reset with a new PIN by acquiring knowledge of the administration key. A CMS removes threats like these and provides many other benefits, such as full lifecycle management, a connection to the Certificate Authority, secure PIN unblock procedures, User Self Service and more.

Why Do You Need A CMS?

A CMS is required, for the following reasons::

  • To centralize YubiKey personalization, management and revocation tasks into one system
  • To reduce costs
  • To simplify installation and usage workflows
  • To enhance Security

Manage the complete Lifecycle

Manage the complete Lifecycle of the YubiKey from one simple view. Management can be delegated and granular access levels can be set. The Life Cycle

This Is How Easy It Is!

We support many different use cases and the configuration options and feature set is vast. But it’s easy to get started. The most common use case is being able to issue a YubiKey with a Windows logon certificate to a user in a secure way. Follow our guides and this can be accomplished in minutes rather than days. Once you have the initial use case configured you can build from there adding User Self Service, Remote Operators and support for other secure devices including Virtual Smart Cards.

Use Case – Windows Logon

We will guide you through the initial setup all the way to you issuing and managing the lifecycle of your YubiKeys. Follow this guide on our Support Portal: Manage PIV Smart Card Tokens
Note: The PKI used in this example use case will be an MS CA. Other PKIs are also supported.

Unblock YubiKey User PIN

We offer a unique way to increase the security of unblocking the YubiKey User PIN. This is done by encapsulating the PUC (PIN Unblock Code) in a Challenge Response Workflow.

Key Archival and Key Recovery

It is possible for a YubiKey to generate a user key on the YubiKey, which is highly secure, but it is not possible for the key to be recovered if the user misplaces the YubiKey. As a result, for encryption of certificates and keys, YubiKeys are used to store only certificates and keys generated by vSEC:CMS S-Series, so the keys can be stored securely in the vSEC:CMS S-Series database secured by the Master Key and are recoverable if needed.

Webinar and Instruction Videos

Webinar: Versasec vSEC:CMS + YubiKeys = A new PIV Smart Card Integration (7.13.16)

Reissue Certificate on YubiKey PIV Token
Central Issuance of YubiKey PIV Token
Offline PIN unblock of YubiKey PIV token
Online PIN unblock of Yubi PIV token
Issuance of Yubi PIV Token using vSEC:CMS Credential Provider
Batch Issue YubiKey Tokens Using vSEC:CMS

Evaluation – Download Today!

Register and download vSEC:CMS directly from versasec.com here.

Once downloaded and installed vSEC:CMS is ready for use in Evaluation Mode. During the evaluation, you can configure your environment with up to 5 licenses and your own use cases. Each license manages one credential. Additional licenses can be acquired as a subscription or by perpetual license. Please contact a Versasec reseller or Versasec directly to proceed.

Scalability

The vSEC:CMS scales with your project. With the new load balancing capability, there is no upper limit!

Product Sheet

Download the vSEC:CMS S-Series product sheet here.

[pdf]

vSEC:CMS

More information about the complete vSEC:CMS product suite can be found here.

[more]

Migrate to vSEC:CMS

vSEC:CMS S-Series includes upgrade wizards that enables quick and simple upgrade paths from third party credential management systems.

Check out the details on how to upgrade from:

Resellers

The product can be purchased from authorized vSEC:CMS integrators and resellers, via our partners reseller network or contact Versasec directly to let us help you find the best way forward.

Videos

The vSEC:CMS video content can be found here.

