<iframe src="https://www.googletagmanager.com/ns.html?id=GTM-M74D8PB" height="0" width="0" style="display:none;visibility:hidden">
Loading
Skip to NavigationSkip to Main Content
YubiKey Showed as Authenticator Instead of Its YubiKey Model Type
Okta Classic Engine
Multi-Factor Authentication
Overview

When users add any FIDO U2F, 4 Series, or FIPS 4 series, they are unable to see the proper name, and instead, it appears as "Authenticator". The YubiKey works as expected. 

Extra Verification 

Applies To
  • FIDO U2F Security Key
  • YubiKey 4 (Series)
  • YubiKey FIPS (4 Series)
  • Okta Classic Engine
Cause

The devices lack FIDO2 AAGUID. Okta is not able to add that information to the dictionary. Therefore, the result is the YubiKey device displayed as "Authenticator" in the user interface.

Solution

According to YUBICO, the attestation is done differently without an Authenticator Attestation GUID (AAGUID) (AAGUID was added in FIDO2/WebAuthn). In a WebAuthn call for a U2F authenticator (YubiKey 4 series and Yubico U2F Security Key), a certificate is returned that can be used to verify that it is a genuine YubiKey, but there is no additional information to identify which YubiKey. The same Yubico root certificate is used to sign all attestation data across all versions of YubiKeys.
 

Related References

Loading
YubiKey Showed as Authenticator Instead of Its YubiKey Model Type