CalNet 2-Step: YubiKeys and Hardware Tokens
UC Berkeley supports hardware-based methods for 2-Step authentication. These options are ideal for users who do not have a smartphone or who work in secure environments without cellular service.
1. What is the difference?
While both devices allow you to 2-Step without a phone, they function differently and have different availability:
| YubiKey (Security Key) | Simple Hardware Token (Legacy) |
|---|---|
|
How to Use: Once inserted into a USB port, you simply touch the YubiKey. It automatically generates a code and completes the 2-Step for you. Availability: Currently available for purchase or request. See below. |
How to Use: You must manually type the 6-digit numerical code generated by the token into the 2-Step prompt on your screen. Availability: No longer available for purchase or distribution. However, students who already have one can enroll it and use it to complete CalNet 2-Step. |
2. How to Obtain a YubiKey
- Employees and UCPath Affiliates: Request a free YubiKey by contacting calnet2-stephelp@berkeley.edu.
- Students: Please visit Student Technology Services for support.
- Alumni and Campus Departments: You can purchase YubiKeys directly from the Yubico website. The newer models support both U2F and OATH-HOTP capabilities.
Recommended Models
U2F tokens can be set up through the self-service portal. For more information, see: How to Enroll a Security Key (KB0012341).
3. Using and Programming YubiKeys
The YubiKey is the current campus standard for hardware-based authentication. It is a durable, battery-free device that fits on a keychain.
Standard/Recommended Use (FIDO2/WebAuthn)
All modern web browsers support FIDO2, which is the easiest and most secure way to use a YubiKey. Once registered, you simply touch the key when prompted by CalNet.
Using YubiKeys as OTP Tokens
YubiKeys can also be configured as OTP (One-Time Password) tokens for use in non-web environments where a standard "touch to sign-in" prompt may not appear.
If you specifically require your YubiKey to function as an OTP token, please email calnet-admin@berkeley.edu for programming assistance.
4. Technical References
Support: If you have questions about which hardware device is right for you, please contact the IT Help Desk (KB0014900).