Supported Credentials

vSEC:TOOL

vSEC:CMS

Supported Credentials

K

S

C

ACS ACOS5-64
Aventra MyEID 4.5
Avtor CryptoCard 337
Atos CardOS v4.4
Atos CardOS v5.3
Cryptovision SCinterface
Key-ID PKI
Feitian ePass FIDO-NFC K9/PlusK9/K40
Feitian BioPass FIDO2 Plus K27/K26/K45
Feitian eJava Token
Feitian SmartCard
Feitian ePass2003
Feitian ePass2003 PKI eJava Token
Feitian ePass2003 PKI SmartCard
Feitian Fingerprint_Smart_Card_F2000
Feitian iePass_FIDO_PIV_K44
Thales IDPrime .NET 510
Thales IDPrime .NET 5500
Thales IDPrime MD 830
Thales IDPrime MD 840
Thales IDPrime MD 930
Thales IDPrime MD 940
Thales IDPrime MD 3810
Thales IDPrime MD 3840
Thales IDPrime MD 3930
Thales IDPrime MD 3940
Thales IDPrime MD 3940 FIDO
Thales IDPrime PIV 2.1
Thales IDPrime PIV 3.0
Thales IDPrime Virtual
Thales MultiApp ID
Thales Safenet eToken 5100/5110 FIPS
Thales Safenet eToken 5300
HID Global Crescendo C200
HID Global Crescendo C1150
Identiv uTrust MD
Longmai mToken CryptoID
Microsoft minidriver enabled devices
Microsoft Windows Hello for Business
Idemia ypsID S2
Idemia ypsID S3
Idemia ID-One Cosmo 8.1 IAS ECC
Idemia ID-One PIV 8.1
Open FIPS 201 Applet
SafeTrust-PIV on Placard
Taglio C2
Taglio PIVKey
TCOS TeleSec IDKey
Virtual Smart Cards
Yubico YubiKey 5 NFC/5C/5 Nano/5C Nano
Yubico YubiKey 4/4 Nano/4C/4C Nano
Yubico YubiKey NEO/NEO-n

NOTE
 – The credential is supported by the product.
L – Known limitations – check release notes.
For details about validated middleware/minidrivers check the Versasec support portal or contact us.

The table below highlights the key features included in the vSEC:CMS product suite. Further detailed information about each product is provided from this table.

vSEC:TOOL

vSEC:CMS

Product Features

K S C

User-Side Credential Operations

Agent-Side Credential Operations

  • Admin Key Change
  • Online Unblock User PIN
  • Offline Unblock User PIN (Operator Side)
  • User PIN Policy Update
  • Certificate Management (pfx or p12 Import, Delete)

Advanced Credential Operations

  • Admin Key Diversification
    from Hardware Protected Masterkey
  • User Fingerprint Policy Update
  • Batch Mode Support

Database

  • Credential Repository
  • SQL-based Databases
  • Backup / Restore
  • Multi-forest & Multi-domain

Credential Management System Features

vSEC:TOOL

vSEC:CMS

Product Features

K S C

Advanced Management Features

  • User Self-service and MS Credential Provider
  • Key Archive and Key Restore
  • Smart Card Stock Management
  • Granular Operator Permissions and Access Control
  • Card Printing and Batch Processing
  • Photo Capturing
  • Remote Security Device Management (RSDM)
  • Certificate Management using ACME

Systems Integrations

  • Certification Authorities (MS CA, Entrust, DigiCert, EJBCA, GlobalSign…)
  • User Directories (LDAP, MS AD)
  • Physical Access System (RFID)
  • Identity Providers (IdP) using OpenID Connect (OIDC)
  • Windows Event Log
  • Mail Server (for PIN mailing)
  • Hardware Security Module (HSM)

Integrations/APIs

Server-Side
  • SQL Database Interface
  • SQL High Availability – Microsoft Always On
  • SOAP Helpdesk API
  • SOAP Lifecycle API
Client-Side
  • COM API
  • Web Start API
  • Plugin API
  • Physical Access System (PACS) API

vSEC:TOOL

vSEC:CMS

Licensing/Packaging

K S C
Freeware
Perpetual Licenses
Subscription
Stand Alone Application
Installation Package
Ready To Deploy Image

 The feature is included in the product.

vSEC:CMS

Our product suite provides all the software tools to administrate and manage credentials in a secure and convenient way.

Start here

Free Product Trial

Versasec provides enabling IT security products centered on the usage of security devices such as smart cards. Our solutions enable customers to securely authenticate, issue and manage user credentials more cost effectively. Get a free product trial

Job Openings

We are always looking for new exceptional persons to join our team! Find out more about our job openings.

Versasec Support

Versasec customers with an existing support and maintenance contract can access the Versasec Support Portal, offering extensive professional support and maintenance services. The Versasec Support Portal offers a variety of services, allowing for customers and any site visitor to communicate directly with support engineers.

Contact Support

Company Blog

Our blog addresses the latest security trends and stories. The posts discuss how identity and access management are playing a larger role in keeping corporate data safe as well as brand reputations intact.

Visit our Blog